Secure chip design
We design authentication and encryption chips that let a product prove it is genuine and keep its keys inside the silicon. Each design is evaluated against the attacks it is meant to resist.
This page covers chip design. For evaluations of chip-based systems, see Security evaluation.
What the chips do
Each chip is designed so that its keys never leave it. Depending on the product, it also does one or both of these.
- Authenticate a device or component to its host
- Encrypt and sign data on the chip
How we design them
- One key per device
- Every device gets its own key. We never rely on a secret shared across devices.
- Controlled provisioning
- Keys are generated or injected in a controlled provisioning step.
- A stated threat model
- Every design starts from a stated threat model: what the chip protects, and the attacks it is meant to resist.
- Evaluated against its threat model
- Each design is evaluated against the attacks it is meant to resist, with the same methods we use for client evaluations.
Working with us on a design
- 1
Requirements and threat model
We agree what the chip must do and what it must protect, and write down the attacks it is meant to resist.
- 2
Architecture
We design the chip’s authentication, key storage and cryptography to meet those requirements.
- 3
Implementation support
We support the implementation and review the result against the architecture.
- 4
Evaluation
We test the design against the attacks in its threat model.
- 5
Provisioning plan
We plan how each chip’s keys are generated or injected, and who controls that step.
Grounded in research
Since July 2009, ChipFans has researched how chips prove their identity and protect their keys. That research shapes both lines of work: the chips we design, and how we evaluate chip-based systems.
Start a chip design
Email us what your product is, what the chip must protect, and your timeline.