Secure chip design

We design authentication and encryption chips that let a product prove it is genuine and keep its keys inside the silicon. Each design is evaluated against the attacks it is meant to resist.

This page covers chip design. For evaluations of chip-based systems, see Security evaluation.

What the chips do

Each chip is designed so that its keys never leave it. Depending on the product, it also does one or both of these.

  • Authenticate a device or component to its host
  • Encrypt and sign data on the chip

How we design them

One key per device
Every device gets its own key. We never rely on a secret shared across devices.
Controlled provisioning
Keys are generated or injected in a controlled provisioning step.
A stated threat model
Every design starts from a stated threat model: what the chip protects, and the attacks it is meant to resist.
Evaluated against its threat model
Each design is evaluated against the attacks it is meant to resist, with the same methods we use for client evaluations.

Working with us on a design

  1. 1

    Requirements and threat model

    We agree what the chip must do and what it must protect, and write down the attacks it is meant to resist.

  2. 2

    Architecture

    We design the chip’s authentication, key storage and cryptography to meet those requirements.

  3. 3

    Implementation support

    We support the implementation and review the result against the architecture.

  4. 4

    Evaluation

    We test the design against the attacks in its threat model.

  5. 5

    Provisioning plan

    We plan how each chip’s keys are generated or injected, and who controls that step.

Grounded in research

Since July 2009, ChipFans has researched how chips prove their identity and protect their keys. That research shapes both lines of work: the chips we design, and how we evaluate chip-based systems.

Read about our research

Start a chip design

Email us what your product is, what the chip must protect, and your timeline.

Discuss a chip design