IN Brief:
- The validated Secure Element can be licensed as a complete platform or individual IP blocks for SoCs, ASICs, and chiplets.
- The OpenTitan and RISC-V implementation combines secure boot, key storage, device identity, firmware update, and post-quantum cryptography support.
- Prototype silicon was manufactured on GlobalFoundries' 22nm FD-SOI process in Dresden before the platform entered technology transfer.
Fraunhofer EMFT has completed functional silicon validation of a RISC-V Secure Element and moved the implementation into technology transfer for custom SoCs, ASICs, and chiplets. Based on OpenTitan and a RISC-V architecture, the platform is now available as licensable intellectual property, either as a complete implementation or as individual IP blocks with integration support.
The Secure Element incorporates a hardware root of trust, secure boot, secure key storage, device identity management, authentication, and secure firmware updates. Conventional and post-quantum cryptography are supported, while future development is expected to add further sensor capabilities. The prototype was manufactured using GlobalFoundries’ 22nm FD-SOI process in Dresden and has completed functional evaluation on dedicated test hardware.
Silicon validation removes a substantial source of risk from security IP intended for integration into another semiconductor design. RTL can behave correctly in simulation yet still expose problems during physical implementation, fabrication, bring-up, firmware integration, or system validation. A verified implementation gives licensees a tested hardware baseline, although each customer still has to qualify the block inside its own clocking, power, interconnect, manufacturing, and product-security environment.
Embedding the root of trust also changes the board-level architecture. Secure boot, identity, authentication, and key handling can move into the main silicon rather than relying on a separate security device, reducing component count and exposed interfaces. Provisioning, debug policy, firmware update, manufacturing test, and lifecycle management then become earlier parts of the SoC programme because the security boundary is coupled more closely to the main device.
Security integration also changes verification scope. A root of trust has to start correctly under reset and brownout conditions, protect secrets during test and debug, enforce lifecycle states, and interact predictably with the host processor and firmware. Manufacturing flows must provision keys or device identities without exposing them, while field-update mechanisms have to recover from interrupted or rejected images without weakening the boot chain.
The platform is designed for products expected to remain deployed for long periods, including industrial automation, medical technology, communications, energy infrastructure, IoT, and edge computing. Support for post-quantum cryptography gives developers a route to accommodate changing cryptographic requirements during those lifecycles, while a licensable implementation allows the security functions to be optimised against area, power, and performance targets in the host design.
Regulation is adding another constraint to that design work. The EU Cyber Resilience Act introduces cybersecurity obligations for products with digital elements, increasing the need to establish secure update mechanisms, device identity, vulnerability handling, and trust anchors before hardware reaches production. Recent production security work around Caliptra illustrates the same implementation problem: an open root-of-trust specification is only one layer of a production security architecture, which also depends on provisioning, firmware, lifecycle controls, and integration with the wider SoC.
The RISC-V Secure Element was developed through the Trusted Electronic Bayern centre by Fraunhofer AISEC, Fraunhofer EMFT, and Fraunhofer IIS. Funding came from the Bavarian State Ministry of Economic Affairs, Regional Development and Energy and the European Regional Development Fund. Fabrication in Dresden gives the prototype a European design and manufacturing route, while the move into technology transfer provides semiconductor companies with a starting point that has already crossed the first silicon-validation barrier.
The licensing model also matters for chiplet-based systems, where security boundaries can cross die-to-die links and package interfaces rather than remaining inside one monolithic SoC. A reusable secure element can anchor identity and boot policy, but the surrounding package still has to establish which chiplets are trusted, how firmware is authenticated across them, and which interfaces remain available during manufacturing and service.
The next engineering work will happen inside customer designs. Integrators still have to connect the Secure Element to their boot architecture, memory map, firmware, manufacturing provisioning, field-update system, and product-specific certification process. The value of the validated silicon lies in narrowing that task: companies can begin from a functioning hardware implementation rather than turning an open security architecture into production-ready silicon from scratch.



