Fraunhofer opens RISC-V secure element for licensing

Fraunhofer opens RISC-V secure element for licensing

Fraunhofer makes validated RISC-V secure element available for commercial licensing. The OpenTitan-based platform combines embedded trust, secure updates and cryptographic functions for custom SoCs, ASICs and chiplets.


IN Brief:

  • The RISC-V Secure Element has completed functional silicon validation and is now entering technology transfer.
  • Functions include hardware root of trust, secure boot, key storage, authentication, device identity and secure firmware updates.
  • The implementation supports conventional and post-quantum cryptography and was manufactured using GlobalFoundries’ 22nm FD-SOI process.

Fraunhofer has moved its RISC-V Secure Element into technology transfer after completing functional silicon validation, making the security platform available as licensable intellectual property for custom SoCs, ASICs and chiplets.

The implementation is based on OpenTitan and a RISC-V architecture and can be licensed as a complete solution or as individual IP blocks. Fraunhofer is also offering firmware integration components, engineering support and collaborative development for companies incorporating the technology into their own semiconductor designs.

Validation was carried out on a physical silicon prototype manufactured using GlobalFoundries’ 22nm FD-SOI process in Dresden. Moving from an architectural implementation to verified silicon gives prospective users a hardware-tested starting point rather than an IP package whose behaviour has only been established through simulation or FPGA prototyping.

The platform integrates a hardware root of trust, secure boot, protected key storage, device identity management, authentication and secure firmware updates. It also supports conventional and post-quantum cryptography, allowing the same security subsystem to address established algorithms and newer cryptographic requirements.

Integrating those functions directly into a custom chip changes both the hardware boundary and the design process. A discrete security device can provide physical separation, but it adds another package, interfaces and board connections. An embedded secure element can reduce component count and board area while giving the semiconductor designer more control over power, performance and silicon area.

Security decisions consequently move earlier in the programme. Boot architecture, memory access, firmware updates, identity provisioning and protected interfaces have to be defined while the SoC or ASIC is still being designed. Changes late in the project become considerably more expensive once RTL, verification, physical design and software have converged around a particular architecture.

Fraunhofer is positioning the verified platform as a way to reduce some of that risk. The implementation already includes firmware integration components, allowing semiconductor developers to work from a known hardware and software foundation rather than assembling separate security blocks and then proving the complete trust chain themselves.

Regulatory requirements add another pressure. The EU Cyber Resilience Act places lifecycle obligations on connected products, increasing the value of hardware mechanisms capable of supporting trusted boot, authenticated updates and protected identities over a product’s service life. An embedded secure element does not make a finished system compliant on its own, but it provides mechanisms around which a product security architecture can be built.

The target applications span industrial automation, medical technology, communications, energy infrastructure, IoT and edge computing. These markets often combine long equipment lifetimes with increasing connectivity, leaving products exposed to evolving software and network threats well after their original hardware architecture has been frozen.

Post-quantum cryptography creates a further design consideration because algorithms developed to resist future quantum attacks can demand different processing, storage and communication resources from established cryptographic schemes. Supporting those functions inside the security platform gives developers a route to introduce them without treating the wider application processor as the sole trusted execution resource.

The European development chain is another feature of the programme. The Secure Element was developed through the Trusted Electronic Bayern Center by Fraunhofer AISEC, Fraunhofer EMFT and Fraunhofer IIS, with the prototype fabricated by GlobalFoundries in Dresden.

OpenTitan provides the platform with an established open-source hardware security foundation, while Fraunhofer’s work takes the implementation through silicon validation and into a form that can be integrated into commercial semiconductor programmes. The difference is practical: potential licensees can assess real implementation data, interfaces and integration requirements rather than beginning with a reference architecture alone.

Fraunhofer plans to extend the platform with additional sensor capabilities. Before those additions arrive, the commercial test will be whether SoC, ASIC and chiplet developers use the verified design to replace discrete security components or internally developed trust blocks.

Functional validation removes one source of uncertainty, but production integration will expose others, including verification effort, area allocation, firmware ownership and qualification. The licensing programme gives semiconductor teams a hardware-proven foundation on which to make those trade-offs.


Stories for you