Root of Trust and Root of Security IP

Protecting data at rest

Protecting Data at Rest with Rambus Root of Trust and Root of Security IP

To provide a hardware-based foundation for security, Rambus offers a broad range of robust Root of Trust and eHSM solutions, ranging from programmable security co-processors with features such as Quantum Safe Cryptography (QSC) to highly compact, firmware-controlled designs. The Rambus CryptoManager™ IP family is ideal for integration in complex gateways and cloud applications where multiple hosts need to access and leverage services provided by the root of trust. The Rambus RT-100 Root of Trust IP family targets secure IoT and MCU designs.

Rambus offers a dedicated security and root of trust IP solution for virtually any application, including data centers, AI/ML processing, automotive, and Internet of Things (IoT) devices.

Explore Rambus Root of Trust and Root of Security IP Products
Root of Trust Solutions for Data Center / AI / SoC / Government

CryptoManager Root of Trust
RT-6xx/16xx
RISC-V Programmable

Root of Trust Solutions for Automotive

CryptoManager eHSM
RT-64x/RT-7xx
RISC-V or Arm Cortex Programmable

Root of Trust Solutions for IoT

RT-100/200
RT-13x/26x
Lightweight IoT

Ask the Experts: CryptoManager Root of Trust

On this episode of Ask the Experts, we chat with Parvez Shaik about the latest developments in security and the concept of the root of trust. Watch this video to learn about the importance of addressing supply chain vulnerabilities, the advantages of a hardware root of trust, and the new features of the third-generation CryptoManager Root of Trust products.

Ask the Experts: CryptoManager Root of Trust with Parvez Shaik

CryptoManager Root of Trust RT-6xx/16xx

The CryptoManager RT-6xx v3 Root of Trust (CMRT) family from Rambus is the latest generation of fully programmable FIPS 140-3 compliant hardware security cores offering Quantum Safe security by design for data center and other highly secure applications. The RT-6xx allows customers to develop secure and trusted applications that run securely within a trusted boundary. Secure applications can be assigned unique roots and keys, allowing independent permissions and access levels.

For Automotive-grade HSM, click here.

ProductProduct Configurations and Cryptographic Accelerators Supported
Baseline for all RT-6xx/16xxRambus secure RISC-V processor, NIST CMVP compliant (incl dedicated certified SKU), SESIP/PSA certified, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG, classic and LMS and XMSS boot flow. FIPS 140-3/SESIP/PSA RoT. Secure Boot, Debug, FOTA. Secure, firewalled, in-core processing. Multi-layered security model. Secure lifecycle management. Secure data store. Secure provisioning. Select Quantum Safe SKUs provide a full quantum safe boot flow, and supports ML-KEM, ML-DSA, SLH-DSA, LMA, XMSS.
FeaturesRT-630RT-631RT-634RT-635RT-660RT-661RT-664RT-1664
OSCCA SM2/3/4     
Full Quantum Safe Boot & Crypto    
CaliptraTM DICE Option       
Physical Attack Resistance (SCA & FIA)    
Target SegmentRT-630RT-631RT-634RT-635RT-660RT-661RT-664RT-1664
SoC 
Data Center     
AI Edge    
Government     

Automotive-grade CryptoManager HSM RT-7xx/RT-64x

The automotive-grade CryptoManager RT-7xx v3 Root of Trust family from Rambus is the next generation of fully programmable ISO 26262 and ISO 21434 compliant hardware security modules offering Quantum Safe security by design for secure automotive applications supporting AutoSAR, EVITA full and SHE+. The RT-7xx allows customers users to develop secure and trusted applications that run securely within a trusted boundary. Secure applications can be assigned unique roots and keys, allowing independent permissions and access levels. The RT-76xD is industry’s first ASIL-HSM. The first-generation RT-640 with its ISO 26262 ASIL-B certificate is also part of this family.

ProductProduct Configurations and Cryptographic Accelerators Supported
Baseline for
all RT-7xx/RT-64x
Automotive-grade HSM. NIST CMVP compliant, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG, classic and LMS and XMSS boot flow. ISO 21434/26262 HSM. Secure Boot, Debug, FOTA. Secure, firewalled, in-core processing. Multi-layered security model. Secure lifecycle management. Secure data store. Secure provisioning. Select Quantum Safe SKUs provide a full quantum safe boot flow, and supports ML-KEM, ML-DSA, SLH-DSA, LMA, XMSS.
FeaturesRT-640RT-641RT-645RT-648RT-730BRT-731BRT-734BRT-760DRT-761DRT-764D
RISC-V Processor 
Arm Cortex-M33 Processor         
OSCCA SM2/3/4     
Full Quantum Safe Boot & Crypto      
Physical Attack Resistance (SCA & FIA)       
SCA SW         
Automotive GradeRT-640RT-641RT-645RT-648RT-730BRT-731BRT-734BRT-760DRT-761DRT-764D
ISO 21434
ASIL-D process    
ASIL-B FuSa   
ASIL-D FuSa       

RT-100/200 Firmware Controlled Root of Trust for IoT

Designed to be integrated in power and space-constrained SoCs or FPGAs, the RT-100 and RT-200 Root of Trust families (formerly VaultIP) include SESIP and PSA certified, FIPS 140-2 and FIPS 140-3 certified hardware security modules that guard the most sensitive assets on chips and establish the foundation for platform security.

Featuring a firmware-controlled architecture with dedicated secure memories, the RT-100/200 families provide a variety of cryptographic accelerators including AES, SHA-2, RSA and ECC. Ideal for power and space-sensitive applications like Secure MCUs, IoT servers, gateways and edge devices, the RT-100/200 families offer the best balance of size and performance available on the market.

Product Product Configurations and Cryptographic Accelerators Supported
Baseline for all RT-1xx/2xx NIST CMVP certified/compliant, SESIP/PSA certified, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG. Secure Boot, Secure Debug, Secure Asset Store.
Features RT-120 RT-121 RT-130 RT-131 RT-260 RT-261
AES-XTS
SHA-512 & SHA-3
OSCCA SM2/3/4
SCA (DPA)
Target Segment RT-120 RT-121 RT-130 RT-131 RT-260 RT-261
IoT Sensor
IoT Gateway
China
Secure MCU

CryptoManager RT-6xx Root of Trust Family: A New Generation of Security Anchored in Hardware

Download RT-600 Root of Trust Series: A New Generation of Security Anchored in Hardware

This latest generation of the Rambus RT-600 Root of Trust IP offers many new features designed to support the security needs of customers today and into the future. These features include Quantum Safe Cryptography, Caliptra Root of Trust for Measurement (RoTM) emulation, an embedded physical unclonable function (PUF), as well as many architectural improvements, such as larger memory space and 64-bit addressing support.

Rambus logo