Home > Security IP > Root of Trust Solutions
To provide a hardware-based foundation for security, Rambus offers a broad range of robust Root of Trust and eHSM solutions, ranging from programmable security co-processors with features such as Quantum Safe Cryptography (QSC) to highly compact, firmware-controlled designs. The Rambus CryptoManager™ IP family is ideal for integration in complex gateways and cloud applications where multiple hosts need to access and leverage services provided by the root of trust. The Rambus RT-100 Root of Trust IP family targets secure IoT and MCU designs.
Rambus offers a dedicated security and root of trust IP solution for virtually any application, including data centers, AI/ML processing, automotive, and Internet of Things (IoT) devices.
On this episode of Ask the Experts, we chat with Parvez Shaik about the latest developments in security and the concept of the root of trust. Watch this video to learn about the importance of addressing supply chain vulnerabilities, the advantages of a hardware root of trust, and the new features of the third-generation CryptoManager Root of Trust products.
The CryptoManager RT-6xx v3 Root of Trust (CMRT) family from Rambus is the latest generation of fully programmable FIPS 140-3 compliant hardware security cores offering Quantum Safe security by design for data center and other highly secure applications. The RT-6xx allows customers to develop secure and trusted applications that run securely within a trusted boundary. Secure applications can be assigned unique roots and keys, allowing independent permissions and access levels.
For Automotive-grade HSM, click here.
| Product | Product Configurations and Cryptographic Accelerators Supported |
|---|---|
| Baseline for all RT-6xx/16xx | Rambus secure RISC-V processor, NIST CMVP compliant (incl dedicated certified SKU), SESIP/PSA certified, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG, classic and LMS and XMSS boot flow. FIPS 140-3/SESIP/PSA RoT. Secure Boot, Debug, FOTA. Secure, firewalled, in-core processing. Multi-layered security model. Secure lifecycle management. Secure data store. Secure provisioning. Select Quantum Safe SKUs provide a full quantum safe boot flow, and supports ML-KEM, ML-DSA, SLH-DSA, LMA, XMSS. |
The automotive-grade CryptoManager RT-7xx v3 Root of Trust family from Rambus is the next generation of fully programmable ISO 26262 and ISO 21434 compliant hardware security modules offering Quantum Safe security by design for secure automotive applications supporting AutoSAR, EVITA full and SHE+. The RT-7xx allows customers users to develop secure and trusted applications that run securely within a trusted boundary. Secure applications can be assigned unique roots and keys, allowing independent permissions and access levels. The RT-76xD is industry’s first ASIL-HSM. The first-generation RT-640 with its ISO 26262 ASIL-B certificate is also part of this family.
| Product | Product Configurations and Cryptographic Accelerators Supported |
|---|---|
| Baseline for all RT-7xx/RT-64x | Automotive-grade HSM. NIST CMVP compliant, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG, classic and LMS and XMSS boot flow. ISO 21434/26262 HSM. Secure Boot, Debug, FOTA. Secure, firewalled, in-core processing. Multi-layered security model. Secure lifecycle management. Secure data store. Secure provisioning. Select Quantum Safe SKUs provide a full quantum safe boot flow, and supports ML-KEM, ML-DSA, SLH-DSA, LMA, XMSS. |
Designed to be integrated in power and space-constrained SoCs or FPGAs, the RT-100 and RT-200 Root of Trust families (formerly VaultIP) include SESIP and PSA certified, FIPS 140-2 and FIPS 140-3 certified hardware security modules that guard the most sensitive assets on chips and establish the foundation for platform security.
Featuring a firmware-controlled architecture with dedicated secure memories, the RT-100/200 families provide a variety of cryptographic accelerators including AES, SHA-2, RSA and ECC. Ideal for power and space-sensitive applications like Secure MCUs, IoT servers, gateways and edge devices, the RT-100/200 families offer the best balance of size and performance available on the market.
| Product | Product Configurations and Cryptographic Accelerators Supported |
|---|---|
| Baseline for all RT-1xx/2xx | NIST CMVP certified/compliant, SESIP/PSA certified, NIST CAVP hardware classic cryptographic accelerators (AES, SHA-2, SHA-3, RSA, ECC), a NIST certified TRNG. Secure Boot, Secure Debug, Secure Asset Store. |
This latest generation of the Rambus RT-600 Root of Trust IP offers many new features designed to support the security needs of customers today and into the future. These features include Quantum Safe Cryptography, Caliptra Root of Trust for Measurement (RoTM) emulation, an embedded physical unclonable function (PUF), as well as many architectural improvements, such as larger memory space and 64-bit addressing support.
