Decoding the world of cybersecurity

·

Fraunhofer validates RISC-V security platform

Fraunhofer AISEC has completed silicon validation of a RISC-V secure-element platform and is making the OpenTitan-based design available as licensable intellectual property.

Fraunhofer validates RISC-V security platform
Summary
  • Fraunhofer says its RISC-V secure-element silicon prototype has passed functional validation.
  • The platform includes root-of-trust, secure boot, key storage, device identity, authentication, and firmware-update functions.
  • The design is moving into licensing for integration into SoCs, ASICs, and chiplets.

Fraunhofer AISEC has moved a European secure-element design from prototype validation into technology transfer, making the hardware platform available for integration into custom chips and connected products.

Fraunhofer said on 28 September that the silicon prototype of its RISC-V Secure Element has completed functional validation and is now available as licensable intellectual property for systems-on-chip, application-specific integrated circuits, and chiplets.

The platform is based on OpenTitan and places several core security functions directly into silicon, including a hardware root of trust, secure boot, secure key storage, device identity, authentication, and protected firmware updates.

Moving those functions onto the chip is intended to reduce reliance on separate security components and make trust controls part of the underlying hardware architecture. Fraunhofer says the approach can reduce component count and board space while allowing security functions to be adapted to performance, power, and silicon-area requirements.

The project has relevance beyond semiconductor design because European product-security rules are increasingly pushing security decisions earlier into development. The Cyber Resilience Act creates lifecycle expectations for products with digital elements, including vulnerability management and secure design requirements that cannot always be added effectively after hardware choices have been fixed.

A hardware root of trust can provide a foundation for determining whether firmware is authentic, protecting device secrets, establishing identity, and controlling how software updates are accepted. It does not make a system secure on its own, but weaknesses at that layer can undermine security controls above it.

Fraunhofer is positioning the technology for environments including industrial automation, medical technology, telecommunications, energy infrastructure, IoT, and edge computing. Those are sectors where devices can remain deployed for many years and where replacing hardware after a security problem emerges can be significantly harder than updating conventional enterprise software.

The platform’s RISC-V basis also feeds into a wider European effort around supply-chain control and technological sovereignty. Open instruction-set and open-hardware ecosystems can reduce dependence on proprietary architectures in some areas, although actual sovereignty still depends on implementation, manufacturing, tooling, intellectual property, and the broader component chain.

The secure element was developed through collaboration involving Fraunhofer AISEC, Fraunhofer EMFT, and Fraunhofer IIS under the Trusted Electronic Bayern centre. Fraunhofer is now offering the design as a complete solution or as individual IP blocks, with integration support and collaborative development available.

Successful functional validation is not the same as certifying every product that may eventually incorporate the technology. Manufacturers integrating the platform will still need to address their own system architecture, firmware, supply chain, lifecycle support, and regulatory obligations.

The transition into licensing nevertheless marks the point at which the work can move from research hardware into commercial designs. As connected-product regulation becomes more prescriptive, access to verified security building blocks could influence how manufacturers balance development time, component sourcing, and security requirements at the silicon level.

×