What is a silicon root of trust?
The component a system's security ultimately depends on, placed in hardware so that device identity and boot integrity derive from the physical part rather than from software that could be replaced.
Hardware-anchored identity, a verified boot chain and cryptographic integration — completing inside the power a contactless field supplies, across the range of positions a card is actually presented at.
A smart card has to establish that it is genuine, protect credentials valuable enough to attack, and complete a transaction fast enough that a person holding it near a reader does not notice a delay — on power drawn from the reader's field.
Those requirements pull against each other. Cryptographic operations cost energy and time. Countermeasures against physical and side-channel attack cost more of both. The power available in a contactless field is fixed, modest, and varies with how the card happens to be held. Architecture is the only place that conflict can be resolved.
Identity is the foundational piece. A credential is only as trustworthy as the assurance that it lives on the hardware it was issued to, which is why the anchor is placed in silicon rather than asserted by software that could be replaced.
Stated as the customer stated them, before any of them had an answer. A challenge that is only described after it was solved is a description of the solution.
Contactless field power is what it is, and it changes with card position and orientation. The transaction must complete across that range, not only at the optimum.
Every countermeasure against physical and side-channel attack consumes part of the same budget the cryptographic operation needs.
Production test needs observability; a secure part must not offer observability to an attacker. Reconciling those has no generic answer.
Personalisation is where credentials enter the device, which makes the factory flow part of the security architecture rather than a manufacturing detail.
The anchor layer is the part that cannot be replaced later: identity derived from the physical die, and a first stage that is mask-programmed and therefore permanent. Everything above it inherits whatever assurance those two provide, which is why they are settled before anything else in the architecture.
The specific scope, rather than a capability list. Where a stage was shared with the customer’s team, it is described as shared.
Rarely the subsystem that sounds difficult. Written out because a reader facing the same programme gets more from this than from a summary of what went well.
Contactless power is limited and varies with position and orientation. The transaction has to complete across that whole range, which drove both the cryptographic implementation and the supply architecture.
Production test needs to see inside the part; a secure part must not let an attacker do the same. There is no generic answer, so this was designed specifically and reviewed as a security decision rather than a test one.
Personalisation is where credentials enter the device. Treating the factory flow as a manufacturing detail rather than an attack surface is a common and expensive error.
Embedded non-volatile memory availability, analog performance and a long supply horizon made a mature node correct here. It was a decision, not a fallback.
Hardware-anchored identity and a verified boot chain, integrated with cryptographic capability and taken through implementation to production transition.
Energy budgeting across field variation rather than at the optimum, so the card works as it is actually presented.
Credentials enter the device through a process that can be shown to be controlled, rather than trusted.
The same properties apply to secure microcontrollers, industrial controllers, IoT device identity and trusted edge hardware. Smart card is the most visible application, not the boundary.
Customer projects are presented at property, capability, outcome and integration level. Customer names, internal architecture, register maps, state machines and confidential deliverables are not disclosed. Where a figure would identify a customer or a design, it is omitted rather than approximated. More detail is available under a non-disclosure agreement, within the limits each customer has agreed.
Every item links to its own page, with characteristics, applications and the maturity status stated honestly for that item.
Silicon-rooted identity and secure boot.
TECHNOLOGYProperties, threat model and its boundary.
TECHNOLOGYThe verified chain in detail.
SOLUTIONThe commercial offering.
KNOWLEDGEWhy mature nodes suit secure silicon.
CAPABILITYFront end through physical implementation.
The component a system's security ultimately depends on, placed in hardware so that device identity and boot integrity derive from the physical part rather than from software that could be replaced.
Mechanism, circuit architecture and implementation detail are discussed under a non-disclosure agreement. Public material covers properties, threat model, integration and assurance — which is what a buyer needs to decide whether a conversation is worth having.
No, and claiming otherwise is the common error. It establishes that the running code is the code that was signed and that the device is what it claims to be. It says nothing about whether that signed code contains an application-layer vulnerability.
Embedded non-volatile memory availability, analog performance, mask cost and a long supply horizon all favour mature nodes for secure identity silicon. Digital density is not the binding constraint.
Written for engineers. Share it with one.
Tell us the specification, the constraint and the deadline. Programmes that cross silicon, radio, embedded and AI are where Faststream is strongest.