Root of Trust IP

Protecting data at rest

Secure Programmable and Firmware-Controlled Root of Trust IP

Providing a hardware-based foundation for security, Rambus offers a portfolio of robust Root of Trust eHSM solutions, ranging from feature-rich programmable security co-processors with Quantum Safe Cryptography and side-channel attack (SCA) protection to highly compact, firmware-controlled designs. With a breadth of solutions applicable from the data center to Internet of Things (IoT) devices, Rambus has a Root of Trust IP solution for almost every application.

Secure Programmable Root of Trust IP

Solution Product Brief Applications
RT-630 Download the Root of Trust RT-63x family Product Brief Semiconductor, cloud and edge AI security
RT-631 Download the Root of Trust RT-63x family Product Brief Semiconductor, cloud and edge AI security, requiring Chinese Cryptography
RT-632 Download the Root of Trust RT-63x family Product Brief Semiconductor, cloud and edge AI security, requiring IoT Cryptography
RT-634 Download the Root of Trust RT-63x family Product Brief Semiconductor, cloud and edge AI security, requiring Quantum Safe Cryptography
RT-640 Download the Root of Trust RT-64x family Product Brief Automotive ISO-26262 ASIL-B embedded Hardware Security Module
RT-641 Download the Root of Trust RT-64x family Product Brief Automotive ISO-26262 ASIL-B embedded Hardware Security Module requiring Chinese Cryptography
RT-650 Download the Root of Trust RT-65x family Product Brief Highly-secure government applications requiring DPA resistance
RT-651 Download the Root of Trust RT-65x family Product Brief Highly-secure applications requiring DPA resistance with Chinese encryption
RT-654 Download the Root of Trust RT-65x family Product Brief Highly-secure government applications requiring DPA resistance with Quantum Safe Cryptography
RT-660 Download the Root of Trust RT-66x family Product Brief Data center and highly-secure applications requiring DPA & FIA resistance
RT-661 Download the Root of Trust RT-66x family Product Brief Data center and highly-secure applications requiring DPA & FIA resistance with Chinese Cryptography
RT-664 Download the Root of Trust RT-66x family Product Brief Data center and highly-secure applications requiring DPA & FIA resistance with Quantum Safe Cryptography
RT-700 Automotive ISO-26262 ASIL-D embedded Hardware Security Module
RT-1660 Download the Root of Trust RT-1660 Product Brief Highly-secure defense applications requiring DPA & FIA resistance
RT-630-FPGA Download the Root of Trust for FPGAs Product Brief FPGA-specific implementation of the RT-630
RT-660-FPGA Download the Root of Trust for FPGAs Product Brief FPGA-specific implementation of the RT-660
RT-600 SDK Download the Root of Trust CSDK Product Brief SDK for RT-6xx secure application development

CryptoCell™ and CryptoIsland™ Root of Trust IP

SolutionProduct BriefApplications
CC-312Download the Root of Trust CC-312 Product BriefArm Cortex®-M TrustZone®-based IoT edge devices and sensors
CC-712Download the Root of Trust CC-712 Product BriefArm Cortex-A TrustZone-based IoT servers and gateways
CC-713Download the Root of Trust CC-713 Product BriefArm Cortex-A TrustZone-based IoT servers and gateways for the Chinese market
CI-300P-CContact Rambus for product informationSecure Element devices such as iSIM, 5G modems, mobile app processors

Firmware-Controlled Root of Trust IP

SolutionBriefApplications
RT-120Download the Root of Trust RT-100 Product BriefIoT clients and sensors
RT-121Download the Root of Trust RT-121 Product BriefIoT clients and sensors for the Chinese market
RT-130Download the Root of Trust RT-130 Product BriefIoT servers, gateways, edge devices and sensors
RT-131Download the Root of Trust RT-131 Product BriefIoT servers, gateways, edge devices and sensors for the Chinese market
RT-260Download the Root of Trust RT-260 Product BriefSecure MCU-based devices and sensors

Secure Programmable Root of Trust IP

The Rambus Root of Trust RT-600 family of fully programmable FIPS 140-3 compliant hardware security cores offers security by design for data center, AI/ML, automotive, government, defense, as well as general purpose semiconductor applications. The RT-600 family protects against a wide range of hardware and software attacks through state-of-the-art anti-tamper and security techniques, as well as Quantum Safe Cryptography to protect hardware and data in the quantum computing era.

FeatureDescriptionRT-63xRT-64xRT-65xRT-66xRT-1660
Application FocusExample Applications Data Center/AI/MLAutomotiveGovernmentHighly Secure ApplicationsDefense
FIPS 140-3NIST CAVP Compliant
FIPS 140-3NIST CMVP Compliant
FIPS 140-3NIST CMVP Certified
FIPS 140-2NIST CMVP Certified 
DPADPA ResistanceRSA/ECCRSA/ECC
FIAFIA Resistance
AutomotiveISO26262 ASIL LevelRT-640 & RT-641: ASIL-B
RT-645: ASIL-D
Key DeriveSecure Key Derivation
Key AgreementECDH, DH
Key TransportKey Wrap Mechanisms
RootsMultiple Roots/Key Splits4/84/88/88/88/8
Caliptra RoTMWith DICE and X.509 SupportOptionalOptionalOptional
Secure BootSecure Boot Assist P-512P-256
Secure DebugSecure Debug P-512P-256
Secure LifecycleLifecycle Stage Management
Secure FeatureFeature and SKU Management
Secure Data StoreSecure Data Store
Anti TamperPower and Clock Glitch Monitor
Memory ECCMemory Error Correction
Quantum Safe CryptoCRYSTALS-Kyber/-Dilithium
XMSS/LMS Stateful Hash Signature
RT-634 onlyRT-654 onlyRT-664 only
Quantum Safe CryptoXMSS/LMS Stateful Hash SignatureOptional for RT-630Optional for RT-650Optional for RT-660
PerformanceCrypto & Hash Performance Gbps66366
I/O busAXI or AHB AMBA Interface
OTPAPB OTP Management Interface
PUFPUF Interface
DPARSA & ECC DPA Resistances
DPAAES DPA Resistance
DPAHMAC-SHA-2 DPA Resistance
FIARSA & ECC & AES FIA Resistance
TRNGTrue Random Number Generator
SP800-90A/B/C
RSAHW Accelerators 4K (up to 8K)
ECCHW Accelerators 521
ECC CurvesNIST-Brainpool-(Ed)25519-(Ed)448
AESHW Accelerators
AESCBC-CTR-CCM-CMAC-CFB-OFB
GCM-GMAC Mode
AESXTS Mode
SM2-3-4HW Accelerators
SHA-2(HMAC-)SHA-2 Accelerators
SHA-2(HMAC-)SHA-2 Max Mode512512512512512
SHA-3(HMAC-)SHA-3 Accelerators
SHA-3(HMAC-)SHA-3 Max Mode512512512512512
CPPChaCha Poly AcceleratorsRT-632 onlyOptionalRT-662 only
WhirlpoolHW AcceleratorsOptionalOptional
3DESHW AcceleratorsOptional

CryptoCell and CryptoIsland Root of Trust IP

Designed to be integrated in Arm TrustZone-based power and space-constrained SoCs or FPGAs, the CC-312, CC-712, and CC-713 Root of Trust solutions (formerly Arm CryptoCell) are FIPS 140-3 certifiable hardware security modules that establish the foundation for the Arm Platform Security Architecture (PSA). The CC-312 targets integration on Cortex-M platforms running embedTLS, and the CC-71x targets integration on Cortex-A platforms running Linux or OP-TEE. 

The CryptoIsland CI-300P-C (formerly Arm CryptoIsland) is a secure programmable Root of Trust targeting Secure Element designs for iSIM, payment, DRM, and 5G modems. It is comprised of an embedded Cortex-M0+ processor and a tailored CryptoCell engine. The CryptoIsland is suitable for designs that target evaluation against Common Criteria PP-0084 or PP-0117. 

FeatureDescriptionCC-312CC-712CC-713CI-300P-C
Application FocusExample ApplicationsIoT SensorIoT GatewayIoT Gateway (CN)Secure MCU
FIPS 140 140-2NIST CAVP Compliant
FIPS 140 140-2NIST CMVP Compliant 
Common CriteriaCC EAL4+ PP-0084 / PP0117
DPARSA & ECC & AES DPA Resistance
Key DeriveSecure Key Derivation
Key AgreementECDH, DH
RootsMultiple Roots/Key Splits2221
Secure BootSecure Boot Verify RSA3K P256
Secure BootSecure Boot Verify ECDSA P-384/P-512
Secure DebugSecure Debug
TRNGTrue Random Number Generator
SP800-90A/B/C
RSA-ECCHW Accelerators
AESHW Accelerators
AESCBC-CTR-CCM-CMAC Mode
AESGCM-GMAC ModeOptional
AESXTS Mode
SM2-3-4HW Accelerators
SHA-2(HMAC-)SHA-2 Accelerators
SHA-2(HMAC-)SHA-2 Max Mode512512512512
SHA-3(HMAC-)SHA-3 Accelerators
SHA-3(HMAC-)SHA-3 Max Mode
CPPChaCha Poly AcceleratorsOptional
ARIAHW Accelerators
3DESHW AcceleratorsOptionalOptional
PerformanceCrypto & Hash Performance Gbps1221
I/O BusAXI or AHB AMBA Interface
OTPTCM OTP Management Interface

Firmware-Controlled Root of Trust IP

Designed to be integrated in power and space-constrained SoCs or FPGAs, the RT-100 and RT-200 Root of Trust families (formerly VaultIP) include SESIP and PSA certified, FIPS 140-2 certified, and FIPS 140-3 compliant hardware security modules that guard the most sensitive assets on chips and establish the foundation for platform security.

Featuring a firmware-controlled architecture with dedicated secure memories, the RT-100/200 families provide a variety of cryptographic accelerators including AES, SHA-2, RSA and ECC. Ideal for power and space-sensitive applications like Secure MCUs, IoT servers, gateways and edge devices, the RT-100/200 families offer the best balance of size and performance available on the market.

FeatureDescriptionRT-120RT-130RT-131RT-260
Application FocusExample ApplicationsIoT SensorIoT GatewayIoT Gateway (CN)Secure MCU
FIPS 140-3NIST CAVP Compliant
FIPS 140-3NIST CMVP Compliant
FIPS 140-2NIST CAVP and CMVP Certified
SESIPLevel 2 Certified
PSACertified Level 2 RoT Component
DPARSA & ECC & AES DPA Resistance
Key DeriveSecure Key Derivation
Key AgreementECDH, DH
Key TransportKey Wrap Mechanisms
RootsMultiple Roots/Key Splits1111
Secure BootSecure Boot Assist P-256
Secure DebugSecure Debug P-256
TRNGTrue Random Number Generator
SP800-90A/B/C
RSA-ECCHW Accelerators
AESHW Accelerators
AESCBC-CTR-CCM-CMAC Mode
AESGCM-GMAC-XTS Mode
SM2-3-4HW Accelerators
SHA-2(HMAC-)SHA-2 Accelerators
SHA-2(HMAC-)SHA-2 Max Mode256512512512
SHA-3(HMAC-)SHA-3 AcceleratorsOptionalOptionalOptional
SHA-3(HMAC-)SHA-3 Max Mode512512512
CPPChaCha Poly AcceleratorsOptionalOptional
ARIAHW AcceleratorsOptionalOptional
3DESHW AcceleratorsOptionalOptional
PerformanceCrypto & Hash Performance Gbps1222
I/O BusAXI or AHB AMBA Interface
OTPTCM OTP Management Interface

RT-600 Root of Trust Series A New Generation of Security Anchored in Hardware

Download RT-600 Root of Trust Series: A New Generation of Security Anchored in Hardware

This latest generation of the Rambus RT-600 Root of Trust IP offers many new features designed to support the security needs of customers today and into the future. These features include Quantum Safe Cryptography, Caliptra Root of Trust for Measurement (RoTM) emulation, an embedded physical unclonable function (PUF), as well as many architectural improvements, such as larger memory space and 64-bit addressing support.

Rambus logo