nQrux® Root of Trust
nQrux® Root of Trust IP core establishes device identity, protects cryptographic keys, and anchors Secure Boot for ASICs, SoCs, and FPGAs.
Root of Trust is the component in a computing system that everything else relies on for establishing trust between components and performing critical security operations. It must be immutable, so that attackers cannot alter its contents or behaviour. It stores cryptographic keys and performs operations with them, for example verifying the authenticity of firmware during system boot.
Secure Boot, firmware updates, device identity, and secure communication all rely on the trust and security foundation built on the Root of Trust. If the Root of Trust is weak or compromised, none of them hold.
No embedded CPU or firmware
No processor, firmware, bootloader or operating system to integrate, update or maintain. Eliminates the software stack attack surface.
Fast track to secure hardware foundation
Easy-to-integrate IP reduces development effort and lead times. It lets your R&D focus on product features and innovation.
Post-quantum Root of Trust
Device identity is established using built-in hardware-based post-quantum cryptography for quantum resilience.
Smaller footprint on silicon
Streamlines logic and memory utilisation while providing comprehensive Hardware Root of Trust functionality.
Solution benefits
- Trust anchor. Upper architecture layers inherit its security and rely on it as the foundation of system trust.
- No processor. Pure digital logic, no CPU, no software, a smaller attack surface.
- Small and low power. Less to verify, smaller silicon and power consumption
- Keys stay isolated. Ephemeral keys in RAM, long-term keys in NVM, each user accessing only their own.
- Protected interfaces. Optional AES256-GCM encryption against eavesdropping, manipulation, and replays.
- Modern cryptography. AES-GCM, elliptic curve cryptography, SHA-3, as well as quantum-resilient PQC algorithms.
- Easy to integrate. A 32-bit mailbox interface, configurable memory.
Key features
Cryptographic operations
- Key generation / derivation
- Diffie-Hellman key exchange
- ML-KEM key encapsulation/decapsulation
- Symmetric encryption
- Hashing
- Message authentication
- Signature generation/verification
User and data management
- Users: Admin vs. Regular
- User-specific memory space (RAM + NVM)
- Slot-based storage with permission and usage policies for data and keys
- Commands via encrypted and authenticated Mailbox interface

Device identity in hardware for...
IoT and industrial automation
Space and satellite systems
AI infrastructure
Data centers and edge
Defence and mission-critical
Product brief
Learn more about the key features and functionalities of nQrux® Root of Trust IP cores.
Blog: Why Hardware Root of Trust Matters
Read why Hardware Root of Trust is becoming essential for modern computing systems and how it provides the trusted foundation needed to secure devices throughout their lifecycle.

Discuss your requirements
FAQ
What is a root of trust?
An immutable component that stores cryptographic keys and performs cryptographic operations with them. It is the trust anchor that the rest of the system depends on.
How is it different from a software or CPU-based root of trust?
nQrux® Root of Trust is built from finite state machines in pure digital logic. There is no processor, firmware, bootloader or RTOS, so there is nothing to patch and no software for an attacker to run.
Which ASIC and FPGA technologies are supported?
The implementation is vendor agnostic and adaptable across FPGA architectures and ASIC processes.
How does it relate to nQrux® Secure Boot?
Both belong to the nQrux® family of Hardware Trust Engines. Root of Trust holds the keys and device identity that Secure Boot relies on when verifying firmware.
In what formats is the IP core delivered?
The IP core can be delivered as either encrypted or cleartext RTL, depending on your requirements. The delivery also includes test benches and comprehensive documentation.