Home / Portfolio / Security IP

Security IP — trust rooted in the silicon.

Protect your device from the silicon up with hardware root-of-trust, crypto coprocessors, and PUF-based security IP — the foundation for secure boot, key management, and post-quantum-ready protection in your SoC.

Hardware security, built in from the start

Security that is added late is security that can be broken. Neurizen AI helps you embed a hardware root of trust directly into your chip — a trusted foundation that establishes device identity, protects keys, and anchors every higher-level security function in tamper-resistant hardware.

Our security IP portfolio gives fabless teams silicon-proven building blocks for confidentiality, integrity, and authentication, without having to develop cryptographic hardware from scratch — reducing risk, cost, and time-to-market on the road to tapeout.

What it enables

  • Hardware Root of Trust — unique device identity (UID), true random number generation (TRNG), and secure key storage.
  • Crypto acceleration — symmetric and asymmetric ciphers, hashing, and key derivation for secure boot, TLS and OTA updates.
  • Anti-tamper — attack-resistant design protecting keys against physical and side-channel attacks.
  • Post-quantum ready — a foundation designed to evolve toward PQC as standards mature.
Featured partner · PUFsecurity

PUF-based security, from root of trust to crypto

Neurizen AI offers security IP from PUFsecurity, a specialist in PUF-based hardware security built on the patented NeoPUF technology. Their solutions turn each chip's inherent physical randomness into an unclonable identity and root key — a strong, cost-efficient hardware root of trust.

  • PUFrt — hardware root-of-trust module combining a chip-unique UID, TRNG, secure OTP (NeoFuse) and an anti-tamper shell.
  • PUFcc — a crypto coprocessor that builds on PUFrt and adds a full crypto engine, DMA and XiP for secure boot, TLS and key management.
Riscure CertifiedARM EndorsedCorstone Ready PSA Level 3 / SESIP 3NIST CertifiedOSCCA Certified

Certifications and endorsements are PUFsecurity's, for the PUFrt and PUFcc IP.

PUFsecurity IP portfolio

From root of trust to a complete security subsystem.

Two building blocks anchor the portfolio: PUFrt establishes the hardware root of trust, and PUFcc extends it into a full crypto coprocessor with a secure enclave for external flash.

PUFsecurity IP portfolio — PUFrt Hardware Root of Trust and PUFcc Crypto Coprocessor block diagrams
PUFsecurity IP portfolio — PUFrt (Hardware Root of Trust) and PUFcc (Crypto Coprocessor). Courtesy of PUFsecurity.

PUFrt — Hardware Root of Trust

PUFrt is a Corstone-ready hardware root of trust that pairs a secure sub-system Crypto Engine with a NeoPUF-based core — OTP (NeoFuse), PUF and TRNG behind a controller — connected to the SoC over APB. It gives every chip an unclonable identity and protected key storage as the foundation for the whole security architecture.

PUFcc — Crypto Coprocessor

PUFcc builds on PUFrt (OTP / PUF / TRNG) and adds anti-tampering, a crypto engine and DMA, plus an execute-in-place (XiP, AES-XTS) path and flash controller that extend the secure boundary to external NOR and NAND. It connects over APB and AXI / AHB and is positioned as a CC312-equivalent secure subsystem.

PUFsecurity one-stop-shop total security solution — hardware to software stack
One-Stop-Shop total solution — a complete security design from hardware to software. Courtesy of PUFsecurity.

The IP is delivered as a complete hardware-to-software solution: PUFrt / PUFcc firmware and APIs at the HAL, integration with PSA / TF-A / TF-M and Linux drivers, and reference secure-boot code plus a device on-boarding application. It works alongside third-party crypto software such as MbedTLS, OpenSSL and WolfSSL, supports cloud provisioning, TLS and PUF-based key generation, and ships with a host toolkit (Sign Tool, Secure Debug and OTP generator) — shortening the path from design to a secure, production-ready device.

Where it fits

Security for connected silicon.

IoT & edge devicesAutomotiveEdge AISecure bootKey managementDevice identityAnti-tamperTLS / OTAPost-quantum cryptography