This technology is developed through expert custom silicon design: IIST engineers security circuits that semiconductor teams can integrate into their own chips.

01Physical entropy

One cell design.
A unique physical response.

Microscopic differences in manufactured transistors and wiring create device-specific electrical behavior. IIST measures a logic-based PUF cell and maps its response into stable and changing digital states.

Logic PUF latch cell with stimulus and output states
01Stimulate the cell

A trigger initiates a measurement of the physical circuit.

Repeated PUF cell measurements accumulating statistics and states
02Collect statistics

Repeated measurements reveal each cell’s behavior.

Digital patterns showing stable zero and one states alongside variable X states
03Map digital states

Stable patterns support key recovery; changing states supply random entropy.

Stable component

Input to ACC for root-key generation and recovery.

Dynamic component

Physical entropy for true random seeds and repeated reseeding.

02Dynamic PUF

Available beyond
the power cycle.

IIST’s entropy source uses logic gates in a latch cell measured by an impulse or clock-like trigger. The same source can be sampled again throughout the device lifecycle.

Its combination of relatively steady behavior and physical randomness supports both recovery of existing roots and generation of new random seeds.

Logic-cell entropy source repeatedly measured by a clock-like stimulus
Dynamic PUF engine accepts checkpoint data and provides multiple root-key outputs and true-random output from a common entropy source
One reusable entropy source supports root-key recovery and true random output.
Conceptual ACC curves for different chips converging to device-specific points
Conceptual curves illustrate device-specific relationships, not literal mathematical plots.

03Attestation Curve Cryptography

Recover the same root.
Create independent roots.

ACC acts as a proprietary fuzzy-extraction method. It combines mathematical curves with the measured PUF response to recover the uniquely associated root key, despite variation in individual measurements.

  1. Generate

    Create checkpoint data associated with a root key.

  2. Recover

    Reload the checkpoint and measure the PUF again to recover that root.

  3. Bind

    Incorporate external inputs such as a password or chip identifier into the recovery relationship.

04Multiple roots of trust

Independent roots.
Independent responsibilities.

A root of trust anchors cryptographic keys. When all domains depend on one master key, compromise of that root can affect every dependent domain. Dynamic PUF supports separate roots from the same entropy source.

Single-root architecture

One root key
System security
Boot & firmware
Maintenance
OEM & ODM
Applications

All domains depend on the same root.

IIST Dynamic PUF

One physical entropy source
Root 1System security
Root 2Boot & firmware
Root 3Maintenance
Root 4OEM & ODM
Root 5Applications

Each domain has its own cryptographic root and lifecycle.

Designed for real silicon

Built for the device lifecycle.

No permanent root-key storage

Recover root keys when required using the physical entropy source and associated checkpoint data.

Independent trust domains

Give system, firmware, maintenance, OEM and applications separate cryptographic roots.

Repeatable measurement

Trigger the logic-cell entropy source throughout the lifecycle, independently of power cycles.

True-random reseeding

Use the changing component of the physical response for random seeds and DRBG reseeding.

External binding

Bind root-key recovery to an external password, chip identifier or ownership relationship through ACC.

Process portability

Port the logic-based cell to a target process while retaining the process-independent ACC method.

How the pieces fit

PUF, PQC and zero trust.

PUF: the hardware root

Device-specific keys and entropy give cryptographic operations a physical foundation.

PQC: the algorithms

Post-quantum key establishment and signatures address the cryptographic layer. Support depends on the selected implementation.

Explore SASP options ↗

Zero trust: the architecture

Verify users, devices and operations through explicit access policies, supported by hardware identity.

Explore integration ↗

Start a conversation

Discuss the root of trust your platform needs.

Tell us what you are securing. We will map the right path from evaluation hardware to customized silicon IP.