Skip to main content
COMPUTE

Trusted compute for constrained infrastructure

Nelix designs compute systems for sites where power, connectivity and physical access are unreliable. The work today is architecture, RTL and FPGA validation. Production silicon is a longer-term direction, not a current product.

Pre-silicon RTL in progress FPGA next
Horizon
Architecture and RTL now
Validation
FPGA path
Silicon
Not shipping
Trust domain Trusted compute
Nelix trusted compute domain Floorplan with four nested planes: board domain, package, die, and a central trust island for device identity, measurement and signing. Compute, memory, sensor I/O, metrology, crypto and telemetry route into a ring bus. Only signed data leaves through an attestation export port. Board domain Package Die Die extent Package extent Compute Bounded array Memory Measured store I/O phy Sensor ingress Metrology Sense & sample Crypto Sign & seal Telemetry Signed export Ring bus Trust island Root of trust Key slots Identity · measure · sign Port signed Attestation export Nothing else crosses
  • Trust boundary
  • Supporting logic
  • Signed data in flight
Platform trust architecture · design intent
Identity Device identity
Per-die cryptographic identity from a PUF A conceptual die floorplan. A physical unclonable function array on the left holds entropy created by manufacturing variation, unique to a single die. Its outputs converge through a one-way conditioning block into a root key, which is never stored. A key ladder derives an identity certificate key, an attestation quote key, a sealing key and a link session key. Only signatures leave the die; no key material is exported. Die boundary Puf macro Puf array Per-die entropy Manufacturing variation No two dies respond alike One-way Irreversible Key ladder Identity cert Names the die Attestation key Signs quotes Sealing key Binds data at rest Session key Protects the link Signatures out Key material never crosses this line Identity path
  • Derived key
  • Array cell
  • Light = derivation, one direction only
Identity comes from the die itself: the root key is reconstructed when needed and never written down.
Device identity and trust boundary · design intent
POSITION

Hardware first. Cloud assumptions last.

Edge and infrastructure compute must keep working when the link drops and the supply sags. That is a hardware problem first.

Trust belongs in the package: identity, measured boot and attributable results, not only in software wrappers after the fact.

Nelix has not fabricated production silicon. Platform pages describe architecture and engineering status: Research, Prototype or In Development.

OPERATING CONSTRAINTS

Conditions the architecture must absorb

  1. Intermittent power

    Safe power-down and resume from non-volatile state.

  2. Sparse connectivity

    Local execute, measure and verify. No cloud dependency.

  3. Thermal extremes

    Passive operation planned into the floorplan, not bolted on.

  4. Physical tamper

    Die-level monitoring with cryptographic response.

  5. Long service life

    Trust and maintenance sized for decades in the field.

FOCUS

Where the compute work sits

  1. Edge and infrastructure compute

    Architectures sized for metering, remote sites, industrial monitoring and other unattended equipment.

  2. Hardware trust

    Per-device identity, measured boot, attestation and result binding specified into the system, not added later.

  3. FPGA and pre-silicon path

    Prototypes and RTL validation before any tape-out decision. Figures on this site are design targets, not measured silicon.

Discuss compute requirements

Design services and research collaboration are open now. Platform work remains pre-silicon.