TrustCore
Continuous hardware trust, manufacture to retirement
Hardware root of trust on every Nelix die: PUF identity, measured boot, tamper monitoring, and signing authority for attestation across the deployed life of the device.
Semiconductor die macro
- Derived key
- Array cell
- Light = derivation, one direction only
Read the architecture
Each state is entered explicitly, failure is a defined transition rather than an absence, and what is drawn is specified rather than measured.
- Ordered step
- Only exit
- Current stage
- Reject path
- Light = hand-off and measurement
What holds, and why
-
PUF-derived identity
Identity from die physics. Invasive attack disturbs the structure it depends on
-
Measured boot
Every stage measured; monotonic counters block withdrawn firmware
-
Active tamper response
Suspect state cannot return to service without authenticated remediation
-
Attestation on demand
Operator can request a signed state report at any point, not only at boot
Specification
Pre-silicon. Architecture specified; RTL in progress; FPGA next. Figures are design targets, not measured silicon results.
| Status | RTL in progress |
|---|---|
| Identity source | Physical unclonable function, per-die |
| Key storage | No stored private key material |
| Boot | Measured, with monotonic anti-rollback |
| Cryptography | Post-quantum and classical, HW-accelerated |
| Tamper | Active mesh, sensors, key zeroisation |
| Update | Signed, staged, offline-queueable |
- Device identity
- Measured boot chains
- Result attestation
- Tamper response
- Cryptographic retirement
Talk to the design team
The specification is still open to review.