Authentication IC with cloud-based credential service, in-field provisioning and secure updates

The Microchip ECC608 TrustMANAGER security solution combines a secure authentication IC with security software-as-a-service to enable self-service custom public key infrastructure, streamlined in-field provisioning and lifecycle management for IoT devices.

Microchip has added the ECC608 TrustMANAGER with Kudelski IoT keySTREAM software-as-a-service (SaaS) to its Trust Platform portfolio of devices, services and tools.  

 

The ECC608 TrustMANAGER security solution gives designers of IoT products a more efficient way of managing devices once products are with customers. The security solution enables custom cryptographic credentials to be accurately provisioned at the end point without requiring supply-chain customization. It also allows the end user to manage their security credentials.  

 

When security credentials are managed and updated in the field via keySTREAM, instead of being limited to a static certificate chain implemented during manufacturing, the benefit is a device-to-cloud solution for securing key assets end-to-end in an IoT ecosystem throughout a product lifecycle. 

 

The ECC608 TrustMANAGER solution consists of a secure authentication IC, the Microchip ECC608, which stores and protects cryptographic keys and certificates, and the keySTREAM SaaS for key management. The combined silicon component and key management SaaS allow the user to set up a self-serve root certificate authority, and the associated public key infrastructure (PKI) secured by Kudelski IoT. This means that users can create and manage a dynamic certificate chain and provision devices in the field the first time that they are connected.  

 

Once claimed in the SaaS account, the devices are automatically activated in the user’s keySTREAM service via in-field provisioning. 

 

Developers can get started with the ECC608 TrustMANAGER by downloading the Trust Platform design suite from microchip.com and testing the keySTREAM use case under the ECC608 TrustMANAGER. 

Features

  • Custom PKI set-up 
    • Root certificate authority creation 
    • Self-service PKI 
    • Protection with IT-grade hardware security modules 
    • Cost-effective managed PKI 
  • Automated device onboarding 
    • Bulk upload of certificates with one click 
    • In-field provisioning  
  • Certificate management  
    • Expiration date 
    • Rotation 
    • Revocation 
    • Renewal 

Applications

  • Industrial equipment 
  • Medical devices 
  • Automotive systems 
  • Access control systems 
  • Consumer electronics 
Extra_FTMIssue62024_Microchip_ECC608TrustMANAGERSecuritySolution

Evaluation Kit

Part supported: ECC608 

Kit part number: EV10E69A 

The CryptoAuth Trust Manager kit from Microchip works with the Kudelski IoT software-as-a-service (SaaS) to offer public key infrastructure (PKI) service and in-field provisioning.   

 

The board contains the ECC608-TMNGTLS Trust Manager, which is a pre-provisioned variant of the ECC608 secure authentication IC. The ECC608-TMNGTLS will work in combination with the keySTREAM SaaS from Kudelski IoT. The device comes pre-provisioned with a set of cryptographic keys to connect to the keySTREAM SaaS.   

 

When deployed, the IoT device containing the ECC608-TMNGTLS will connect to the keySTREAM SaaS, which will give ownership of the IoT device to the intended owner by provisioning the device in the field with its custom PKI, symmetric keys, and/or data. 

 

The CryptoAuth Trust Manager kit consists of the ECC608-TMNGTLS, a Microchip ATSAMD21E18A as the main microcontroller, an onboard debugger, and a user-defined switch and user-defined LEDs.   

 

The main MCU comes pre-programmed with the Microchip Security and Computing Group (SCG) kit protocol. This protocol handles communication between the CryptoAuthentication devices and the host MCU over a USB interface.  

 

Various Microchip components can be used in conjunction with the EV10E69A board, including the ECC204, ECC206, SHA104, SHA105, SHA106, TA010, TA100 and TA101, by inserting the appropriate mikroBUS board into the mikroBUS header of the DM320118 board. 

 

FTM Board Club

Sign up for access to exclusive development boards, an essential tool for many innovative design projects.

*Available to pre-qualified EMEA customers only.

Related Articles

STMicroelectronics — STSAFE-A110 Secure Element
This STSAFE-A110 Secure Element by STMicroelectronics provides a certified solution for asset authentication...
Read More
Susumu — RG and URG Series Resistors
RG and URG series resistors from Susumu maintain tight tolerance in challenging conditions, including...
Read More
I-PEX — MHF I LK and MHF 4L LK Micro-RF Connectors
I-PEX has introduced the first micro-RF connectors to include a locking feature to increase retention...
Read More

Subscribe to our newsletters

Subscribe to Future Electronics

Get access to the latest product information, technical analysis, design notes and more

Choose your region