Embedded & Compact

Micro HSM Type-C

The most compact hardware root of trust for USB-C and embedded systems

Micro HSM Type-C · Embedded Root of Trust

Compact root of trust that keeps keys in hardware on USB-C and embedded boards.

Delivers a direct hardware root of trust with minimal deployment footprint. Cryptographic operations run in isolated hardware; keys never leave the chip.

USB-C Connection

Modern USB-C interface for fast integration and evaluation.

Embedded-Ready

Low-footprint fit for boards and embedded platforms.

Compact Form

Smallest hardware root-of-trust form for space-constrained systems.

Micro HSM Type-C hardware security module

Product Showcase

Micro HSM Type-C

Embedded root of trust

Key Features

High-Performance Cryptographic Acceleration

Hardware-accelerated AES-128 CBC, SHA-256, and ECDSA-256 — measured on TC375 with a 100 MHz HSM core: AES-128 CBC HW 4,065 op/s (1 KB), SHA-256 HW 19,230 op/s (1 KB), ECDSA-256 signing ~216 op/s.

Secure Key Generation & Storage

Hardware-based True Random Number Generator (TRNG) compliant with AIS 31 for cryptographically secure key generation and tamper-resistant key storage.

PKCS#11, PKCS#8 Support

PKCS#11 (Cryptoki) for signing, verification, AES/ECDSA/ECDH, and key management; PKCS#8 for secure key import/export. Integrates with OpenSSL and enterprise stacks — private keys never leave the hardware.

Secure Updater

Encrypted Secure Updater that can update itself as well as the application and the HSM — signed, tamper-protected update paths without insecure firmware delivery.

Technical Specifications

Cryptographic Algorithms & Functions

  • Symmetric cryptography: AES with 128/256-bit key lengths (CBC, GCM modes).
  • Asymmetric cryptography: RSA with 2048/4096-bit keys; ECC with NIST curve P-256.
  • Hash algorithms & MAC: SHA-256/384/512; HMAC-SHA256/384/512.
  • Random number generation: Hardware-based True Random Number Generator (TRNG) according to AIS 31.

Secure Updater

  • Update payloads are received and processed encrypted with AES-128.
  • Update integrity and authenticity are verified via asymmetric signature verification (e.g. ECDSA).
  • Supports secure self-update as well as application and HSM updates.

Performance Benchmarks

Detailed performance measurements of our cryptographic operations on embedded platforms.

SHA-256 (Hardware)

32 Byte 40,000 op/s
64 Byte 93,457 op/s
128 Byte 76,923 op/s
256 Byte 54,644 op/s
1 KB 19,230 op/s

AES-128 CBC (Hardware)

32 Byte 23,255 op/s
64 Byte 28,169 op/s
128 Byte 20,202 op/s
256 Byte 12,820 op/s
1 KB 4,065 op/s

ECDSA-256

Signature Generation

32 Byte 219 op/s
64–256 Byte 216 op/s
1 KB 210 op/s

Signature Verification

32–256 Byte 122 op/s
1 KB 120 op/s

ED25519

Signature Generation

32 Byte 119 op/s
64 Byte 114 op/s
128 Byte 111 op/s
256 Byte 105 op/s
1 KB 78 op/s

Signature Verification

32 Byte 144 op/s
64–128 Byte 140 op/s
256 Byte 136 op/s
1 KB 116 op/s

Lower Energy Use

than external HSM modules

On-chip integration removes the need for separate HSM hardware

Cost Advantage

over discrete HSMs

Integration replaces a dedicated hardware component

Parallel Processing

for cryptographic operations

Multiple crypto operations run concurrently without blocking the CPU

Measurement conditions (HSM Performance Report v0.3): TC375 host at 300 MHz, HSM core at 100 MHz, Saleae Logic at 500 MS/s. Figures are minimally optimized measured results. Total time = start + operation + response.

Use Cases

Industry & IoT

  • Protection of production data
  • Device authentication
  • Secure cloud connectivity
  • Compliance with industry standards

Defense

  • Classified information protection
  • High security communication
  • Hardware security modules
  • Certified security solutions

Other Critical Systems

  • Medical device security (MDR/IVDR compliance)
  • Energy infrastructure (Smart Grid, meters)
  • Aerospace & satellite communications
  • Secure payment terminals & kiosks