Tamper-Resistant Security Solution for Embedded DevicesUbiquitous Securus

Protects against data leakage and tampering through secure hardware

Ubiquitous Securus is a tamper-resistant security platform that securely protects confidential data such as keys and certificates for IoT and embedded devices, providing the functions required to prevent device spoofing, data leakage, and tampering.

By controlling secure hardware built into SoCs and MCUs and reliably protecting confidential data, Securus enables robust key management, device authentication, and secure storage that have traditionally been difficult to achieve with software alone.

It also supports key-pair generation, signing and authentication, encryption, and secure updates, helping customers build secure devices throughout the entire lifecycle from planning and design to manufacturing and operation.

Ubiquitous Securus

Are You Facing These Challenges?

  • Difficulty securely storing and operating device-specific IDs and certificates to prevent device spoofing
  • Risk of cryptographic key leakage because software-only protection is not sufficient
  • Secure management of confidential data such as keys and certificates when writing them on the manufacturing line
  • Prevention of software tampering and unauthorized updates during field operation through secure updates
  • Need to maintain portability across semiconductor generations and multi-vendor environments

Ubiquitous Securus helps solve these challenges.

Why Choose Securus?

With Securus, keys and certificates can be isolated from applications and handled securely inside the device, while cryptographic processing and authentication are performed by leveraging secure hardware functions.

1

Robust confidential data management using secure hardware

Securus directly controls secure hardware built into SoCs and MCUs, protecting confidential data such as keys and certificates within the hardware domain. By combining hardware tamper resistance with secure control, it helps fundamentally mitigate risks such as key extraction, tampering, and spoofing that cannot be fully prevented by software alone, enabling the construction of a secure device authentication platform.

2

Hybrid implementation combining software and hardware

When the target SoC or MCU includes security functions, Securus makes maximum use of that hardware. In environments without dedicated security hardware, it can provide security functions through software processing alone. This enables consistent security strength across a wide range of device lineups, regardless of SoC or MCU differences.

3

High compatibility through a portability layer that absorbs SoC/MCU differences

Security hardware specifications vary by SoC/MCU manufacturer and generation. Securus provides a portability layer that absorbs these differences, allowing smooth migration across devices and generations while minimizing the impact on upper-layer applications. For IoT products designed for long-term operation, continued use of the security platform is essential, and Securus helps turn security into a long-term asset.

4

Comprehensive support from pre-introduction through post-shipment operation

Rather than simply providing middleware, Securus offers support as contract development across all phases of secure device development, including planning, design, implementation, manufacturing, and operation.

  • Planning / pre-introduction consulting: identification of confidential data, security policy development, and hardware selection support
  • Design and development: support for designs using hardware security functions and hybrid implementation
  • Manufacturing optional support: secure key writing on production lines using factory-oriented tools
  • Operation optional support: long-term operation support including secure updates and certificate renewal

This end-to-end support helps transform security from a burden in the embedded development process into an accelerator for development.

What You Can Achieve / Use Cases

Device Authentication

Secure Storage & Encryption

Signature & Verification

Secure Update

  • Secure generation, storage, and use of device IDs and certificates to prevent spoofing
  • Secure storage for operating cryptographic keys, certificates, confidential information, and other sensitive data
  • Local encryption of content and sensor data to prevent unauthorized use in the event of leakage
  • Signature generation and verification, and message authentication using HMAC and CMAC
  • Provision of functions required for secure updates, including encryption and signature verification

Key Features

  • Encryption and decryption: AES 128/192/256-bit and RSA including OAEP
  • Hash functions: SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, and MD5
  • Message authentication: HMAC using SHA-256 and CMAC using AES
  • Digital signatures: RSA PKCS#1 v1.5, RSA-PSS, and ECDSA
  • Secure storage: secure saving and use of confidential data such as keys and certificates
  • Content protection optional feature: local encryption of streams and logs
  • Key-pair generation: RSA 1024/2048/3072/4096 and EC P-192/224/256/384/521
  • Key box function: enables applications to use keys without directly accessing key material
  • Channel function: specifies hardware-priority or software-based cryptographic processing

Supported Cryptography

Securus supports a wide range of public-key cryptography, symmetric-key cryptography, hash functions, and message authentication algorithms, including ECDSA, RSA signature and verification, RSAES-OAEP, AES, CBC, CTR, ECB, GCM, CCM, SHA series, MD5, HMAC, and CMAC.

Technical Information / Supported Environments

  • Supported platforms: supports security functions of various SoCs and MCUs. Please contact us for details on individual support.
  • Development language and environment: C/C++ assumed. Embedded OS, RTOS, bare-metal environments, and other details to be confirmed individually.
  • License and delivery format: middleware plus introduction support. Details provided through individual quotation.

Introduction-to-Operation Flow / Support

Planning(Pre-sales Consulting)

  • Data Analysis
  • Security Policy
  • Hardware Selection

Design &
Implementation

  • Secure Design
  • Middleware Provisioning
  • Hardware Integration

Manufacturing (Optional)

  • Encryption Tools
  • Secure Line Operation

Operations (Optional)

  • Secure Updates
  • Certificate Renewal
  1. Planning / pre-introduction consulting: identification of confidential target data, support for security policy development, and hardware selection
  2. Design and implementation: secure function design, middleware provision, use of hardware functions, and hybrid implementation
  3. Manufacturing optional support: secure operation of confidential data on production lines using encryption tools for factories
  4. Operation optional support: secure updates and certificate renewal according to certificate expiration dates

Contact Us

If you have any technical or introductory questions, please feel free to contact us via the inquiry form.