Flexible and configurable solutions for protecting data at rest
Home > Security IP > Crypto Hub IP > CryptoManager Hub (CH-6xx) and CryptoManager Core (CC-6xx)
CryptoManager Hub (CMH) from Rambus is the next-generation family of flexible and configurable cryptographic accelerator cores intended for embedding in customer or Rambus provided Root of Trust security modules.
These cores target power and space-constrained SoCs or FPGAs. The CMH supports SESIP-PSA level 2/3 and FIPS 140-3 level 2/3 certifications when integrated into a security module. It offers optional side-channel attack protection and fault injection attack detection mechanisms. Dedicated CH-7xx configurations offer automotive ISO 21434 compliance and ISO 26262 ASIL-B and ASIL-D safety mechanisms.
Featuring a controller-based architecture with dedicated secure memories, the CMH offers a variety of classic asymmetric cryptographic accelerators including RSA, ECC, SM2, TRNG, KDF (Key Derive), as well as Quantum Safe accelerators like ML-DSA, ML-KEM and SLH-DSA. Ideal for power and space-sensitive applications like secure MCU, IoT server, gateway and edge devices, these accelerators are the most versatile, complete crypto solutions that offer the best balance of size and performance available on the market.
This latest generation CryptoManager RT-6xx Root of Trust IP offers many new features designed to support the security needs of customers today and in the future. These features include Quantum Safe Cryptography, Caliptra Root of Trust for Measurement (RoTM) emulation, DPA and FIA protections, as well as an innovative three-tier architecture that lets customers tailor a Root of Trust solution to their specific requirements.
The CMH products are silicon IP cores developed to provide strong and futureproof cryptographic support, enhancing security designs in SoC platforms.
The CMH implements a public key infrastructure comprising of a true random number generator, classic and, optionally, Quantum Safe accelerators, orchestrated by an internal controller. DPA and FIA are available. A local key store provides local storage of provisioned, derived or generated keys. CMH is also controlled over an AMBA (AHB or AXI) subordinate interface, where data is transferred over a DMA-based AXI manager interface. Readily deployable, CMH cores are offered in off-the-shelf configurations, allowing a choice tailored to the needs of your application. Configurations differ by cryptographic accelerators contained, protection mechanisms required, and third-party security standard compliance. Rambus can optionally offer dedicated certification support packages to its CMH licensees that provide related certification documentation, test scripts, and dedicated support to achieve FIPS 140-3, SESIP and PSA certification with your product embedding the CMH.
Quantum computing is being pursued across industry, government and academia with tremendous energy and is set to become a reality in the not-so-distant future. Once sufficiently large quantum computers exist, traditional asymmetric cryptographic methods for key exchange and digital signatures will be broken. Many initiatives have been launched throughout the world to develop and deploy new quantum-resistant cryptographic algorithms, known as Post-Quantum Cryptography (PQC).
| Feature | Description | Details |
| SESIP | Supports systems requiring Level 2/3 | L3 for DPA and FIA configurations |
| PSA | Supports systems requiring Level 2/3 RoT Component | L3 for DPA and FIA configurations |
| FIPS 140-3 | Supports systems requiring FIPS 140-3 | CAVP and CMVP Level 2 |
| Cipher Algorithm Support | AES (all key sizes) Optional: ChaCha20 Optional: SM4 | AES Modes: ECB, CBC, CFB, CTR, GCM, XTS, CMAC, GMAC, CCM, CMAC |
| Hash Algorithms | SHA-2 SHA-3 Optional: SM3 | SHA-2 224-256-384-512 SHA-3 224-256-384-512, SHAKE |
| Message Authentication Code Algorithms | HMAC-SHA-2, HMAC-SHA-3, KMAC-SHA-3 Optional: HMAC-SM3 | SHA-2 224-256-384-512 SHA-3 224-256-384-512 |
| AEAD Algorithms | AES-GCM, AES-GMAC, AES-CCM Optional: ChaCha20/Poly1305 | Modes: GCM, GMAC, CCM |
| Sign/Verify Algorithms | ECDSA EdDSA SM2 ML-DSA, SLH-DSA | NIST P-224, P-256, P-384, P-521, Brainpool Ed25519, Ed448 OSCCA Quantum Safe ML-DSA-44/65/87, SLH-DSA (roadmap) |
| Key Agreement Algorithms | ECDH EdDH ML-KEM | NIST P-224, P-256, P-384, P-521 Curve25519, Curve448 Quantum Safe ML-KEM-512/768/1024 |
| Key Derive Algorithms | NIST SP800-56C NIST SP 800-108r1-upd1 | Two-step KDF AES-CMAC KDF |
| Key Transport Algorithms | ECIES RSA Wrap/Unwrap (RSA-OAEP) | 128- and 256-bit strength up to 4096 bits |
| Random Number Generator HW | Standard CRNG or AES-31 NIST SP800-90 compliant TRNG | NIST ESV certificate |
| Crypto Performance | Cipher/Hash Performance | Scalable, ~6 Gbps @1000MHz |
| I/O Bus | AMBA Bus | AXI Manager, AXI/AHB Subordinate |
Complete Documentation
RTL and FW Package
