The Lattice SupplyGuard service extends the system protection provided by the Sentry stack across today's challenging and evolving supply chain by delivering factory-locked devices to protect them from attacks such as cloning and malware injection, and enabling secure device ownership transfer. These hardware security solutions are increasingly important for a variety of applications, including communications, data centers, manufacturing, automotive, aerospace, and client computing.

According to Patrick Moorhead, president and founder of Moor Insights & Strategy, “5G, edge computing, and IoT are accelerating the pace at which devices are connecting, and security concerns are rising among high-tech OEMs serving all markets. Developers need to know their hardware platforms are protected against cyberattacks and IP theft. They need security solutions that support comprehensive protection throughout a product’s lifecycle in the field, meaning the solution must be able to dynamically adapt to an evolving threat landscape.”
“Lattice continues to execute our solution stack roadmap and strategy to provide our customers with easy-to-use, system-level solutions for critical applications. The Lattice Sentry solution stack makes it easy for customers to deploy a hardware-based Root-of-Trust (RoT) PFR solution that meets NIST SP-800-193 guidelines,” says Deepak Boppana, senior director of segment and solutions marketing at Lattice. “With Sentry’s validated IP, pre-verified reference designs, and hardware demos, developers can quickly customize the PFR solution by modifying the C code provided with the RISC-V and Propel design environment, reducing time to market from ten months to just six weeks.”
The security paradigm is shifting, and firmware is an increasingly popular attack vector. The National Vulnerability Database reported that between 2016 and 2019, the number of firmware vulnerabilities grew by more than 700 percent. Protecting systems against unauthorized firmware access requires a dynamic, persistent, real-time security hardware platform for all connected devices. This includes protecting component firmware from unauthorized access and enabling the system to automatically protect, detect, and recover from an attack in an instant. TPM- and MCU-based hardware security solutions use serial processing and cannot deliver the real-time performance that parallel processing solutions like Lattice FPGAs can offer.
“To provide peace of mind in a constantly changing and increasingly risky supply chain environment, Lattice developed our SupplyGuard service to help our customers provision their devices securely and reduce their overall costs,” said Eric Sivertson, Vice President of Security Business at Lattice. “With Sentry and SupplyGuard, Lattice delivers comprehensive, truly parallel, nanosecond-reactive, next-generation security to enable dynamic trust for our customers and the users of their products.”

featuresof the Lattice Sentry solution stack include:
• Hardware security capabilities: The Sentry solution stack provides a pre-verified, NIST-compliant PFR implementation that enforces strict, real-time access controls on all system firmware during and after system startup. If corrupted firmware is detected, Sentry can automatically revert to a previously known, healthy firmware version to ensure uninterrupted, secure system operation.
• Compliance with the latest NIST SP-800-193 standard and CAVP certifications: The stack enables hardware RoT implementation through its support for the cryptographically robust Lattice MachXO3D™ FPGA family.
• Ease of use: Developers can drag and drop Sentry's validated IP addresses and modify the included RISC-VC reference code in the Lattice Propel design environment without any prior FPGA experience.

Rapid time to market: The Sentry package provides application demos, reference designs, and pre-verified and tested development boards that can reduce PFR application development times from ten months to just six weeks.
• Flexible, platform-independent security solution: Sentry offers comprehensive, real-time PFR support for firmware and programmable peripherals. It can act as a Root of Technology (RoT) in a system and/or complement any existing BMC/MCU/TPM-based architecture for full NIST SP-800-193 compliance.

Key features of Lattice SupplyGuard's supply chain protection service include:
• Robust security throughout the device lifecycle: SupplyGuard is a subscription service that provides peace of mind to OEMs and ODMs by tracking locked Lattice FPGAs throughout their entire lifecycle, from the point of manufacture, through transport across the global supply chain, system integration and assembly, initial configuration, and deployment. SupplyGuard helps protect OEMs by:
o Ensuring that only authorized manufacturers can build an OEM's design, regardless of their location.
o Providing OEMs with a secure key infrastructure to prevent the activation of their IP on unauthorized components, thus stopping product cloning and overbuilding.
o Securing devices against the download and installation of Trojans, malware, or other unauthorized software to protect platforms and systems against hardware hijacking or other cyberattacks.
• Flexible and low-cost implementation: SupplyGuard is highly customizable to meet the specific security and supply chain needs of OEMs across all industries served by Lattice. The service reduces the operating costs associated with implementing a secure manufacturing ecosystem.

Learn more about Lattice Sentry

More information about Lattice Supply Guard