Microchip's custom Soteria-G2 firmware, embedded in its CEC1712 Arm® Cortex®-M4-based microcontroller, provides secure boot with hardware root of trust protection in a preboot mode for operating systems booting from external SPI flash memory. Furthermore, the CEC1712 provides lifetime key override and code deactivation protection, enabling field security upgrades. Compliant with NIST 800-193 guidelines, the CEC1712 protects against, detects, and recovers from corruption for overall firmware robustness across the system platform. Secure boot with hardware root of trust is critical to protecting the system from threats before they can enter, allowing only software trusted by the manufacturer to boot.
The Soteria-G2 firmware is designed for use with the CEC1712 to help designers accelerate the adoption and implementation of secure boot by simplifying code development and reducing risk. Soteria-G2 uses the CEC1712's tamper-proof secure boot loader, installed in ROM (Read-Only Memory), as the system's root of trust.
“One particularly insidious form of malware is the rootkit because it loads before the operating system boots, can evade conventional antimalware software, and is quite difficult to detect,” says Ian Harris, vice president of Microchip’s computing products group. “One defense against rootkits is secure boot. The CEC1712 and Soteria-G2 firmware are designed to protect against threats before they can load.”.
The CEC1712's secure bootloader is used to load, decrypt, and authenticate firmware running on the CEC1712 from an external SPI flash. The code validated by the CEC1712 then authenticates the firmware stored in the SPI flash for the first application processor. Two application processors, each with two flash components, can be used. Pre-provisioning customer-specific data is an option offered by Microchip or Arrow Electronics. Pre-provisioning is a secure manufacturing solution that helps prevent overlap and counterfeiting. In addition to shortening development time by several months, the solution significantly simplifies supply logistics, making it easier for customers to secure and manage devices without the added cost of third-party provisioning services or certification bodies.
“Ensuring the secure supply of some of Microchip’s flagship products is a key part of our offering, and the Soteria-G2 firmware and CEC1712 microcontroller are designed to protect systems,” said Aiden Mitchell, vice president of IoT at Arrow Electronics. “Customers will increasingly seek out these types of products as we move closer to the 5G era and adopt more connected solutions and autonomous machines.”.
In addition to preventing malware during pre-boot in 5G and data center operating systems, the combination of Microchip's CEC1712 and Soteria-G2 enhances security in operating systems for connected autonomous vehicles, advanced driver assistance systems (ADAS), and other systems that boot from an external SPI flash.
Development Tools:
The CEC1712 and Soteria-G2 offer several software and hardware support options. Software support includes Microchip's MPLAB® X IDE, MPLAB Xpress, and MPLABXC32 compilers. Hardware support is built into programmers and debuggers such as the MPLAB ICD 4 programmer/debugger and PICkit™ 4.
Prices and availability
The CEC1712H-S2-I/SX is now available in production for orders of 10,000 units, starting at $4.02 (includes Soteria-G2 firmware). For more information, contact a Microchip representative, an authorized distributor, or visit the Microchip website.
For supply prices, contact Arrow Electronics at
