Hardware Root of Trust
A hardware root of trust is a tamper-resistant component, such as boot ROM, a secure element or a Trusted Platform Module, that anchors a device's secure boot, key storage, identity and attestation functions.
A hardware root of trust is a component built into a device whose integrity is assumed and which anchors security functions such as secure boot, cryptographic key storage, device identity and attestation. It is usually implemented as immutable boot code in read-only memory, a secure element, a Trusted Platform Module (TPM) or a protected security subsystem in a processor. Because its keys and boot code cannot be read or changed by normal software, it provides a trustworthy starting point for verifying everything else.
In industrial and IoT devices, hardware roots of trust enable secure boot, verification of signed firmware, unique device certificates for authenticating to networks and cloud services, and protection of secrets if a device is stolen or physically accessed. The TPM is specified by the Trusted Computing Group and standardised as ISO/IEC 11889, and is common in industrial PCs and gateways.
A root of trust is only useful if the surrounding software uses it correctly, for example by enforcing secure boot and binding keys to measured device states. Device provisioning must inject identities and keys securely at manufacture or commissioning. When selecting equipment, asset owners can ask suppliers how keys are protected, how device identity is established and how compromised keys are revoked, in line with IEC 62443-4-2 component requirements.
Key points
- Anchors secure boot, key storage, device identity and attestation
- Implemented as boot ROM, secure elements, TPMs or processor security subsystems
- The TPM is specified by the Trusted Computing Group and standardised as ISO/IEC 11889
- Secure provisioning of keys at manufacture or commissioning is essential
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.