CONNECT WITH US

Macronix Secure Memories Build Hardware Defenses for EU CRA

Sue Chang, Hsinchu
0

Macronix Secure Memories Build Hardware Defenses for EU CRA. Credit: Maronix

In the fiercely competitive European and global markets, high-end applications such as automotive electronics, industrial control, networking equipment, and AI data centers face increasingly stringent requirements for supply chain transparency and device identity recognition. The European Union's Cyber Resilience Act (CRA) mandates that digital product manufacturers implement cybersecurity measures across the entire product service life cycle, from design, development, and production. In addition to secure-by-design principles, manufacturers must also establish mechanisms for vulnerability management, security updates, incident reporting, and supply chain transparency.

As the full implementation timeline of the CRA approaches, establishing security capabilities from the underlying product architecture has become a critical issue across industries. Macronix International, a global leader in non-volatile memory, leverages its two core products, ArmorFlash and ArmorBoot, focusing on data protection and secure boot respectively, to provide the international market with comprehensive hardware solutions. These solutions help system products establish a trusted security foundation and meet the CRA's requirements for secure-by-design, asset protection, and product life cycle security management.

Deeply Rooted in the High-Security Market: Strengthening Critical Data Protection with Chip-Level Defense

Addressing the high demands for data and firmware security in the European market, Macronix ArmorFlash directly integrates secure storage, hardware encryption, and identity recognition functions into the memory component. Its built-in hardware encryption engine and secure communication mechanisms enhance the protection of data during storage and transmission, reducing the risk of data eavesdropping or man-in-the-middle attacks. Meanwhile, through hardware security mechanisms such as a non-volatile Monotonic Counter and a True Random Number Generator (TRNG), it strengthens protection against Replay Attacks and Rollback Attacks, preventing systems from being maliciously downgraded to older, vulnerable firmware versions. Its secure credential support design assists the host in verifying the identity of connected devices, providing equipment with a copy-protected and reliable chip identity.

This reduces the risks brought by the connection of unauthorized devices, thoroughly blocking the risks of hardware tampering and counterfeiting throughout the customer's product life cycle, thereby ensuring a highly secure trust foundation for the software supply chain. ArmorFlash supports standard SPI interfaces and is pin-compatible with standard NOR Flash, making it convenient for clients to integrate into existing NOR Flash memory designs for rapid adoption without substantially altering system architecture, effectively lowering the barrier to entry for reinforcing storage component security.

CT Yeh, Project Manager of the Product Marketing Division at Macronix, pointed out that ArmorFlash targets markets with high demands for data and firmware security, including automotive, industrial control, medical, aerospace, AI data centers, networking equipment, and edge AI. The product has been successfully introduced into the supply chains of autonomous driving and networking systems, meeting the growing demands of these top-tier systems for device identification, data protection, and firmware security. It demonstrates significant value in high-security connected applications, assisting system manufacturers in strengthening their overall product defense capabilities.

Establishing a Trust Foundation for System Startup: Combating Malicious Firmware Attacks with Dedicated Secure Boot Architecture

To address the critical requirement during client system startup to prevent unauthorized or tampered code from being loaded, Macronix's ArmorBoot plays a pivotal role in firmware verification and protection during the system boot phase. It provides a dedicated solution paired with mechanisms such as security updates, backup, and recovery to confirm firmware trustworthiness, enhancing system resilience against firmware attacks and abnormal conditions. Its secure memory product line supporting standard SPI/QSPI interfaces provides embedded systems with a reliable hardware Root of Trust and Secure Boot, while implementing Replay Attack Protection and Rollback Attack Protection functions.

It is worth noting that during the execution of the secure boot procedure, ArmorBoot can complete code integrity verification directly inside the chip without exposing code on the external SPI bus. Once a digital signature mismatch is detected, it automatically routes the system to device recovery software to prevent hardware damage, while providing Authenticated Protection to fully safeguard the integrity of system operations. This product is particularly well-suited for embedded systems, industrial equipment, automotive electronics, networking equipment, and high-end computing platforms that require a hardware Root of Trust. It assists clients in strengthening product security mechanisms ranging from boot-up and firmware updates to product life cycle management, forming a complementary fit with existing system architectures.

Defense from the Underlying Architecture: A Two-Pronged Approach to Tackle CRA Challenges

Macronix advances security capabilities to the hardware layer through ArmorFlash and ArmorBoot. Based on different system requirements, it provides solutions spanning device authentication, data protection, secure boot, firmware updates, and system recovery. This assists clients in reducing risks such as unauthorized access, data tampering, and firmware replacement, while complying with product security requirements emphasized by international cybersecurity standards such as IEC 62443 and ISO 21434. In addition to meeting the stringent requirements of the EU CRA for asset protection and product life cycles, it also helps global customers strengthen product security design and high performance to establish product cybersecurity capabilities that comply with CRA requirements.

Credit: Maronix

Macronix ArmorFlash Product Series. Credit: Maronix

Maronix ArmorFlash-Secure and High-Speed NOR. Credit: Maronix