6 Bolt On or Build In: The Case for Microchip Security
The CRA essentially makes "security-by-design" a requirement for access to the EU market. Ideally, building in security by integrating secure microcontrollers into a design is the most robust and cost-effective path to compliance to satisfy the CRA requirements. However, for legacy devices and designs, it is completely possible to augment or "bolt on" security using software workarounds and additional hardware. Microchip provides solutions for every scenario, every complexity, and every engineer.
I Want to Keep my Current Design and Parts. Is it Possible to “Bolt On” Compliance?
- The risks surrounding the product.
- The capacity available in the product.
- The security use case being implemented.
In the case where all factors favor retrofitting, Microchip can support multiple approaches toward compliance.
For a more hardware-based approach, integrating a secure element into the design, such as Microchip’s CryptoAuthentication™ or Hardware Root of Trust (HRoT) chips paired with Microchip's Secure Bootloaders and Firmware Update Protocols, can secure the design better with minimal rework. For additional information on using these tools and products, visit the Microchip Security Products site, and the Secure MDFU Workflow documentation.
I am Starting a New Design. How Would Using Secure MCUs Make CRA Compliance Easier?
Supporting Compliance Through Hardware Security
A secure MCU handles the heavy lifting of the CRA’s technical requirements natively. Instead of writing many lines of software to protect keys or verify signatures, hardware blocks can be utilized.
- Hardware-Accelerated Crypto: Whether it is an on-chip secure element as seen on the PIC32CM LS60 and PIC32CX SG60/61, or a Hardware Security Module (HSM) peripheral found on the PIC32CK SG00/01 and PIC32CZ CA9x families, Microchip products integrate dedicated hardware to power cryptographic operations that are essential in meeting multiple CRA requirements, such as encryption and authentication, without stalling the main application.
- Isolated Execution Environments: Easily satisfy "separation of concerns" by running sensitive code (such as key management) in a Trusted Execution Environment (TEE). Microchip’s Arm® Cortex® M23 and M33 products, such as the PIC32CM LS60, PIC32CM SG00, and the PIC32CK SG00, support Arm TrustZone® which separates the application space into secure and non-secure areas for the secure execution of firmware. The TrustRAM (TRAM) peripheral further secures sensitive data and operations by enabling users to perform data persistence routines to recover data even after memory wipes or to initiate a full erasure of data once tampering is detected.
Lowering Total Cost of Ownership (TCO)
While a secure MCU may have a higher unit price, it significantly reduces engineering hours in the long run:
- Reduced Audit Risk: Certified or standards-aligned components simplify the evidence needed for a product-level conformity assessment. Particularly for products that fall under the Default and Important Class I categories, which will follow a self-assessment compliance regiment, having components that are already adhere to known harmonized standards reduces the burden on the manufacturer to compile evidence of compliance.
- Simplified SBOMs: By using integrated hardware features, the number of external software libraries (and their associated CVE risks) that need to be tracked is reduced.
Future-Proofing for the 5-Year Support Window
- The CRA requires support products for at least five years after the last individual product is placed in the market. Software-only security fades as new exploits are discovered. Hardware-based security, such as TrustRAM and Anti-Tamper modules, provides a permanent foundation that does not degrade over time.
What Features do Microchip’s Secure MCUs Have That Can Help Fulfill the CRA Essential Requirements?
The following table shows how the security features offered by each Secure MCU family correspond to the particular security operations that address the requirements put forth by the CRA.
| CRA Requirement | Device Family | |||||
|---|---|---|---|---|---|---|
| PIC32CM SG00 | PIC32CM LS60 | SAM L11 | PIC32CK SG00/01 | PIC32CX SG41/60/61 | PIC32CZ CA9x | |
| Secure Boot |
✔ Secure Boot using HSM-Lite | ✔Software solution verified by the ECC608 Secure Element | ✔Software solution | ✔Secure Boot using HSM | ✔Immutable Secure Boot (1) | ✔Secure Boot using HSM |
| Secure Firmware Updates | ✔Software solution | ✔Software solution | ✔Software solution | ✔Secure Update supported by HSM | ✔Software solution with OTA update support (2) | ✔Secure Update supported by HSM |
| Secure Memory Storage | ✔TrustZone ✔Trust RAM ✔ Key wrapping using the Physically Unclonable Function (PUF) | ✔TrustZone ✔Integrated ECC608 for secure key storage | ✔TrustZone ✔TrustRAM | ✔TrustRAM ✔Secure Flash ✔TrustZone | — | ✔TrustRAM ✔ Secure Enclave |
| Cryptography Support | ✔Cryptoaccelerators in HSM-Lite | ✔Integrated ECC608 Secure Element | ✔Cryptoaccelerators | ✔Cryptoaccelerators in dedicated M0+ HSM Core | ✔Cryptoaccelerators in optional HSM in package | ✔Cryptoaccelerators in dedicated M0+ HSM Core |
| Random Number Generation | ✔TRNG in HSM-Lite | ✔ TRNG in ECC608 Secure Element | ✔Dedicated TRNG peripheral | ✔ TRNG in HSM | ✔TRNG | ✔TRNG in HSM |
| Tamper Resistance | ✔Anti-Tamper Module ✔RTC with Anti-tampering monitoring ✔ Zeroization of TrustRAM | ✔Up to 16 Tampering detection pins | ✔Up to 4 Tampering detection
pins ✔ Zeroization of TrustRAM | ✔ Tamper inputs managed by
HSM ✔ Zeroization of TrustRAM | ✔Up to 5 Tampering detection pins | ✔Tamper inputs managed by
HSM ✔ Zeroization of TrustRAM |
- Immutable/secure boot not available for PIC32CXSG60.
- Specific software solution available for PIC32CXSG41 available on TPDS. More information can be found at this link: https://www.youtube.com/watch?v=-2g0i0rDAhM.
Action Checklist
- Based on the risk assessment and the position of the product in its design and life cycle, decide whether the risks allow “bolting on” security features or if a more in-depth security solution must be “built in” and integrated.
- Identify the CRA requirements applicable to the product or design.
- Determine which security implementations will be executed to accomplish the CRA requirements.
- Choose the correct hardware or software solution that has the features to power the security implementations for the product or design.
- For additional information or any questions, contact a local Microchip Field Applications Engineer or Sales Personnel.
