Skip to content
ICTK PUF

The Key That Was Never Written Down: Hardware Identity for the Post-Quantum, Chiplet Era

Simon Bennett
Simon Bennett

WATCHTOWER BRIEF · HARDWARE SECURITY · CHIPLETS & UCIe

AiT × ICTK · A VIEW FROM THE WATCHTOWER

Every root of trust starts with a secret. For most chips, that secret is generated somewhere else, injected on a test floor, and stored in memory that an attacker can eventually reach. A physically unclonable function asks a different question: what if the chip simply was its own key?

IN BRIEF

Most device identities are provisioned, not inherent. Keys are injected during manufacturing and stored in non-volatile memory, which adds cost, test time and attack surface.

Three pressures are converging: post-quantum policy, billions of connected edge devices, and chiplet designs where dies must authenticate each other.

A PUF derives identity from the silicon itself. Nothing is injected and nothing is stored; the key is regenerated on demand from physical variation.

Not all PUFs are equal. Stability across temperature, voltage and ageing, overhead in area and power, and qualification evidence all matter.

Supplier independence matters too. The leading PUF IP is now owned by an EDA incumbent; some teams prefer not to source their security anchor from their tool vendor.

When I was sourcing third-party IP at Intel, the security blocks were always the hardest conversations. Not because the cryptography was difficult to evaluate, but because nobody could answer a simple question cleanly: where does this device's identity actually come from, and who else has touched it on the way?

The usual answer involves a hardware security module on a test floor, a key injected into one-time-programmable memory or flash, a provisioning flow that has to be trusted at every manufacturing partner, and a stored secret that must be protected for the life of the product. It works. It is also expensive, slow to scale across suppliers, and a standing target for anyone with a microscope and time.

Why is hardware identity getting harder now?

Three shifts are landing on security architects at the same time.

Three pressures on device identity
POST-QUANTUM POLICY U.S. policy on quantum readiness and critical-infrastructure security is pushing faster adoption of post-quantum cryptography. PQC algorithms are only as trustworthy as the keys underneath them, which puts the hardware anchor back under scrutiny.
EDGE SCALE Edge AI and ambient IoT put identity on devices measured in the hundreds of millions, often with tight power and area budgets. Provisioning a unique secret into every die becomes a line item, and stored keys cost silicon the device cannot spare.
CHIPLETS Disaggregated designs connect dies from different sources over standard interfaces such as UCIe. Each die needs a way to prove what it is to its neighbours, and a counterfeit chiplet is harder to spot than a counterfeit package.

Each of these on its own would justify a fresh look at how identity is anchored. Together they make the provisioned, stored-key model look like what it is: a manufacturing workaround that has been asked to carry more and more weight. We touched on the chiplet side of this in Old Is New Again and in our EDA 3.0 work, where trust becomes a property that has to follow a design across companies, not just across a die. The policy side is covered in Where Trust Ends, And Assurance Begins.

The safest place to keep a key is nowhere at all.

What is a physically unclonable function?

A PUF uses the tiny, uncontrollable physical differences that every manufacturing process leaves behind. No two dies are identical at the nanometre scale, so a circuit that measures those differences produces a response unique to each chip. Feed that response into a key-derivation step and you have a device key that was never generated externally, never injected and never stored. Power the chip down and the key is gone; power it up and the silicon regenerates it.

The idea is not new. What has changed is that PUFs have moved from research papers into commercial IP blocks, and the differences between implementations now matter to anyone putting one into a product.

How should a security architect evaluate a PUF?

Five questions to ask any PUF supplier
STABILITY Does the response stay the same across temperature, voltage and ageing, and how much error correction and helper data does it need to get there? Heavy correction costs area and can leak information.
OVERHEAD What does it add in area, power, memory and process steps? For an ultra-low-power or tag-scale device, the answer decides whether a PUF is viable at all.
QUALIFICATION Has it been qualified for the environment you ship into? Automotive (AEC-Q100) and certification evidence such as Common Criteria tell you more than a datasheet.
PROCESS PORTABILITY Is it validated on the foundries and nodes you use, and does it rely on standard process steps or special ones?
SUPPLIER INDEPENDENCE Who owns the IP, and what else do they sell you? A root of trust is a long-term dependency.

The last question deserves a sentence of its own. The market leader by distribution in SRAM-based PUF IP was acquired by one of the big EDA vendors in 2024. That is not a criticism of the technology. It does mean that for many design teams, the company supplying their synthesis and verification tools could also supply the anchor of their security architecture. Some teams will welcome that consolidation. Others, particularly those selling security themselves, will want an independent option. Our guide to managing commercial semiconductor IP covers why supplier concentration is worth thinking about early.

What makes a via-based PUF different?

ICTK's vPUF takes a different physical source of randomness from SRAM start-up states. It uses the random formation of via holes between metal layers during standard chip fabrication: whether a given via connects or not is decided by process variation, so the pattern is unique to each die and fixed once it is made.

NO STORED KEY The identity is generated on chip at first use and never written to external storage, so there is no injection step and no secret to protect in memory.
STANDARD CMOS It uses normal process steps and, according to ICTK, needs no error-correction or extra memory for data compensation, which keeps area and power overhead low.
QUALIFIED AEC-Q100 and JEDEC qualified, certified to ISO/IEC 20897, KCMVP and Common Criteria EAL5+, and silicon-validated across multiple foundries and nodes.
POST-QUANTUM WORK In July 2026 ICTK and BTQ Technologies completed the design of a joint chip combining BTQ's quantum-security processing with vPUF identity.
INDEPENDENT ICTK is a publicly listed security company (KOSDAQ: 456010) that is not owned by an EDA vendor.

Those characteristics line up with the three pressures above. Automotive qualification answers the robustness question for vehicles and harsh environments. Low overhead suits edge AI and tag-scale devices. A die-level identity that needs no provisioning step is a natural fit for chiplets that must authenticate each other inside a package.

Where does this matter first?

AUTOMOTIVE SOCS Secure boot, ECU authentication and regulation-driven cybersecurity requirements, with a qualified root of trust as evidence.
EDGE AI AND IOT Device identity, anti-cloning and binding AI models to the device that runs them, without spending scarce power or area.
DATA-CENTRE CONTROL PLANES Platform roots of trust for servers, where identity has to survive a multi-site ODM supply chain.
DEFENSE AND CRITICAL INFRASTRUCTURE Anti-counterfeit evidence and post-quantum readiness, subject to each programme's IP-provenance rules.
CHIPLET ECOSYSTEMS Die-to-die authentication as multi-vendor packages become normal.

THREE QUESTIONS FOR SECURITY ARCHITECTS

Where does each of your devices get its identity today, and how many companies handle it before it ships?

What does provisioning cost you per device in test time, equipment and supply-chain controls?

If your next product is a chiplet design, how will each die prove what it is to the others?

Frequently asked questions

What is a physically unclonable function (PUF)?

A PUF is a circuit that derives a unique, repeatable response from the random physical variations in each chip. That response can be turned into a device key that is regenerated on demand rather than stored, so there is no secret sitting in memory to extract.

How is a PUF different from a key stored in OTP or flash?

A stored key is generated outside the chip, injected during manufacturing and kept in non-volatile memory for the life of the device. A PUF key is derived from the silicon itself each time it is needed, removing the injection step and the stored secret.

What is ICTK vPUF?

vPUF is ICTK's via-based PUF IP. It uses the random formation of vias between metal layers during standard fabrication to give each die a unique identity, with no external key storage, and is AEC-Q100 qualified.

Why does post-quantum cryptography increase interest in hardware roots of trust?

Post-quantum algorithms protect data against future quantum attacks, but they still depend on keys that must be generated and held securely. Policy pressure to adopt PQC brings fresh scrutiny to how those keys are anchored in hardware.

Why do chiplets need hardware identity?

In a chiplet design, dies from different sources share a package and communicate over standard interfaces. Each die needs to authenticate itself to the others so that a counterfeit or tampered chiplet can be detected.

Who represents ICTK in North America?

AiT is a North American sales representative for ICTK's vPUF IP.


AiT represents ICTK in North America. If your team is weighing how to anchor device identity on its next platform, I would be glad to compare notes and to set up a technical session with ICTK. Reach me directly at simon@ai-techsales.com.

FURTHER READING ON THE WATCHTOWER BRIEF

Where Trust Ends, And Assurance Begins
Old Is New Again
RISC-V, Akeana, and the New Trust Model for Configurable Silicon
The Memory Wall Is Reshaping AI Inference Chip Design

Sources: ICTK product and certification information and the ICTK and BTQ joint chip announcement (July 2026), per ICTK. Product capabilities described per ICTK. AiT is a North American sales representative for ICTK.

Share this post