We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest! Update Here
Stay in the loop with the latest from Microchip! Update your profile while you are at it. Update Here
Complete your profile to access more resources.Update Here!

Manage the Security of Connected Devices with TrustMANAGER


Our ECC608 TrustMANAGER device helps you manage the trust of connected devices in an IoT network. Combined with the Kudelski IoT keySTREAM SaaS, TrustMANAGER sets up a self-serve Public Key Infrastructure (PKI) that provisions your devices while they are connected in the field to automatically activate them in your account.

TrustMANAGER also enables the bulk upload of credentials, either with one click or automatically, and only charges for the devices in a fleet that are actually connected. Once your IoT device is connected, the keySTREAM SaaS will remotely provision various cryptographic credentials. In addition, the keySTREAM SaaS provides managed Firmware Over-the-Air (FOTA) updates to dynamically manage the security lifecycle of your product, from deployment to end of life.

The combination of TrustMANAGER and keySTREAM SaaS creates a powerful force in end-to-end IoT security. Redefine key and certificate management and FOTA updates with the ECC608 TrustMANAGER device, the first security IC in the TrustMANAGER series. 

TrustMANAGER Device and keySTREAM Services


Custom PKI Setup

  • Root Certificate Authority (CA) creation
  • Self-service PKI
  • Protection with IT-grade Hardware Security Modules (HSMs)
  • Kudelski HSM with 99.99% SLA
  • Quick to set up, in minutes
  • Cost-effective managed PKI

Automated Device Onboarding

  • Automated bulk upload of certificates for quick onboardings
  • Take ownership of the fleet with in-field provisioning   

Certificate and Key Management 

  • Expiration date
  • Rotation
  • Revocation
  • Renewal

Managed FOTA Update

  • Code Signing
  • Create and protect signing key in keySTREAM HSM
  • Bring your own signing key
  • In-field provisioning of verification public key
  • SaaS-based firmware delivery
  • Management of FOTA campaigns

Benefits of Using a TrustMANAGER Device


  • Prepare for European Cyber Resilience Act (CRA) and US Trust Mark compliance
  • Use the keySTREAM-managed FOTA updates to comply with the CRA-mandated patch updates
  • Set up your IT-grade, custom PKI in minutes using a proper HSM with no expertise
  • Protect your root certificate and associated private key in keySTREAM HSMs
  • Reduce onboarding time and cost by leveraging the auto-claim process and scale of the keySTREAM
  • Remove the need for customization during manufacturing with in-field provisioning to reduce the risk of mishandled keys and only pay for the provisioning of devices that connect
  • Manage keys remotely to keep your IoT device security up to date

Set up IT-Grade Custom PKIs in Minutes 

Protect Root Certificates in Kuldelski IoT HSM

No Customization in Factory 

Managed, Scalable FOTA SaaS Infrastructure

Cyber Resilience Act: Key Insights for Manufacturers


The Cyber Resilience Act (CRA) sets strict security requirements for digital products in the EU with penalties for noncompliance. We offer secure product solutions, cryptographic tools and provisioning services to help manufacturers achieve compliance.

Our white paper explores CRA guidelines, affected markets and security use cases. Learn how our TrustMANAGER security ICs and solutions with Kudelski IoT keySTREAM SaaS can simplify CRA compliance.

TrustMANAGER Development Tools


Trust Platform Design Suite

Use the TrustMANAGER examples and documentation within the Trust Platform Design Suite software, available for Windows® and macOS® operating systems.

CryptoAuth TrustMANAGER Kit

Begin prototyping with the TrustMANAGER development kit.

CryptoAuth Pro Trust Platform Kit

Begin prototyping with the CryptoAuth Pro Trust Platform Kit to implement secure Firmware Over-ther-Air (FOTA) updates in your design.

Scalable Manufacturing Solution


The keys, certificates and data to be loaded in the ECC608 will be provisioned in the field at the time of connection, so there is no need to expose those credentials to contract manufacturers or spend test time and infrastructure cost in their factories.

Although you will have a custom root CA associated with your company name, there are no custom part numbers involved. As a result, you can better manage your inventory across multiple product lines. Financially, charges for in-field provisioning only occur if your customer connects the device; you only pay for the devices your customer connects. 

Ready to Go to Production with TrustMANAGER?


There are two different ordering flows avaible to the user to go to production:

Auto Claiming 

  1. Create Microchip e-commerce account
  2. Create keySTREAM account
  3. Select Auto Claiming workflow in keySTREAM
  4. Order ECC608-TMNGTLS, no manifest upload required

Claim Devices with a Manifest

  1. First order the ECC608-TMNGTLS and download the manifest
  2. Open keySTREAM account
  3. Upload the manifest in keySTREAM

Products


Supporting Content


Understanding the Role of ECC608 TrustMANAGER and Kudelski IoT SaaS

Blog Article

In this blog post, we will explore the significance of the ECC608 TrustMANAGER combined with the keySTREAM™ Software as a Service (SaaS) from Kudelski IoT, its functions and its role in establishing security and reliability in an Internet of Things environment.

How to Set up the ECC608 TrustMANAGER with keySTREAM from Kudelski IoT

Tutorial

This video will guide you through the step-by-step process of setting up the ECC068 TrustMANAGER with the keySTREAM SaaS from Kudelski IoT. You will learn how to create your custom root certificate authority and associated PKI, trigger the in-field provisioning, and get ready for certificate management services.

keySTREAM Trusted Agent (KTA) Library

GitHub Library

This page contains the keySTREAM Trusted Agent Library (KTA_LIB) Configurations and an example application. Here are the primary folders:

  • apps - Example application to demonstrate useage of KTA_LIB with MPLAB® Harmony
  • config - KTA_LIB module configuration files 
  • docs -  KTA_LIB help documentation 

Contact the TrustMANAGER Team


Contact our marketing team with questions about the ECC608 TrustMANAGER device and Kuldelski keySTREAM services.