Secure Storage for Sensitive Data and Keys in Advanced Node SoCs

The Synopsys Secure Storage Solution for OTP is an add-on to Synopsys One-Time Programmable (OTP) Non-Volatile Memory (NVM) IP. It addresses the need for secure storage of sensitive information in embedded NVM SoCs across markets such as AI, HPC, IoT, Automotive, and Aerospace & Defense. By combining Synopsys OTP NVM IP, Synopsys SRAM PUF technology, and an industry-standard cryptographic engine, it delivers robust, hardware-based security for sensitive data, code, and keys. The SRAM PUF generates a device-specific root key at power-up, which is never stored on-chip and is used to derive keys for encrypting data stored in the OTP and scrambling addresses. This layered defense provides strong protection against attacks, keeping critical secrets secure—even if hardware is accessed directly.

The Synopsys Secure Storage Solution for OTP integrates seamlessly into SoC designs, offering flexible configuration, system-level security, and automated provisioning. It supports functions such as secure storage of keys, data, and code; ROM patching; device identification; anti-counterfeiting; and anti-rollback protection.

Key Benefits

Features

  • OTP and Encryption Security: Address scrambling and AES encryption with SRAM PUF keys deliver secure storage for sensitive data in OTP.

  • System-Level Security Extension: Optional add-on allows SRAM PUF sharing with OTP, safeguarding chip-level assets and enabling advanced key management and secure ID generation.

  • Flexibility and Scalability: Configure secure regions within OTP to tailor protection levels, meeting diverse design requirements.

  • Easy Integration: Standard APB interface ensures quick, seamless incorporation into various SoC architectures for faster development. 

  • Simple Software API: Internal management of security operations requires only basic read/write commands, eliminating the need for complex drivers or libraries.

  • Automatic Provisioning and Initialization: Key generation and security features are automatically initialized at power-up or reset, reducing manual intervention and deployment risk.

  • Short Time-to-Market: Fully integrated, out-of-the-box solution cuts development and integration time, enabling rapid implementation of secure SoC designs.

Secure Storage Solution for OTP Diagram

What's New

Video

Introducing Synoposys Secure Storage Solution for OTP IP

Watch Pim Tuyls and Krishna Balachandran unveil Synopsys' next-level hardware-based security innovation.

Frequently Asked Questions

Security is now critical for every NVM SoC targeting AI, HPC, IoT, Aerospace & Defense, and Automotive markets. Software protection alone isn’t enough, so hardware-based security—using embedded encryption keys and PUFs—is vital. With high design costs and constantly evolving security threats, companies must protect sensitive information in embedded NVM to avoid re-spins and reputational harm.

There is a market gap for secure storage solutions with hardware-based security. Most current products use embedded OTP and static keys, which are vulnerable to advanced attacks and lack the ability to generate unique, hardware-rooted keys. This limits their effectiveness in providing robust, device-specific security.

Synopsys Secure Storage Solution for OTP is an add-on to Synopsys OTP NVM IP. It is designed to address the need for hardware-based security in embedded NVM for AI, HPC, IoT, Aerospace & Defense, and Automotive applications. The solution is the industry’s first offering that combines OTP memory with SRAM PUF technology to provide robust hardware-level protection for sensitive data and keys. It generates a unique root key at power-up, utilizes a crypto engine that provides AES encryption and decryption with 256-bit keys for data stored in the OTP, and is managed by a Secure Controller which interfaces with the rest of the chip. Integration is seamless through standard AMBA APB interfaces.

 

The Synopsys Secure Storage Solution targets HPC, AI, IoT, Aerospace & Defense, and Automotive applications needing strong protection for sensitive data stored in embedded OTP memory. The solution is ideal for SoCs implementing secure key, data and firmware/boot code storage, device identification, ROM patching, and features like anti-counterfeiting and anti-rollback.

Key features include OTP security with dynamic, unique keys generated by SRAM PUF, AES encryption for robust data protection, optional system-level security extension, configurable secure regions, and easy integration into designers’ SoCs. These benefits deliver robust data security, flexibility, and faster time-to-market.

Customers begin by licensing Synopsys’ advanced node OTP. The Secure Storage Solution is offered as an add-on with two options: one protects only the OTP, while the other extends protection from the Synopsys SRAM PUF to the entire chip. This flexible model lets designers choose the security level and licensing structure that best fits their needs.

Find Your IP

Search for IP

Quickly identify and access the right IP solutions for your project needs.


Foundation IP Selector

Find embedded memory and logic IP for your SoC design.

Non-Volatile Memory IP Selector

Find silicon-proven NVM IP for your SoC design needs.