Industrial IoT Devices
A hardware root of trust for PLCs, industrial PCs, gateways and field devices.
TROPIC01 is an open, auditable secure element that anchors device identity, key storage and firmware integrity in silicon — designed while your schematic is still open.


One extracted key shouldn't compromise your entire fleet
PLC, ICP, controllers, or other IIoT devices are commissioned once and run in an unattended cabinet for 10+ years. Through all of it, the device holds secrets: the key that authenticates it to the controller network, the key that verifies its firmware, the credentials it uses to reach a historian or a cloud endpoint.
Extract the keys from one unit and the consequence is rarely one unit. Industrial products ship in families of thousands of identical devices running identical firmware — one extracted key can mean cloned devices, impersonated devices, or firmware the whole family accepts as authentic.
In most industrial devices shipping today, those secrets sit in external flash, protected by the assumption that nobody will open the enclosure. The attacker doesn't need your network to get a sample: a decommissioned line, the secondary market, or twenty minutes at an unattended site is enough. Whether compromising one device compromises the entire fleet in this way is a design decision. It is made at the point where you decide where the keys live.
Anatomy of a secured industrial controller
One QFN32 alongside the host MCU or CPU. Four SPI signals, one 3.3 V rail, three decoupling capacitors. Everything the host sends after the handshake with TROPIC01 is AES-256-GCM encrypted — a logic analyser on the bus sees ciphertext.
Boot integrity
The host verifies firmware against signatures anchored in the secure element; monotonic counters prevent rollback.
Device identity
A per-chip X.509 certificate signed at manufacture; the private key is generated inside the chip and never leaves it.
Credential store
32 ECC key slots and 237 KiB of encrypted storage for network credentials, certificates and configuration.
Tamper response
Voltage, glitch, laser, EM and temperature sensors with a configurable alarm state the host can read and act on.

TROPIC01 Specification
Where TROPIC01 fit
PLCs and compact controllers
TROPIC01 can anchor per-device identity, provide hardware-protected signing, and support anti-rollback state via monotonic counters; host firmware remains responsible for signature verification policy and update flow.
Industrial PCs and gateways
TROPIC01 provides host-independent hardware key custody and identity primitives, with integration via Linux/PKCS#11-style paths, complementing TPM-based platform trust where present.
Gateways and edge devices
VPN and TLS credential protection through the PKCS#11 provider; reference OpenWRT integration published.
Remote I/O and field devices
Per-device key uniqueness at a cost and board area a terminal-class BOM can carry.
Claims you can check
One QFN32 alongside the host MCU or CPU. Four SPI signals, one 3.3 V rail, three decoupling capacitors. Everything the host sends after the handshake with TROPIC01 is AES-256-GCM encrypted — a logic analyser on the bus sees ciphertext.
Protection | What is implemented | Where to verify |
|---|---|---|
Physical tamper | Active shield, voltage, glitch, laser, EM and temperature sensors, configurable alarm response | View Github |
Side-channel | Threshold-shared Keccak engines, masked AES-GCM, randomised ECC, constant-time execution | View Github |
Fault injection | Detectors, redundant encoding, error correction — and published mitigations where independent research found a bypass | Security advisory, June 2026 |
TROPIC01 was independently audited by Ledger's Donjon security research team. The findings, our mitigations, and the coordinated disclosure are public — see the security advisory and our CVD process.
Why the design is published
Continuous security
The RTL and firmware source are public, so the chip is examined by researchers and the community, with a coordinated vulnerability disclosure process and published advisories when something is found.
Faster time-to-market
Design files, the SDK and a Python model of the chip are public; your team can develop and test host software before silicon arrives.
Lower integration cost
BSD-3-Clause-Clear licence, no NDA, no per-unit software fees; .
Verifiable claims
"No backdoors, no hidden features" is checkable in source, not taken on trust.
Regulatory readiness
A signed firmware update path, published errata and transparency documentation that map onto CRA and IEC 62443 evidence needs.
From zero to a verified certificate chain
No hardware yet? ts-tvl is a Python model of the chip — write and test host software in CI before the board arrives.
Order a devboard
Ships globally within days; design files are public.
Run the examples
Clone libtropic, build for your platform, ping the chip over an encrypted channel.
Verify the certificate chain
Device attestation working end to end, demonstrable to a sceptical colleague.
Port the HAL
Four functions wrapping your SPI driver, then measure the timings on your own hardware.
We are here to help
Is TROPIC01 a TPM?
No. It does not implement the TCG TPM 2.0 command set. It is a secure element — a complement or an alternative to a TPM, covering device identity, key storage and application-layer credentials, including on ARM and RISC-V platforms that have no fTPM.
Is TROPIC01 Common Criteria or SESIP certified?
No, and certification is not planned for this product. We publish the design instead — RTL, firmware source, architecture documentation — so it can be examined continuously rather than evaluated once under NDA. If a certificate is a hard gate in your procurement process, tell us early and we will say plainly whether we can help.
What is the operating temperature range?
The datasheet specifies −25 °C to +85 °C as the absolute maximum rating. Comfortable for cabinet-mounted and indoor equipment; if your product needs the full −40 °C industrial range, contact us before designing in.
Will it work with my existing software stack?
Usually without rewriting it. The PKCS#11 provider exposes TROPIC01 as a standard cryptographic token, so OPC UA servers, TLS endpoints and VPN clients can use it as a key store through configuration. SDKs: C, Rust, Go, Arduino; examples for STM32, Linux and OpenWRT.
What does hardware integration involve?
One QFN32 (4 × 4 mm), four SPI signals, one 3.0 – 3.6 V rail, three decoupling capacitors and a pull-up. No crystal, no extra regulator. The KiCad footprint and full devboard design files are on GitHub.
What are the lead times and minimum quantities?
Prototypes from a single unit up to 1,000; production from 1,000 units with no upper limit. Up to roughly 10,000 units ships from stock; above that, 4–9 months. Indicative pricing on request.





