Cryptography-enabled MCU with Soteria-G2 Firmware Stands Guard in the Data Center

A global provider of high-performance server technology upgraded their battle plan for hardware and OS-based security with a comprehensive solution set from Microchip.

I wrote and published the following case study which originally appeared as one of Microchip’s web-based Customer Stories during the time I served as Technology Marketing Advisor for the company. 

 

Each generational advance in areas such as network architecture, cloud infrastructure, smart product design, wireless evolution, smart city deployments and autonomous vehicle operation represents millions of new opportunities for cost savings, efficiency gains and performance acceleration. Cloud data centers and new data storage structures are growing in tandem to meet the demand. Businesses, governments, utilities, consumers and a wide spectrum of public and private institutions all expect to leverage these advances right alongside the inventors of each new element of our increasingly connected world.

Another group eagerly awaits each new incremental leap forward. Hackers.

Some would say that the first hackers were simply teenagers who gained access to telephone switchboards during the early 1900s and rerouted customer calls as a prank. Security meant locking the doors to the office in those days.

To be known as a hacker in the 1960s meant that you were probably a mainframe computer programmer who devised new code to push computing operations beyond their intended performance limits. It wasn’t an evil designation. It meant that you had advanced the practice of mainframe manipulation and gained the respect of your peers. 

 

Telecom Carriers Targeted

The next evolutionary hacker targets were telecom carriers. Technologists studied devices connecting to networks and mimicked the tones used to route calls – to treat themselves to free long-distance service. These phreakers (a mash-up term describing their phone network understanding and freakish intentions) created a gray market for black boxes that performed this workaround. By the time telephone networks migrated to software-based control systems, hackers had moved on to other sectors like the emerging population of PCs and newly-defined local area computer networks. And – at some point – they crossed the line between seemingly harmless experimenters to criminal disruptors.

A connected future will offer a variety of hardware, software and service disconnects that security-oriented vendors and manufacturers must address to avoid disruptions in service, theft of operator and customer data, and loss of revenue for service providers. Vulnerabilities that could not be imagined a generation ago now attract the attention of those with good intentions – to plan for new solutions to address weaknesses – as well as those with bad intentions seeking to exploit the vulnerabilities.

 

 

In the not-so-distant past, a common prescription to combat the potential for nefarious misuse of popular USB memory drives was to use glue or silicone to fill each USB computer port on enterprise computers and laptops. Today that approach seems obsolete, like pulling teeth to combat a toothache.

 

A New Focus on Communications Networks

While advertising by wireless network operators would have you believe that ubiquitous 5G is here today with companion waves of IoT-enabled devices populating their networks, the reality is on a slightly slower trajectory.

And, data center architects and storage system designers are building tomorrow’s infrastructure solutions at the same time hackers are testing their vulnerabilities. In an interesting twist, the hacking community may be sensing the arrival of 5G access and billions of IoT nodes as a return to telecom-oriented networks for backdoor access to valuable data and entry points for chaos. The sheer volume of devices and systems available for software and hardware-based mayhem will be unprecedented. Newly-designed bots and scripts will need to be accounted for, as hacker business models will be aimed at emerging ports-of-entry for their malicious code.

Cybersecurity specialists have been battle testing the vulnerabilities of devices featuring embedded sensors and always-on network connectivity since IoT specifications were first popularized. Increasingly sought-after penetration testers are becoming rock stars in corporate IT departments and popular targets of IT recruiters as demand for their services grows. Their skill at breaking into the same systems that nefarious hackers also seek out leads to industry-best preventive, corrective and protective countermeasures that keep system compromises from taking place. A Certified Ethical Hacker (CEH) designation can lead to a corporate role researching and testing the weaknesses and vulnerabilities in target systems by applying the same knowledge base and tools as a malicious hacker. The work of cybersecurity pros supports an ongoing, accurate assessment of the security posture within a corporate IT system.

 

Security at the Heart of Microchip’s Portfolio

It’s not just hardware and computer systems that are subject to attack by hackers. Unprotected components in a system are susceptible as well. The landscape for device security is layered with industry-specific requirements – and market drivers that are constantly changing.

When companies are publicly called out for security breaches, they are likely to experience a significant loss of credibility and may experience revenue and stock price declines. Unfortunately, no set of standard security guidelines for platform firmware resiliency has been practiced across the board. A dizzying array of considerations must be considered in any security approach to ensure alignment with standards, industry mandates, functionality, costs, customer demands, safety, performance and network paradigms. In embedded designs, security measures interface with many layers of on-device storage, communication hardware and protocols, node and gateway implementations, device management systems, cloud data access and more.

Security needs to be considered and planned at the inception of each embedded design. Microchip has a long history of delivering solutions that directly protect products and, ultimately, protect intellectual property, corporate brand, reputation and revenue.

Microchip customers can confidently rely on embedded solutions that protect their products with our comprehensive security portfolio and world-class Security Partner Program. From authentication devices and trusted platform modules, to crypto-enabled microcontrollers and microprocessors, software libraries and enhanced protocols – the Microchip approach to security is central to everything we do. 

 

 

THE CHALLENGE


 

A global provider of high-performance server technology was interested in upgrading its battle plan for hardware and OS-based security. Increasing awareness of rootkit and bootkit vulnerabilities in systems that boot from external SPI Flash memory has been an increasing focus area for many OEMs.

Rootkit malware is designed to be unnoticeable to the user, even while it is active. Cybercriminals gain the ability to remotely control computer systems via rootkits and can use them to subvert security programs while stealing personal data, passwords, bank details and credit card information. A bootkit is poisonous code that affects the master boot record of a computer motherboard, enabling malicious programs to be executed just prior to the time when the operating system loads. 

Microchip’s new cryptographic MCU, custom firmware and provisioning service are purpose-built to enable platforms to detect and stop malicious firmware prior to run time. Our customer was particularly interested in a multi-pronged strategy to address:

  • Fast response times to correct security breaches
  • Understanding security threats and mitigation
  • Migrating from a secure device strategy to a secure platform strategy
  • Aligning with evolving security organizations and standards
  • Adopting security expertise and resources
  • Understanding the impacts on legacy devices and platforms
 

 

THE SOLUTION


 

After meeting with the customer to better understand their requirements and advising them on the project’s dynamics, the Microchip team was able to recommend a solution with the cryptography-enabled CEC1712 MCU with Soteria-G2 custom firmware as its centerpiece. The project commenced in 2019.

Microchip’s Soteria-G2 custom firmware on its full-featured CEC1712 Arm® Cortex®-M4-based microcontroller provides secure boot with hardware root of trust protection in a pre-boot mode for those operating systems booting from external SPI Flash memory. In addition, the CEC1712 provides key revocation and code rollback protection during operating life enabling in-field security updates. Complying with NIST 800-193 guidelines, the CEC1712 protects, detects and recovers from corruption for total system platform firmware resiliency. The secure boot with hardware root of trust is critical in protecting the system against threats before they can load into the system. It only allows the system to boot using software trusted by the manufacturer.

 

The Soteria-G2 firmware is designed to be used in conjunction with the CEC1712 to allow designers to speed adoption and implementation of a secure boot, by simplifying the code development and reducing risk. Soteria-G2 uses the CEC1712 immutable secure bootloader, implemented in Read-Only Memory (ROM), as the system root of trust.

The CEC1712 secure bootloader loads, decrypts and authenticates the firmware to run on the CEC1712 from the external SPI Flash. The validated CEC1712 code subsequently authenticates the firmware stored in SPI Flash for the first application processor. Up to two application processors are supported with two Flash components supported for each. Pre-provisioning of customer-specific data is offered as an option. Pre-provisioning is a secure manufacturing solution to help prevent overbuilding and counterfeiting. In addition to saving up to several months of development time, the solution significantly simplifies provisioning logistics, making it easy for customers to secure and manage devices without the overhead cost of third-party provisioning services or certificate authorities.

Platform firmware resiliency is more than a point solution however. According to industry guidelines, all potential firmware security breaches need to be protected and all devices and subsystems within the platform need to attest to their identity and state of security. This means that ideally there needs to be a system aggregator for platform attestation.  Microchip’s combination of CEC1712 and Soteria software scales to meet the needs of various attestation use cases within the platform.

 

 
 

 

THE RESULT


 

Our data center customer’s end users are now less likely to have their corporate, personal, financial, or medical data systems breached by hackers, avoiding the mitigation nightmare that accompanies a compromising event.

Defending against rootkits with secure boot is a powerful approach, and the adoption of the CEC1712 and Soteria-G2 firmware was an ideal strategy to protect against threats before they can be loaded. The combination of hardware root-of-trust practices, secure boot capabilities and Soteria firmware can easily be added to legacy systems, enabling them to scale from a point solution to a platform level security solution.

Share Article
Related Articles
Physical AI Field Notes from Actuate 2026

A specialized technology stack is beginning to form around Physical AI. At Actuate 2026, developers got a close look at its emerging data, simulation, training, observability, compute and teleoperation layers, offering a glimpse of an ecosystem being assembled in real time.

The New Mandate for Global Consulting Leaders: Physical AI

The firms that rewired the digital world now aim to transform the physical one. And just as they did with digital transformation, the consulting giants are positioning themselves to support this next era of enterprise reinvention.