Andes Technology and ProvenRun to strengthen RISC-V trusted execution environment

1 min read

Andes Technology, a leading supplier of RISC-V processor IP, and ProvenRun, a secure OS vendor, are to offer ProvenRun’s formally proven Secure OS and Trusted Execution Environment (TEE) on Andes’ RISC-V processors.

Move to strengthen RISC-V trusted execution environment Credit: UK Studio - adobe.stock.com

As security threats increase, device and data protection is now critical for consumers and governments alike. Preventing information leaks and safeguarding systems from misuse requires embedded systems and IoT devices to integrate advanced security features.

Hardware and software isolation, in particular, is essential to prevent unauthorised access to sensitive information in device memory.

Andes Technology has played a central role in enhancing RISC-V security standards, having chaired RISC-V International’s IOPMP (IO Physical Memory Protection) task group and co-chaired the TEE (Trusted Execution Environment) task group. These efforts resulted in the IOPMP specification that provides the hardware isolation mechanisms needed to secure hardware, as well as a secure monitor and TEE to use this hardware to allow OS and applications to run protected from each other and malicious code.

ProvenRun’s ProvenCore is the only OS certified at ISO/IEC 15408 Common Criteria Evaluation Assurance Level 7 (EAL7) – the highest recognised level of security assurance, achieved through rigorous testing, analysis, and formal methods. It is suitable for the high-risk, mission-critical environments, including critical infrastructure, financial systems, automotive, aerospace, and defence.

Through this partnership, the two companies bring to market a highly secure platform running ProvenRun’s Common Criteria EAL7-certified TEE and OS on a system that integrates Andes IOPMP with Andes RISC-V processors.

“ProvenRun offers the most secure TEE and OS on the market today for ARM and now RISC-V architectures,” said Thierry Chesnais, ProvenRun CEO. “Andes leadership in RISC-V security task groups and broad portfolio of RISC-V IP, makes them a natural partner to deploy ProvenCore for highly secure environments.”

“Andes RISC-V IOPMP IPs bring unique and competitive security advantages to our customers using RISC-V processors,” said Samuel Chiang, marketing director of Andes Technology. “Our partnership with ProvenRun allows us to deliver robust solutions for customers developing trusted execution environment products. We are excited to work with ProvenRun as they introduce the benefits of ProvenCore to the RISC-V community, enhancing the performance and resilience of security-focused RISC-V applications.”