As the AI model, training data, and proprietary workloads become increasingly valuable, the need to protect them is also rising in tandem. Data center security has always been of paramount importance, but today, the demand for stronger and more effective protective measures is higher than ever before.
All of this is taking place in an increasingly complex environment: data center architectures are becoming more and more heterogeneous, with CPU, accelerators, SmartNIC, DPU, memory subsystems, and dedicated controllers working together to handle increasingly demanding workloads. Such architectural evolution has led to significant performance improvements, but it also presents a major challenge: it is necessary to establish trust among a large number of complex devices.
As attackers become more motivated to target the lower layers of the system stack, security can no longer start from the operating system; it must begin with hardware. We need to establish a credible foundation to authenticate device identities, verify code integrity, protect encrypted assets, and ensure credible verification throughout the entire lifecycle of the devices. In other words, security must commence with Root, of, and Trust within the hardware.
One of the important reasons why the industry increasingly needs a universal trust framework is precisely to explore Caliptra technology. Caliptra is an open-source silicon-level Root of Trust architecture designed for data center-grade devices.
Why is the industry considering Caliptra
Traditionally, hardware Root of Trust is custom-made to meet the security, performance, and lifecycle requirements of a single product. Such specialized implementations are still essential for many applications, but the differences between various architectures, interfaces, and trust models can make it more difficult for cloud service providers and infrastructure operators to establish a consistent level of trust among hardware from multiple suppliers.
Caliptra provides an open-source silicon-level Root of Trust architecture for data center-grade devices. It defines a common mechanism for device identity, measurement startup, and verification, which helps to enhance consistency among different implementations. With the support of multiple cloud and semiconductor companies, this project is becoming a path forward towards more consistent hardware trust.
Its open-source development model allows security architects to review the architecture, firmware, documentation, and implementation details. This transparency facilitates evaluation, collaboration, and interoperability across the entire ecosystem. For organizations considering adopting Caliptra, it provides a shared technical framework that can complement the differentiated security capabilities required for production deployment.
The requirements of end-users are also driving up the adoption rate. Cloud and data center operators increasingly hope that chip suppliers will provide implementations that meet the requirements of the Caliptra trademark, in order to give customers more confidence that Caliptra has been integrated according to the project-defined requirements. To qualify, suppliers must complete a consistency process, and their architectures and implementations will be evaluated based on the Caliptra integration checklist.
The continuously strengthening momentum of Caliptra raises an important question: once the decision is made to adopt Caliptra, what is the next step?
Choosing Caliptra does not equate to deploying Caliptra.
For many engineering teams, choosing between a Root, of, or Trust architecture seems to be the most difficult decision. However, in practice, the actual work often begins only after the choice has been made. Open-source Root, of, and Trust have laid a valuable foundation, but the requirements of commercial deployment far exceed what is provided by these basic implementations. Development teams must determine how to extend trust to a broader audience, how to expose encryption services to the software, how to coordinate secure startups across multiple subsystems, and how to integrate proofs with the platform management framework.
Subsequently, even more challenges will arise rapidly: it will be necessary to define authentication objectives, implement security configuration processes, establish lifecycle management strategies, and develop and maintain software interfaces, drivers, and applications. Organizations also need to formulate strategies for long-term maintenance, support, and bug fixing.
These requirements are not unique to Caliptra; they are realities that any hardware security architecture faces when it comes to implementation. However, they often only become apparent once a team moves beyond the evaluation phase and begins preparing for product deployment. As a result, industry discussions are increasingly shifting from the adoption of Root, of, and Trust to the deployment of Root, of, and Trust.
Root of Trust are evolving into security orchestrators
There is another important trend that is reshaping the hardware security architecture. Traditionally, Root, of, and Trust mainly served as independent security anchors, responsible for protecting keys, verifying software integrity, and establishing an initial chain of trust. Although these capabilities are still crucial, today's complex platforms often require more comprehensive functions.
Modern data center equipment consists of multiple processors, memories, accelerators, firmware domains, and management subsystems, and often supports workloads from multiple tenants on shared infrastructure. As a result, security policies must cover the entire platform to protect tenant data, workloads, and encrypted assets among these interconnected components, rather than being limited to a single security module. Consequently, Root, of, and Trust have begun to assume broader roles in platform security orchestration.
This orchestration capability can include coordinating secure launches across multiple domains, managing lifecycle states, supporting system-level proofs, executing security policies, and maintaining trust relationships throughout the entire SoC. Root of Trust are no longer just isolated security modules, but rather coordinators of platform-level trust.
As systems continue to become more heterogeneous, this broader visibility and control capability may be just as important as traditional security features themselves.
What exactly constitutes being truly ready for production?
Moving from a reference implementation to a deployable security architecture requires more than just adding functionality. Being production-ready typically includes a secure execution environment, protected key storage, a lifecycle management framework, integrated software, authentication preparations, and robust software interfaces. It also must take into account changes in encryption algorithms, with the flexibility to adopt new classical algorithms, post-quantum algorithms, or regional-specific algorithms as standards and requirements evolve. Development teams also need documentation, maintenance processes, as well as clear long-term ownership and support models.
As products enter real deployment environments, resistance to side channels and protection against fault injection become increasingly important. Development for authentication typically requires clearly defined security boundaries and supporting documentation. Even what seems like a simple software integration task can consume a significant amount of engineering resources if it has to be developed from scratch.
Overall, these requirements illustrate why deployment often becomes the most challenging phase of the security journey.
Bridging the gap between foundation and deployment

Rambus is aimed at the Caliptra specifications of CryptoManager Root, of, and Trust. It was proposed precisely to address this deployment challenge. It does not aim to modify or replace Caliptra, but rather to work in parallel with the unmodified Caliptra. In this way, chip suppliers can maintain the implementations that meet the Caliptra trademark compliance requirements, and at the same time, they can extend trust to a broader SoC through CryptoManager Root, of, and Trust, while also providing the infrastructure necessary for commercial deployment.
Figure 1: Integration of CryptoManager Root, of, Trust with Caliptra.
CryptoManager provides a secure execution environment, protected key and data storage, platform-level security orchestration, dedicated Caliptra drivers, system applications, as well as an integration framework designed to simplify deployment. It also supports a wide range of classical, post-quantum, and regional encryption algorithms through its programmable architecture, to meet the encryption agility required for future evolution.
At the platform level, CryptoManager Root, of, and Trust contribute to coordinating secure initialization, authentication, lifecycle management, and the execution of security policies within a broader scope of SoC. Advanced side-channel and fault injection countermeasures provide additional protection for security-sensitive operations, while design principles oriented towards authentication support the development of frameworks such as FIPS 140-3, PSA Certified, and SESIP.
The goal is clear: to allow engineering teams to spend less time setting up security infrastructure and devote more time to product differentiation.
Conclusion
Open-source security foundations are becoming an increasingly important part of the semiconductor industry. Caliptra is helping to establish a common trust framework for data centers and AI infrastructure, laying the groundwork for the solutions that many organizations now choose to build upon.
However, adopting a common foundation is just the first step. The engineering team still needs to transform this foundation into a secure, supportable, and production-deployable solution to protect the increasingly valuable workloads and data. CryptoManager Root, of, and Trust are designed to work in parallel with the unmodified Caliptra to complement the platform's security orchestration, authentication preparation, encryption agility, lifecycle management, and the integrated infrastructure required for commercial deployment, thereby bridging this gap.
The issue faced by the industry is no longer whether a universal Root of Trust framework is needed, but rather how to implement this trust in increasingly complex systems. By combining the universal foundation of Caliptra with the production-ready capabilities of CryptoManager, organizations can accelerate their path towards secure AI and cloud infrastructure.












