Custom Part Manufacting Services (CPMS)
Customize Your Wireless Hardware and MCUs with Advanced Security and Unique Certificates.
Building an IoT device was easy in the past: developing code, flashing it on a chip, and manufacturing. Today, security is the ultimate challenge for IoT device makers. Your IoT device faces severe security threats throughout its entire supply chain, starting at the beginning of the outsourced manufacturing process.
Why CPMS?
Why CPMS?
Securing an IoT device is a highly complicated and costly process - you must generate public and private keys for secure boot and secure debug, sign code with a private key, store all the private keys in an HSM, place the public keys for secure boot and secure debug in one-time-programmable (OTP) memory, flip OTP bits for secure boot and secure debug, and flash the encrypted code and identity certificates within the hardware.
CPMS streamlines the programming part of this process for you. Even the most advanced security features, certificates, and identities can be programmed in a secure, fast, and cost-efficient way at the Silicon Labs factories.
New IoT Challenges
Product Counterfeiting
Outsourced manufacturing imposes various security risks at your IoT products – cloning, overproduction, and counterfeiting. Unencrypted software is subject to IP theft, and tampering is a threat throughout the supply chain.
“Zero Trust” Security Paradigm
No IoT device is trusted to pair with other devices or join an ecosystem such as AWS, Matter, and Wi-SUN any longer without a unique identity and secure authentication. Soon unauthenticated IoT devices cannot generate revenue!
Regulation and Legislation
US and European authorities are responding to the increasing security threat with laws mandating IoT companies implement better security. Soon IoT devices must only run authenticated code. Only secure interfaces and ports are allowed. Secure software OTA update and a unique device ID become mandatory.
Nine things IoT device makers can do with Custom Part Manufacturing Service (CPMS)
What is CPMS?
What is CPMS?
Custom Part Manufacturing Service (CPMS) allows you to customize Silicon Labs hardware – wireless SoCs, modules, MCUs – at the factory. The CPMS self-service web portal guides you through the customization process and its various customizable features and settings. You can place orders for customized test and production units to our factories securely via the CPMS portal.
Unlike traditional flash programming, CPMS is a secure provisioning service that enables you to customize your chips with several highly advanced features – these can include: secure boot, secure debug, encrypted OTA, public, private and secret keys, secure identity certificates, and more.
The custom features, identities and certificates are injected on the hardware securely, quickly, and cost-efficiently at the world’s safest place, the Silicon Labs factories.
Key Features
Unique Part Number
Program your chips with a unique part number to track shipments to avoid overproduction and over-pricing. With the custom part numbers, you can know exactly how many parts your contract manufacturers order from Silicon Labs.
Secret Keys
Inject custom public and private keys and other custom secret keys on the chips during manufacturing – safeguard your products right from the beginning of their lifecycle.
Secure Bootloader
Pre-flash a secure bootloader of your choice on the chips to encrypt your software Intellectual Property (IP) during contract manufacturing. Safeguard your competitive edge in the market.
Tamper Detection
Set up the right tamper detection features on your hardware in manufacturing. CPMS helps to navigate the countless alternative settings to protect your products against the most sophisticated tampering attacks.
Debug Port
Configure the debug port to one of the three possible states securely before the chips leave the factory. 1. Standard 2. Secure Lock (can be unlocked with a secure debug token)
3. Permanent Lock
Application Software
Pre-flash your application software already in Silicon Labs chip manufacturing securely, and cost-efficiently without delaying your time to market at third parties.
Custom Markings
Customize markings on the hardware to hide the exact technology used in your products to hide competitive advantages.
Custom Certificates
Program custom certificates on your chips at the Silicon Labs factories. Custom certificates can be used to authenticate (attestation) your devices with IoT cloud services, ecosystems (AWS, Matter, Wi-SUN) and smartphone applications.
Benefits
Ecosystem Certificate Injection with CPMS
Simplify Matter Device Manufacturing with CPMS
CPMS can simplify the manufacturing of your Matter devices by safely and securely injecting signed DACs at the factory and providing custom programming and marking.
Why CPMS for Matter?
Matter has raised the bar for the security of smart home devices. However, with increased security comes increased complexity. Matter’s focus on simplifying adoption for the consumer means that this added complexity falls to device manufacturers.
One of these areas of increased complexity is device certificates. Not only does Matter require a unique certificate on each device, but it also uses Public Key Infrastructure. This requires a Certificate Authority to provide those certificates, and getting those certificates from a Certificate Authority to your manufacturer securely and with trust can be complex.
This is where Silicon Labs can help. Whether you’re in pre-production or production, our Custom Programming Manufacturing Service and our partnership with Kudelski—an authorized Certificate Authority for Matter—make it possible for you to order Silicon Labs Matter ICs and Modules with the Matter DACs injected securely and help keep them secure throughout the process.
Matter DAC Injection Supported Wireless SoCs and Modules
Silicon Labs DAC injection is supported on MG24 devices with Secure Vault High. This provides a secure and seamless way to store Matter private keys and certificates, preventing counterfeiting of your Matter devices.
CBAP with CPMS
Certificate Based Authentication and Pairing (CBAP) enabled devices can utilize certificates injected by CPMS during manufacturing.
Ready to Get Started?
Click below to get started with Custom Part Manufacting Services.