Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenTitan is an open-source silicon root-of-trust project: an ecosystem of hardware designs, firmware, security specifications, and development tools for building secure silicon. It can be relevant to embedded, operational-technology, and IoT devices, but it is not a device-management service or a ready-made security product. What it provides depends on the design selected and how that design is integrated, provisioned, and maintained.

What is OpenTitan?

OpenTitan is a project for developing and integrating silicon root-of-trust designs. Its materials include hardware IP, complete top-level designs, firmware, technical documentation, security specifications, and development utilities. The project is administered by lowRISC CIC, and its repository documentation says the project is generally licensed under Apache 2.0 unless a specific item states otherwise. See the OpenTitan project introduction and its product architecture.

A silicon root of trust is a hardware-based foundation for security functions that need a trusted starting point on a device. In OpenTitan’s case, the design can be used as a discrete secure microcontroller or integrated as a secure execution environment within a larger system. The integration choices matter: OpenTitan is a set of designs and components to build with, not a universal security layer that automatically protects every device using it. The project introduction describes its scope.

Why does a silicon root of trust matter for OT and IoT?

Connected embedded devices can remain in service for years, handle sensitive operations, or sit at the boundary between networks and physical equipment. A hardware root of trust can provide a foundation for checking software at startup, establishing device identity, and supporting security operations over a device’s lifecycle. Those capabilities are useful only when the surrounding product implements and operates them appropriately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
  • Compatible with TPM-M R2.0
  • Chipset: Infineon SLB9665
  • PIN DEFINE:14Pin
  • Interface:LPC
  • Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.

OpenTitan addresses silicon-level building blocks and lifecycle security concerns; it does not by itself enroll fleets, manage devices over a network, operate a cloud service, or define how a manufacturer handles every update and key. The project’s security overview describes its security goals and components. Exact protections in a finished OT or IoT product depend on its silicon integration, firmware, provisioning process, lifecycle configuration, and operational practices.

How does OpenTitan’s security model work across a device’s life?

The OpenTitan Security Model covers more than the first boot. Its scope includes secure boot, device and software attestation, provisioning, firmware update, chip identity, lifecycle states, and ownership transfer. The point is to treat security as a sequence of related responsibilities—from manufacturing and initial setup through software changes and possible changes of ownership—rather than as a single boot-time check. The security overview describes this model.

Rank #2
Sale
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS

The documented hardware primitives include an entropy source, CSRNG, AES, HMAC, key manager, OTBN, and alert handler. They are components that can support security functions; their presence in a project design should not be read as proof that a finished product meets a particular certification or production requirement. OpenTitan explicitly cautions that some component reference implementations may not yet meet production or certification expectations. A reference implementation, an integrated product, and a certified product are distinct things.

How does OpenTitan secure boot work?

OpenTitan’s secure-boot design begins with immutable ROM. After minimal setup, ROM authenticates ROM_EXT and transfers execution to it. The specification describes a rule that all executed code must be cryptographically signed by either the device owner or the trusted entity that originally established the device at manufacturing time, called the Silicon Creator. Read the OpenTitan Secure Boot specification for the design details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
  • TPM 2.0 module for ASROCK motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
  • LPC 18 Pin for TPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASROCK

The trust arrangement separates creator and owner responsibilities. The Silicon Creator signs ROM and ROM_EXT, while the Silicon Owner signs later software stages. Ownership may change, but the Silicon Creator’s trust role persists. This lets an owner control later software without replacing the original trust anchor. How a particular product uses this model still depends on its implementation and key-management decisions.

How does device provisioning work?

Provisioning is the process of establishing a device’s identity and placing or associating the material it needs to operate securely. OpenTitan’s provisioning specification distinguishes creator personalization, performed during manufacturing, from owner personalization, which may take place during manufacturing or later after ownership transfer.

Rank #4
Sale
Yeiwenl TPM 2.0 Module with 20-1 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • Compatible with ASUS motherboards with 20-1 pin TPM header; Please check your motherboard manual to confirm the presence of a 20-1pin TPM header before purchasing. Not compatible with ASUS X570-P or other models with other TPM header
  • TPM 2.0 module 2.54mm pitch, 2x10P, 20-1 pin security module
  • LPC 20-1Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.If you are unsure whether your motherboard is compatible with our TPM module, please verify with us before making a purchase. Thank you.
  • Packing list:1x TPM 2.0 Module for ASUS (Doesn't fit the connector on a ASUS Prime X570-P motherboard)

The documented proposed flow involves a provisioning appliance, a hardware security module (HSM), device authentication, certificates, secrets, and a host transport chosen for the use case. This is not a universal recipe: the Device Provisioning specification is marked Pre-RFC, so its flow should be understood as a documented proposal rather than a generally deployed procedure.

Earl Grey or Darjeeling: which OpenTitan design fits?

The two named top levels reflect different deployment shapes. Earl Grey is a standalone, low-power secure microcontroller. Darjeeling is designed as an integrated secure execution environment for a larger system and can serve as a root of trust for a SoC, platform, or chiplet. The project describes their architecture in its product architecture documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
  • TPM modules are suitable for GIGABYTE for Windows 11 motherboards.
  • Some motherboards require a TPM module inserted or an update to the latest BIOS to enable the TPM option.
  • 12Pin Remote Card Encryption Security Module Is Easy To Use, No Complicated Procedures Are Required, And It Can Be Used Immediately After Installation.
  • Interface: LPC
  • Packing list:1x TPM 2.0 Module for GIGABYTE
Design Deployment shape and intended role Project-reported status
Earl Grey Standalone secure microcontroller. The OpenTitan top-levels page describes Earl Grey as in production. The current design documentation says it is work in progress and refers to Earl Grey 2; it directs readers to the earlgrey_1.0.0 branch for the first production-silicon design.
Darjeeling Integrated secure execution environment for a larger SoC; possible SoC, platform, or chiplet root-of-trust role. The top-levels page says Darjeeling is used in production devices by Rivos, while also saying further design verification is required.

These are project-reported status descriptions, not a blanket independent certification or guarantee for every implementation. Check which top level and design revision a product or technical document actually uses. The relevant status and architecture information is on the OpenTitan Top Levels and Product Architecture pages.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can you run OpenTitan on an FPGA?

Yes. The official setup guide describes running OpenTitan on an FPGA, including the ChipWhisperer CW340 as a target. The process requires a supported FPGA development board and the FPGA vendor’s tools; users can load a prebuilt bitstream or build one locally, then bootstrap demo software. The guide notes that HyperDebug is needed for some memory-programming and advanced test cases. Consult the current FPGA setup guide for supported targets and the applicable procedure.

An FPGA board emulates the design; it is not production OpenTitan silicon. This route is useful for exploring the design and running supported demonstrations, but it does not establish that an FPGA setup has the properties of a finished ASIC product. The Earl Grey design documentation distinguishes ASIC synthesis from FPGA targets and describes CW310/CW340-family emulation. It also identifies its current-branch design material as work in progress and points to earlgrey_1.0.0 for the first production-silicon design. For implementation-level work, match documentation and instructions to the branch or revision in use.

What OpenTitan does—and does not—establish

  • It does provide: open silicon designs and related hardware, software, security specifications, and tools for building root-of-trust capabilities.
  • It can support: lifecycle security functions such as verified startup, attestation, provisioning, updates, identity, and ownership transfer, when implemented and operated as intended.
  • It does not automatically provide: a turnkey IoT fleet-management service, a guarantee that every reference component is production-ready, or a certification claim for a product that integrates OpenTitan.

For an OT or IoT product team, the practical question is not simply whether a design uses OpenTitan. It is which top level and revision is integrated, what security functions the product actually implements, how keys and ownership are handled, and how firmware and the device lifecycle are maintained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
Compatible with TPM-M R2.0; Chipset: Infineon SLB9665; PIN DEFINE:14Pin; Interface:LPC
$19.99
SaleBestseller No. 2
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
TPM 2.0 module for Asus motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
$19.99
SaleBestseller No. 3
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
TPM 2.0 module for ASROCK motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
$23.74
SaleBestseller No. 4
SaleBestseller No. 5
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
Yeiwenl TPM 2.0 Encryption Security Module with 12 pin Compatible with Windows 11 for GIGABYTE Motherboard
TPM modules are suitable for GIGABYTE for Windows 11 motherboards.; Interface: LPC; Packing list:1x TPM 2.0 Module for GIGABYTE
$18.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.