1024x1024 SecureSPOT BG
1920x980 SecureSPOT BG1920x980 SecureSPOT

secureSPOT: Embedded Security for Apollo SoCs

Design Securely

1024x830 SecureSPOT

In an increasingly connected world, device security plays a vital role in safeguarding sensitive data, preserving privacy, and upholding the integrity of digital systems and communications. Ambiq secureSPOT® solution addresses these essential concerns by delivering a comprehensive suite of security features without compromising device performance or battery life. secureSPOT 3.0 builds on this with Arm® TrustZone®, adding Secure Boot, encrypted Secure Peripherals, controlled Secure Debug access, and Secure Lifecycle Management across the full device lifecycle.

secureSPOT 3.0 Highlights

01

Secure Boot

Enhanced security with root of trust ensures that only authenticated and trusted firmware is loaded during device initialization, safeguarding against unauthorized/malicious code execution from the boot process onwards.

02

Secure Peripherals

Bolstered protection through hardware-based security features like encryption, authentication, and access control, ensuring data integrity and confidentiality in peripheral operations.

03

Secure Debug

Controlled and authenticated access to debugging interfaces, ensuring that only authorized users can access and interact with the device during development.

04

Secure Lifecycle Management

Ensure the integrity and security of the device throughout its lifecycle, from manufacturing and provisioning to deployment and decommissioning, mitigating risks and vulnerabilities at every stage.

Security Centered

Our products are specifically engineered to serve a diverse array of applications, encompassing wearables, medical devices, smart home technologies, IIoT solutions, and more.

Technology Bg L scaled

Specifications

Apollo510 mockup white

secureSPOT 3.0 with Arm® TrustZone®

  • Secure Boot
  • Extensible to Custom Secondary Boot Loader
  • Secure/Non-Secure True Random Number Generator (TRNG)
  • Trusted Execution Environment
  • Anti-Tamper Protection
  • Secure Peripherals
  • PUF-based Identity/Sign/Verify
  • Key Revocation
  • Flash protections (copy and write protection)
  • Hardware cryptographic acceleration
  • Hardware Keys (Inaccessible to software)
  • Secure Upgrade (OTA)
  • Wired Interface Support
  • Anti-Rollback
  • Encryption support for updates
  • Recovery (factory reset)
  • Hardware Entropy
  • Security Lifecycle Management
  • Secure Debug
  • OTP Support
  • Secure Key Storage
Apollo4 Plus SoC

secureSPOT 2.0

  • Secure Boot
  • Extensible to Custom Secondary Boot Loader
  • True Random Number Generator (TRNG)
  • Key Revocation
  • Flash protections (copy and write protection)
  • Hardware cryptographic acceleration
  • Hardware Keys (Inaccessible to software)
  • Secure Upgrade (OTA)
  • Wired Interface Support
  • Anti-Rollback
  • Encryption support for updates
  • Recovery (factory reset)
  • Hardware Entropy
  • Security Lifecycle Management
  • Secure Debug 
  • OTP Support 
  • Secure Key Storage
Apollo3 Blue Plus

secureSPOT 1.0

  • Secure Boot
  • Extensible to Custom Secondary Boot Loader
  • Key Revocation
  • Flash protections (copy and write protection)
  • Secure Upgrade (OTA)
  • Wired Interface Support
  • Anti-Rollback
  • Encryption support for updates
  • Recovery (factory reset)
  • Hardware Entropy
  • Debugger Lockout Support

Design Resources

Browse our Design Resources which includes product briefs, datasheets, selector guides, family brochures, white papers, quick start guides, and more to help you learn more about products.

Additional Documentation

  • Set favorites
  • Get update notifications
  • Use search filters

Video Library

hqdefault
hqdefault

Frequently Asked Questions (FAQ)

  • secureSPOT® is Ambiq’s hardware-based security technology for Apollo ultra-low-power SoCs. It provides a comprehensive platform for embedded device security, including Secure Boot, Secure Peripherals, Secure Debug, Secure Lifecycle Management, and Trusted Execution capabilities. secureSPOT helps protect firmware, sensitive data, cryptographic assets, and device integrity while maintaining the ultra-low-power performance required for battery-powered edge devices. 

  • secureSPOT® 3.0 introduces support for Arm® TrustZone®, an extensible secondary boot loader, a Trusted Execution Environment (TEE), a secure and non-secure True Random Number Generator (TRNG), and Anti-Tamper Protection. These capabilities build on the security foundation established in secureSPOT 2.0 and 1.0 to provide stronger isolation, more flexible secure boot, and enhanced protection for modern edge AI and embedded applications. 

  • secureSPOT® secure boot establishes a hardware root of trust that verifies firmware authenticity before execution. Only authenticated and trusted software is allowed to boot, helping prevent unauthorized firmware, malicious code injection, and device compromise during system startup. 

  • secureSPOT® secure peripherals use hardware-based encryption, authentication, and access control to protect communications between the processor and connected peripherals. These protections help maintain data confidentiality, integrity, and isolation while reducing the risk of unauthorized access to sensitive device resources. 

  • Secure Debug provides authenticated, controlled access to hardware debugging interfaces during development and manufacturing. By restricting debug access to authorized users, secureSPOT® helps prevent unauthorized firmware extraction, device manipulation, and security bypass in production devices. 

  • Secure Lifecycle Management protects devices throughout their entire lifecycle—from manufacturing and secure provisioning through deployment, firmware updates, maintenance, and decommissioning. It enables organizations to securely manage device state and credentials while reducing security risks across manufacturing and field operations. 

  • SecureSPOT® is supported on Ambiq Apollo generations 3 through 5, including Apollo3, Apollo4, and Apollo510 series SoCs. Support will continue to expand with future Apollo platforms. 

  • secureSPOT® is designed for battery-powered embedded devices that require strong hardware security, including wearables, medical devices, smart home products, industrial IoT (IIoT) systems, asset trackers, and edge AI devices. 

Preparing to download