- Target Market: Designed for billions of IoT devices, including smartwatches, fitness trackers, and sensors.
- Power Efficiency: Optimized for low-power, battery-operated devices with deep low-power states.
- Quantum-Resistant: Built-in support for post-quantum cryptography (PQC) algorithms like Kyber and Dilithium.
Experts would likely conclude that Peppermint represents a significant advancement in IoT security, offering a transparent, quantum-resistant, and power-efficient solution that addresses critical vulnerabilities in the rapidly expanding IoT ecosystem.
OpenTitan Unveils Peppermint: Quantum-Resistant Security for IoT
CAMBRIDGE, United Kingdom – August 25, 2026 – The OpenTitan project, a global coalition dedicated to building transparent and trustworthy hardware security, today announced a significant expansion of its portfolio with Peppermint. This new open-source silicon design is an integrated Root of Trust (RoT) meticulously engineered for the unique demands of area, cost, and power-constrained devices, a category that includes everything from smartwatches and fitness trackers to the billions of sensors and microcontrollers underpinning the Internet of Things (IoT).
An RoT serves as the immutable security foundation for a computing system, a hardware-based anchor that ensures the device boots securely and runs only authenticated software. While OpenTitan has already established its credibility with commercial-grade designs like Earl Grey for Google Chromebooks and Darjeeling for data center servers, Peppermint marks a strategic push into a more challenging and diverse market. It is designed to handle critical tasks such as secure boot, firmware updates, and cryptographic operations while consuming minimal energy, a crucial feature for battery-powered devices.
Beyond Servers: A New Frontier for Hardware Security
The introduction of Peppermint signals OpenTitan's ambition to provide a unified security architecture across the entire computing spectrum. The project, stewarded by the non-profit lowRISC C.I.C., recognizes that the security principles proven in servers and laptops are just as vital, if not more so, for the personal and often physically exposed devices we are beginning to rely on daily.
Early adoption interest from companies like Sesame AI, which is developing intelligent eyewear, highlights the pressing need for this technology. “Security and privacy are foundational at Sesame. We’re asking people to wear our intelligent eyewear all day, and that only works if they trust it,” said Ryan Brown, Head of Hardware at Sesame AI. “Building in the open, with lowRISC and the OpenTitan community, means people can validate our approach for themselves.”
Wearable devices present a unique security conundrum. They are physically vulnerable, collect highly sensitive personal data, and must operate for long periods on tiny batteries. Peppermint addresses this by integrating directly onto a device's main System-on-Chip (SoC), remaining in a deep low-power state for most of its operational life and waking only when needed to perform a security function. This efficiency makes robust, hardware-backed security feasible for product categories where it was previously considered too costly in terms of power, size, and price.
The Open-Source Advantage in a High-Stakes World
In an industry where security components are often proprietary 'black boxes', OpenTitan champions a different philosophy. By developing its silicon designs in the open, the project allows anyone—from academic researchers to competing hardware vendors—to inspect, audit, and contribute to the source code. This transparency is Peppermint's core competitive advantage.
“Cybersecurity is a huge concern that affects everyone, cutting across country and organisational boundaries,” said Javier Orensanz Martinez, CEO of lowRISC. “Open silicon is quickly becoming the security foundation for the semiconductor industry. With the release of Peppermint, OpenTitan is demonstrating its versatility to deliver a hardware security solution for multiple types of devices and use cases."
This collaborative model fosters a cycle of continuous improvement. Vulnerabilities can be identified and fixed transparently, and the design is hardened by a global community of experts. For device manufacturers, this provides a higher degree of assurance and reduces reliance on a single vendor's security claims. For consumers, it offers the potential for verifiably trustworthy technology, a critical factor as smart devices become more integrated into our lives.
Engineering a 'Tiny' Fortress: Inside Peppermint's Design
Achieving a high level of security within a minimal power and area budget required significant engineering innovation. While the full design of Peppermint is planned for the latter half of 2026, it will build upon OpenTitan's existing, proven IP blocks. The architecture is centered around Ibex, a small, efficient, and formally verified 32-bit RISC-V processor core, which serves as the RoT's brain.
To minimize its footprint, Peppermint is not a standalone chip but an IP block designed for tight integration within a larger SoC. Its architecture is carefully partitioned into 'always-on' components, which are minimal, and larger sections that can be completely power-gated, drawing virtually no energy when inactive. This allows the main application processor to offload all security-critical operations—from verifying a firmware update to generating a cryptographic signature—to a dedicated, hardened, and efficient hardware block.
This approach ensures a strong isolation between the secure world, managed by Peppermint, and the rest of the system. Even if the main operating system is compromised by malware, the hardware RoT remains protected, preserving the device's fundamental integrity and ability to be securely recovered.
Preparing for the Quantum Threat on the Edge
Perhaps the most forward-looking feature of Peppermint is its built-in readiness for the era of post-quantum cryptography (PQC). Security experts warn of a "harvest now, decrypt later" threat, where adversaries capture today's encrypted data with the intent of breaking it years from now with a sufficiently powerful quantum computer. For IoT devices with lifecycles spanning a decade or more, this is not a distant threat but an immediate design consideration.
Peppermint will incorporate hardware acceleration for PQC algorithms compliant with the CNSA 2.0 (Commercial National Security Algorithm Suite 2.0) standard. This includes native support for ML-KEM (Kyber) for key establishment and ML-DSA (Dilithium) for digital signatures, the algorithms selected by the U.S. National Institute of Standards and Technology (NIST) to withstand quantum attacks.
Executing these complex algorithms efficiently on a low-power device is a major challenge. OpenTitan addresses this by extending its OpenTitan Big Number (OTBN) accelerator, a specialized co-processor designed for cryptographic computations. This hardware acceleration provides a substantial speed-up over software-only implementations, making quantum-resistant cryptography practical for even the smallest edge devices. Furthermore, these PQC implementations are being hardened against physical side-channel and fault injection attacks, ensuring the security holds up not just in theory, but in the real world.
Topics & Related
Cybersecurity & Privacy
Semiconductors
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →