Insyde®TapRUUT™Platform Root of Trust

Platform Root of Trust: Secure Firmware with Insyde TapRUUT

What is the Platform Root of Trust and how does it secure your platform?

TapRUUT is Insyde’s production-ready Platform Root of Trust — firmware resilience, standards-aligned attestation, and hardware-anchored security for PCs, servers, and data center platforms at scale.

 

Every chain of trust starts in firmware.

If the layer beneath the OS can’t prove it hasn’t been tampered with, nothing built on top of it can be trusted either. TapRUUT is Insyde’s production-ready Platform Root of Trust — firmware resilience and device attestation aligned with NIST SP 800-193, across Intel, AMD, NVIDIA, and Arm-based platforms.

Hardware-anchored

Hardware-anchored Built on leading PRoT silicon — ASPEED, Intel, Infineon, and Microchip Technology at launch.

Standards-aligned

NIST SP 800-193 resilience and SPDM 1.1/1.2 device attestation, not a proprietary approach.

Natively integrated

Works end-to-end with InsydeH2O® UEFI BIOS and Supervyse® OpenBMC — one chain of trust, not three.

The Problem

Firmware attacks don't show up in antivirus logs.

They persist across OS reinstalls, survive disk wipes, and run before security tooling even loads — making them some of the hardest compromises to detect and the most damaging to recover from."Root of Trust" isn't one part. It's an integration problem spanning silicon vendors, firmware layers, and management stacks that were never designed to speak the same language.

The Approach

A protect–detect–recover model, built in.

TapRUUT turns NIST SP 800-193 from a checklist into a working system: a hardware-anchored point of trust that verifies firmware integrity, detects tampering, and recovers a platform to a known-good state.It integrates natively with Insyde's own firmware stack, while remaining fully compatible with your existing OpenBMC implementation.

How It Fits Together

From silicon to fleet reporting, each layer has one job.

 

Root of Trust Hardware

PRoT-capable silicon from ASPEED, Intel, Infineon, or Microchip Technology.

TapRUUT Firmware Layer

Measurement, verification, update, and recovery logic anchored to that hardware.

Boot Firmware Integration

Native alignment with InsydeH2O® UEFI BIOS.

Management Firmware Integration

Native alignment with Supervyse® OpenBMC, or your existing OpenBMC implementation.

Attestation Layer

SPDM-based device attestation, provable to external parties.

Fleet & Compliance Tooling

A security posture that's auditable and reportable at scale.

What TapRUUT Delivers

Hardware-anchored security, standards-based attestation, and one architecture spanning boot and management firmware.

 

Hardware-Anchored Root of Trust

Support for leading PRoT silicon at launch — ASPEED, Intel, Infineon, and Microchip Technology.

NIST SP 800-193 Resilience

Secure firmware update and recovery mechanisms built around the protect–detect–recover model.

Device Attestation

Cryptographic attestation with SPDM 1.1 and 1.2 support — proof of firmware integrity, not just a claim.

Cryptographic Services & PQC

Modern cryptographic services, including post-quantum cryptography support on compatible hardware.

End-to-End Integration

Native integration with InsydeH2O® UEFI BIOS and Supervyse® OpenBMC, plus CPLD online update support.

Cross-Silicon Consistency

One security model across Intel, AMD, NVIDIA, and Arm-based platforms — no fragmented posture.

How is TapRUUT's Root of Trust approach built for future platforms?

The same Root of Trust approach, scaled to every platform that needs it.

 

AI PCs & AI Servers

A security foundation designed for the platforms carrying the industry's newest, most demanding workloads.

Hyperscale Data Centers

A consistent security model across mixed-silicon fleets, without a separate integration project per vendor.

Embedded & Edge Devices

The same Root of Trust approach, scaled down to platforms far from the data center.

Forward Compatibility

Active alignment with the CHIPS Alliance–driven OpenPRoT initiative, alongside AMD, Google, Intel, and Nuvoton.

Frequently Asked Questions

1 How does TapRUUT address the challenge of detecting and recovering from stealthy firmware attacks?

TapRUUT implements a protect-detect-recover model, anchored in hardware, to verify firmware integrity and detect tampering. It then recovers the platform to a known-good state, effectively countering attacks that bypass traditional OS-level security and persist across reinstalls.

2 What makes TapRUUT easy to integrate into existing embedded systems and development workflows?

TapRUUT is natively integrated with InsydeH2O® UEFI BIOS and Supervyse® OpenBMC, creating a single chain of trust across boot and management firmware. It also supports leading PRoT silicon from vendors like ASPEED, Intel, Infineon, and Microchip, ensuring broad compatibility.

3 Which industry standards does TapRUUT comply with for platform security and attestation?

TapRUUT is standards-aligned with NIST SP 800-193 for firmware resilience and SPDM 1.1/1.2 for device attestation. This ensures a non-proprietary, verifiable security posture across Intel, AMD, NVIDIA, and Arm-based platforms.

upbtn
Skip to content