ELECTRONICS·INSIDER
All stories
Semiconductors

GlobalPlatform launches Pavona, the first open-silicon distribution with production-grade post-quantum cryptography, on 26 May 2026

GlobalPlatform launched Pavona on 26 May 2026 - an open-source silicon distribution with 12 founding members, two TSMC 3 nm taped-out root-of-trust designs, and the first openly available PQC stack for embedded silicon.

Generated image

GlobalPlatform launched Pavona on 26 May 2026 - an open-source silicon distribution that ships production-quality, certification-ready IP components alongside the first openly available post-quantum cryptography (PQC) stack for embedded silicon. The project is hosted by GlobalPlatform and governed by a board chaired by Dominic Rizzo, CEO and founder of zeroRISC[1].

What Pavona ships on day one

The distribution is not a concept or a roadmap. It includes two successfully taped-out reference designs - a standalone chip root of trust and an integrated root of trust for chiplet architectures - both fabricated at TSMC 3 nm (N3). The full IP repository, top-level designs, continuous-integration dashboards, and getting-started documentation are publicly available at pavona.org.

The starting IP kit is built on OpenTitan components. OpenTitan provides a hardware root-of-trust - a chip-level security anchor that serves as the foundation for all secure operations in a system[1]. Pavona extends those components with PQC accelerators targeting the newly standardized ML-KEM and ML-DSA algorithms. Research from a multi-year collaboration between ZeroRISC, the Max Planck Institute for Security and Privacy, and Academia Sinica - presented at Real World Crypto 2026 in Taipei - showed 6-9× performance improvements for those algorithms on embedded silicon, with near-zero area cost.

The framework is aligned with FIPS 140-3, SESIP, and Common Criteria certification requirements from the outset, which is intended to shorten the compliance path for end products rather than treating certification as a late-stage exercise.

A modular composition engine, not a monolithic design

The central technical contribution is what Rizzo's team calls an architectural composition engine. It wraps the open-hardware IP so that it can interface with different computing cores - ARM or RISC-V - without requiring changes to the surrounding software stack[1]. The goal is to make secure silicon components behave like interchangeable modules:

  • A small IoT device can pull in a minimal root-of-trust subsystem.
  • A data-center SoC can assemble a larger, chiplet-integrated configuration.
  • An automotive controller can select components aligned to its specific certification tier.

This modular approach distinguishes Pavona from earlier open-hardware security efforts, which tended to produce single-use, monolithic designs that were difficult to repurpose across markets.

Twelve founding members span the supply chain

Twelve founding members committed at launch: Agile Analog, Analog Devices, Baochip, CrossBar, Max Planck Institute for Security and Privacy, Meta, SIMPLE Crypto Association, Qualcomm Technologies, Tenstorrent, University of Oxford, Winbond Electronics, and ZeroRISC. The mix covers IP providers, memory vendors, AI-chip companies, and academic research institutions. Governance follows a model similar to Yocto and Zephyr: a governing board funds the project while an independent Technical Steering Committee owns the technical roadmap.

The breadth of the founding cohort matters for a project whose value proposition depends on community scrutiny. Security hardware benefits from openness precisely because public inspection by a broad community can surface vulnerabilities that a closed, proprietary design would obscure[1].

Whether Pavona can sustain that community - and whether the composition engine proves flexible enough to cover the full range of claimed targets from constrained IoT to AI-accelerator chiplets - will determine how quickly the distribution moves from reference designs into production silicon at scale.

Written by Electronics Insider's automated desk from the sources above and published automatically. How we work.

Related