Unibap SEQR
Unibap SEQR establishes a hardware-backed chain of trust spanning boot, operation, updates, and recovery to protect mission-critical computing platforms and data.
Technical specifications
- High-Throughput SHA-3 Hashing
- 100 Gbps+
- APU AES-NI Acceleration
- >40 GB/s
- Post-Quantum Cryptography Support
- ML-KEM-1024
About
Unibap SEQR is a secure platform designed to protect mission-critical computing platforms and data. It establishes a hardware-backed chain of trust spanning boot, operation, updates, and recovery. The platform ensures secure data by protecting mission data with encryption, signing, and hardware-rooted key management, guaranteeing confidentiality and integrity from collection to delivery. Unibap SEQR is developed and maintained through cybersecurity processes aligned with leading international standards, regulations, and assurance frameworks.
Key features include a layered secure boot chain (FPGA → UEFI/BIOS → Kernel), a hardware root of trust based on FPGA eFuse AES and ESA/ECDSA keys, and AMD fTPM secure boot. It employs a Zero Trust model where the APU/OS is isolated from the FPGA, allowing only signed updates for critical FPGA functionality. Compartmentalization is achieved through AppArmor MAC enforcement and per-channel SDMA permissions. Memory and disk encryption are handled by TSME for DDR and fTPM for disk encryption keys. Tamper-proof audit logging flows security events from APU to FPGA to MRAM in AES-GCM sealed slots. Secure OTA updates with ZFS rollback and OS & service hardening (DISA-STIG compliance, systemd sandboxing) are also integrated.
For data security, Unibap SEQR offers FPGA source data signing, real-time FPGA AES-GCM encryption on data streams, and an in-fabric FPGA AES-GCM Crypto Engine without key exposure. It supports high-throughput SHA-3 Hashing (100 Gbps+) for data integrity, APU AES-NI acceleration (>40 GB/s AES-256-GCM encryption throughput), and Post-Quantum Cryptography Support (ML-KEM-1024 key exchange). Active key zeroization and ground-to-FPGA signed configuration for critical platform changes are also provided, alongside encrypted audit log export with per-entry authentication.
Documentation
Need the full ICD, test reports or a specific revision? Ask the supplier directly.