Ambimat GroupAmbimatAmbiSecureV2XeSIM & eUICCAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
Solution

Embedded secure element integration — the chip in the product.

A secure element is the trust anchor. Picking the right one, integrating it into a product, and operating it through the product's lifecycle are three different problems. AmbiSecure handles all three — from chip selection through firmware, applet, personalisation, and field rotation.

What is an embedded secure element?

An embedded secure element is a tamper-resistant chip that sits on your product's BOM and does one job: hold key material and run cryptographic operations on it without the keys ever crossing onto the host. The application MCU asks the secure element IC to sign, verify, or derive; it never sees the private key. That boundary is what makes the device identity survive firmware extraction.

The chip's physical packaging, side-channel countermeasures, and on-die verifier resist attacks — differential power analysis, fault injection, microprobing — that would trivially break software-only crypto. Secure elements are not general-purpose processors: they do a small number of operations very securely, and they do not run application code the way an MCU does.

Use cases where an embedded secure element is the right choice:

  • FIDO2 / WebAuthn authenticators (smart card, USB key, embedded SE in phone).
  • Payment terminals (EMV chip-and-PIN, EMV contactless).
  • Connected vehicles (V2X HSMs, automotive cybersecurity).
  • Industrial IoT root-of-trust.
  • eSIM / iUICC for cellular authentication.
  • Document signing terminals (eIDAS qualified signatures).

What an embedded secure element integration covers

SELECTION

Chip selection

Match SE family to security tier (CC EAL6+ vs EAL4+), interface (ISO 7816, ISO 14443, SPI, I2C), throughput, certifications.

FIRMWARE

Host driver

Driver on the host MCU / SoC for talking to the SE. APDU framing, secure channel (SCP03), session management.

APPLET

SE-side applet

JavaCard applet running on the SE. Custom or off-the-shelf (FIDO, PIV, OpenPGP). Designed for the product's threat model.

LIFECYCLE

Field operations

Issuance, key rotation, applet update under SCP03. Telemetry for tamper detection.

Secure element families we integrate

NXP

NXP SmartMX

JavaCard 3.x, GlobalPlatform 2.3.1, CC EAL6+ on flagship variants. Used in OnePass Card.

Infineon

Infineon SLE / SLJ

JavaCard, CC EAL6+ / EAL6+. Strong eID / payments deployment history.

STMicro

ST33 family

CC EAL6+ secure microcontrollers. Embedded SE common in IoT root-of-trust.

Multi-vendor

Vendor-agnostic integration

For customers wanting to dual-source. We handle abstraction at the host-driver layer.

Secure element vs TPM vs HSM

All three are “hardware that stores keys”, and they are not interchangeable. The question is not which is strongest — it is which one belongs in the architecture you are building.

  • Secure element — lives inside the device, on its BOM. Built for per-device identity at low throughput. This is the one you embed in a product.
  • TPM — lives on a PC or server motherboard. Built for platform attestation and measured boot, binding keys to a machine's software state.
  • HSM — lives in a rack. Built for bulk server-side crypto, CA roots and key-management systems, at thousands of operations per second.

A connected product that needs its own identity wants a secure element; a fleet-management backend signing on behalf of that product wants an HSM. They frequently appear in the same system.

Secure Element vs TPM vs HSM — where each fits works through the boundaries, certifications and deployment contexts in full.

Frequently asked questions

What is an embedded secure element?

An embedded secure element is a tamper-resistant chip on a product's bill of materials whose only job is to store key material and perform cryptographic operations on it. The host MCU sends it operations to perform; the private keys never leave the chip. Secure elements are certified at the chip class level — Common Criteria EAL6+ is typical for the silicon and its operating system — and resist physical attacks such as differential power analysis, fault injection and microprobing.

What is included in a secure-element integration project?

Four workstreams: chip selection against your security tier, interface and certification requirements; the host-side driver that talks to the secure element, including APDU framing and an SCP03 secure channel; the SE-side applet, either custom or an off-the-shelf FIDO, PIV or OpenPGP applet; and field lifecycle — issuance, key rotation and applet update under SCP03.

Which secure element families can AmbiSecure integrate?

NXP SmartMX, Infineon SLE / SLJ and the STMicroelectronics ST33 family, all of which run JavaCard and GlobalPlatform. We also do vendor-agnostic integrations for customers who want to dual-source, handling the abstraction at the host-driver layer.

When should a product use a secure element instead of a TPM or software key store?

Use a secure element when the device itself needs a hardware-bound identity that survives firmware extraction, and the operation rate is low. Use a TPM when you need to attest a PC or server platform's boot state. Use an HSM when the cryptography is server-side and high-throughput. A software key store is appropriate only where the threat model genuinely tolerates key extraction.

Embedding a secure element in your product?

We have shipped silicon-to-cloud integrations across smart cards, USB authenticators, payment terminals, IoT gateways, and connected vehicles. Tell us your platform and constraints.

Discuss a secure-element integration