Trusted AI agents must be anchored within silicon wafers.
PR Newswire
1h ago
Ai Focus
As the AI agent begins to perform operations on behalf of users, eMemory's subsidiary PUFsecurity believes that device identity, remote authentication, and protected on-chip state will determine its credibility. The company states that the security of trusted AI agents ultimately depends on the hardware root of trust within the chip.
Helpful
No.Help

Trusted AI proxies must be anchored within the silicon wafer.

As the AI agents begin to act on behalf of users, PUFsecurity, a subsidiary of eMemory, believes that device identity, remote authentication, and protected on-chip state will determine to what extent these agents can be trusted.

San Jose, California, USA, October 9, 2026 / PRNewswire / -- The first wave of generative AI is answering questions and generating content, but it is still up to humans to decide how to use this content. Proxy-based AI goes a step further: AI proxies can book trips, send emails, fill out forms, and make purchases [1], often doing so while users are busy with other things. eMemory Technology's subsidiary PUFsecurity believes that this change also alters where trust must come from. In a new tech perspective article titled " Building Trusted AI Agents from the Sil Token Issuance n Root of Trust ", the company explains that the security of such proxies ultimately depends on the hardware root of trust in the chips that run them.

Proxying increases risk.

Chatbot-generated content is subject to human decision on how to handle it; whereas agents will take action based on their own output. It runs continuously, holds delegate credentials, browses web pages, executes code, and invokes connected services.

In the view of PUFsecurity, this changes the cost when a system is breached. When a chatbot is misled, the result is just a wrong answer, and people still have a chance to detect it; however, when an agent is misled, it may take action using user credentials before anyone can check.

Software isolation is necessary, but it depends on the platform.

Muse clearly demonstrates how the industry addresses proxy security issues. According to Meta, each user's proxy runs within a dedicated cloud virtual machine (VM), in an isolated runtime environment with its own file system and network interface. An independent Sentinel proxy is the sole authorized entity for outbound network operations and connector management. The code within this unit can only access substitute tokens; the actual credentials are replaced only at the network boundary, after the request has been approved [2].

Meta also clearly outlines the next steps. The company stated that the launch of Secure VM "will not prevent Meta from accessing data when necessary to support, protect, or operate the service" [2], and they plan to introduce Muse Confidential VM. In this version, the entire VM will be encrypted, with the keys being held solely by the users [1].

PUFsecurity points out that this step relies on hardware. The security of the software boundaries shared on the same host is only as strong as the platform beneath it; whereas the keys held solely by users can be securely released only when the platform can prove its authenticity and has started up as expected with the correct software.

Years of collaboration with Arm

This type of certification originated in the field of processors, where PUFsecurity has been collaborating with Arm for many years. In 2022, Arm selected PUFsecurity's hardware trust root IP —– PUFrt [3] – in the security subsystem of its Armv9 Confidential Compute Architecture reference implementation. Subsequently, eMemory joined Arm Total Design and adopted PUFrt as the hardware trust root within Arm Neoverse Compute Subsystems ( CSS ), specifically for Runtime Security Engine ( RSE ).

Arm The latest data center processors are built on the same platform. Arm It is positioned for proxy-based AI infrastructure, with Arm AGI CPU [4] constructed upon Neoverse CSS V3, and RSE serves as its trust root [5].

Remote proof requires an identity that is bound to hardware.

For proxy platforms, the party that needs to provide proof is usually located remotely: it could be the service that decides whether to unlock the user's confidential VM key, or it could be the cluster controller that determines whether a certain server can run the proxy workload. Remote proof provides this kind of verification. The device will generate a report by signing its startup content, and the verifying party will compare this report with the expected values before releasing any secrets [6].

There are three key attributes involved here: identity, which is used to determine which physical device is running the workload; integrity, which is used to record what actually started; and confidentiality, which is used to ensure that secrets only reach verified environments. PUFsecurity points out that the entire chain depends on one detail: the credibility of the report is only as good as the credibility of the signing key. If the compromised software is able to read or forge this key, then the report loses all its probative value. The signing identity must be anchored in the silicon chip itself.

The number of trust roots in data centers is increasing.

Data center processors are increasingly integrating trust roots directly into the chip die, and modern designs often contain more than one. As demonstrated in Hot Chips 2026 by Arm, Arm AGI CPU consists of two computing chiplet; each chiplet has its own RSE and also supports Arm Realm Management Extension. This constitutes the hardware foundation for Arm confidential computing [5]. Therefore, there are two trust roots within a single package, and a dual-core server would have four.

CPU is just a part of the whole. Meta indicates that limited data will leave Muse VM for reasoning [2]; therefore, prompts and context will also enter accelerators, network interfaces, and storage. The security model of Open Compute Project ( OCP ) requires that each device have a root of trust and report its integrity through remote proof [7]. The Caliptra of OCP incorporates this function within the silicon chip, serving as an integrated root of trust module for data centers such as CPU , GPU , and DPU [8]. With the emergence of multi-supplier chiplet designs, industry efforts led by Arm and contributed to by OCP ( FCSA ) are addressing how components from different suppliers [BJWKEEP_00017__ ] can be coordinated to start up and protect the entire system [9].

Common security primitives are located at the underlying level.

These architectures vary, but PUFsecurity believes that the fundamental capabilities required at their core are the same. Regardless of whether the chip uses Arm's RSE, Caliptra, or a proprietary design, their trust roots all require a device-specific secret that is protected in a static state, a high-quality entropy source, as well as secure non-volatile storage for states that must be preserved across power-off cycles (such as lifecycle states and revocation data).

Caliptra illustrates this point very well. Its specification anchors the device identity to a unique secret generated by on-chip entropy and stored in a one-time programmable fuse, and then expands this secret into a DICE ( Device Identifier Composition Engine ) identity chain for remote verification [8][10].

PUFrt: The Silicon Foundation of Trusted Agents

PUFrt integrates these primitives into a single hardware trust root IP. Its 1024-bit physically unclonable function (PUF) derives a unique device value from the natural variations of the silicon chip, providing four 256-bit fingerprints that can be used as unique identifiers or seed values for root keys [11]. Since the secret comes directly from the silicon chip itself, there is no need to inject it during the manufacturing process; PUFsecurity believes that this becomes increasingly important as chiplet from multiple suppliers are assembled into a single package.

PUFrt also includes a true random number generator, as well as secure storage based on NeoFuse, anti-fuse, and OTP. The process range provided by eMemory ranges from 0.15 micrometers to 3 nanometers [13], with 2 nanometers also under development [BJWKEEP_00007__]. Combined with anti-tampering protection, these features support secure startup, secure debugging, entropy generation, and key configuration, among other functions [11][12].

Building Trust from the Silicon Chip Upward

Generative AI generates content. AI agents take action on this content and continue to operate with increasing autonomy, performing tasks on behalf of users. In the view of PUFsecurity, the next step is physical AI. At this stage, the same level of autonomy will drive robots, vehicles, and industrial machines, and the misdirected systems could result not only in digital losses but also potential physical harm.

Software protection is making rapid progress at every stage. However, the ultimate guarantee—ensuring that keys and permissions are only released to a platform that can prove who it is and what it has initiated—must come from hardware, from every chip along the path, from data centers all the way to edge devices.

The complete article " Building Trusted AI Agents from the Sil Token Issuance n Root of Trust " can be viewed here.

Reference materials

Tip
$0
Like
0
Save
0
Views 22
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
KONST Raises $30 Million in Series B Financing, Led by ADATA Technology to Expand Data Centers in Asia and Advance Token Factory Strategy
KONST Announces Completion of $30 Million Series B Financing, Led by ADATA Technology, with Participation from M Mobility, Pegatron Venture Capital and Other Corporate Investors. The Company Says It Will Use the Funds to Expand the Construction of AI Data Centers in Asia and Accelerate the Token Factory Strategy to Meet the Adoption Needs of Enterprises AI.
PR Newswire
·2026-10-09 23:36:21
9
Ethereum price hovering around the $2,500 mark, Supertrend shifts to bearish stance
Ethereum prices rebounded to around $2,493 after briefly falling to $2,400, but the daily Supertrend indicator has turned bearish, and the 4-hour chart still shows negative capital flows. US spot Ethereum ETF has seen a net outflow of $486.1 million over four consecutive trading days. In the short-term technical outlook, $2,500 and $2,569 remain key resistance levels.
crypto.news
·2026-10-09 23:26:15
16
Ledger Investigation into the Theft of Cryptocurrency Assets
Encrypted hardware wallet manufacturer Ledger stated that they have launched an investigation into reports of customer funds being stolen from authorized distributors in Southeast Asia. The company has requested that the Malaysian distributor CryptoBilis suspend sales and deliveries, and reminded customers who purchased products from this distributor within the past 90 days not to initialize their wallets; if they have already initialized them, it is recommended to transfer their encrypted assets to a new Ledger wallet and use a new recovery phrase. CZ believes that this incident may involve a supply chain attack.
U.Today
·2026-10-09 23:26:11
15
Bank of America appoints Jeff Crabtree as President of the Sarasota/Manatee Region
Bank of America announces that Jeff Crabtree, the regional head of the Consumer Banking area, has been appointed as President of the Sarasota/Manatee region, succeeding Stephenie Whitfield who was recently transferred to Georgia for a new position. Crabtree will continue to serve as the regional head of the Consumer Banking area as well, leading the company in expanding market share and customer relationships locally.
PR Newswire
·2026-10-09 23:17:36
16
The State Council issues "Opinions on Developing New Productive Forces": Accelerating the Promotion of Applications in New Generation Intelligent Terminal Scenarios Such as Intelligent Connected New Energy Vehicles, Artificial Intelligence Phones and Computers, and Humanoid Robots
The Central Committee of the Communist Party of China and the State Council issued the "Opinions on Developing New Productive Forces," outlining 19 major tasks for development and reform, with "vigorously promoting scientific and technological innovation" listed as the top priority among these tasks. The document proposes to accelerate the development of strategic emerging industries such as new-generation information technology, new energy, robotics, biomedicine, high-end equipment, and aerospace. It also foresees the layout of future industries including quantum technology, hydrogen energy, nuclear fusion energy, brain-computer interfaces, embodied intelligence, and 6G. At the same time, a comprehensive implementation of the "Artificial Intelligence+" initiative is carried out to advance the application of new-generation intelligent terminals such as intelligent connected new energy vehicles, artificial intelligence smartphones and computers, and humanoid robots.
The Block
·2026-10-09 23:07:41
14
View More