-
产品
应对不断发展的物联网威胁的行业领先安全性
保护物联网是一项挑战,也是一项关键任务。在整个产品生命周期中,设备制造商都面临着保护连接设备免受频繁出现的物联网安全漏洞的挑战。在互联世界中保护您的产品是必要的,因为客户数据和现代在线商业模式越来越成为代价高昂的黑客和企业品牌损害的目标。为了保持安全,设备制造商需要在硬件、软件、网络和云中建立基础安全平台。我们可满足您的需求。
Secure Vault
Secure Vault™ 包含一整套业界前沿的先进安全功能,可解决不断升级的物联网 (IoT) 威胁,极大降低物联网生态系统安全漏洞风险,降低因仿冒导致的知识产权或收入损失的影响。具体而言,Secure Vault 技术:
- 防止可扩展的本地和远程软件攻击
- 防御本地硬件攻击,尽管从历史上看,本地硬件攻击不如软件攻击常见,但由于攻击工具成本较低且易于获得,致使此类工具激增,进而导致本地硬件攻击也呈上升趋势
- 通过独立第三方实验室的测试,这些实验室试图在指定时间内使用复杂的设备入侵安全功能
哪种安全级别适合您?
-
高
-
中级
-
基础
Secure Vault - 高
通过保护通信信道和设备本身免受逻辑和物理攻击向量,获得设备最高安全性。除了 Vault-Mid 功能外,还使用物理不可克隆功能 (PUF) 对密钥进行封装,每台设备都有对自身进行唯一标识的私钥,并且设备还具有高级篡改检测设置,可保护设备免受任何物理形式的篡改。
Secure Vault - 中级
通过确保对通信信道的保护和防逻辑攻击向量,来提供高级别安全性。除了 Vault-Base 功能外,得益于具有信任根和安全加载器 (RTSL) 的安全启动顺序,设备也运行有经过身份验证的固件。设备还具有安全调试功能,可确保只有经过身份验证的人员才能够调试设备。Secure Vault-Mid 部件还包括 TrustZone 支持功能*。TrustZone 支持功能可使密钥和其他应用程序固件的存储受到保护。
*目前,所有 BLE 设备上均提供 TrustZone 支持功能,计划在不久的未来,会将此支持功能发布到
所有其他协议栈。
Secure Vault - 基础
通过保护两台设备之间的通信信道并加密信道中流动的数据,在设备上提供良好级别的安全性。此层的显著特征包括安全应用程序启动、经验证的加密引擎和真随机数发生器 (TRNG) 功能。
Silicon Labs 物联网产品安全
| 特点 | 3 系列 Secure Vault™ |
高 | 中级 | 基础 |
| 安全框架 | PSA 4 级 认证 |
PSA 3 级 认证 |
PSA 2 级 认证 |
PSA 1 级 认证 |
| 真随机数发生器 | ✔ | ✔ | ✔ | ✔ |
| 加密引擎 | ✔ | ✔ | ✔ | ✔ |
| 安全应用程序启动 | ✔ | ✔ | ✔ | ✔ |
| 安全引擎 | HSE | HSE | VSE/HSE | — |
| TrustZone | ✔ | ✔ | ✔ | — |
| RTSL 安全启动 | ✔ | ✔ | ✔ | — |
| 带锁定/解锁的安全调试 | ✔ | ✔ | ✔ | — |
| DPA 应对措施 | ✔ | ✔ | 选择 OPN | — |
| 防篡改 | ✔ | ✔ | — | — |
| DFA 检测 | ✔ | — | — | — |
| 经过验证的 XiP (AXiP) | ✔ | — | — | — |
| 安全认证 | — | ✔ | — | — |
| 安全密钥管理 | ✔ | ✔ | — | — |
| 高级加密 | ✔ | ✔ | — | — |
-
认证
在 Silicon Labs,安全性是我们设计、开发和交付无线技术的核心基石。
信息安全是我们的当务之急,也是我们日常运营工作的重要组成部分。随着全球互联程度不断加深,每一台设备、每一个网络、每一套生态系统的运转都离不开信任的支撑。我们遵循行业惯例、力求与标准保持一致,并在技术架构的每一层嵌入安全防护机制,以此保障数据、设备及相关使用者的安全。凭借深厚的工程技术积淀、诚信正直的企业文化与持续改进的坚定承诺,我们确保创新与安全协同并进——让每一次连接都兼具智能与安全双重属性。
点击此处,了解我们如何凭借经认证的信息安全管理体系 (ISMS) 及全公司对安全的坚定承诺,践行最高标准的安全要求。
Silicon Labs 的 ISO 27001:2022 证书
我们对安全的坚定承诺,已通过 ISO 27001:2022 认证得到印证。此项认证证实,我们的安全实践符合全球最严格的信息安全管理国际标准之一。Silicon Labs 已通过北美 TÜV Rheinland 的 ISO 27001:2022 标准认证。
-
CRA
CRA Readiness that is Built on Secure Product Design, Lifecycle Governance, and Coordinated Vulnerability Handling.
Silicon Labs is reviewing and updating our existing products, processes, and supporting documentation to ensure conformance with the European Union Cyber Resilience Act (CRA). Our approach combines secure-by-design development, product security governance, public vulnerability handling, and evidence-backed readiness activities across the product lifecycle.
Our Commitment to the Cyber Resilience Act
The CRA determines horizontal cybersecurity requirements for products with digital elements placed on the EU market. It raises expectations for secure development, vulnerability handling, user information, technical documentation, and lifecycle support.
Silicon Labs will ensure conformance to our applicable CRA obligations for secure product lifecycle controls, documentation, PSIRT operations with coordinated vulnerability handling, and internal practices. These practices have already been in place, based on other security standards, certifications, and/or frameworks.
This page is designed to communicate that readiness while linking visitors to the official regulation text, relevant certification pages, product security resources, and reporting channels.
Why This Matters
Product manufacturers need confidence that their silicon and software suppliers can support secure deployment, vulnerability response, software transparency, and lifecycle maintenance under tightening global regulations.
CRA Milestones
CRA Key Topics
Cyber Risk Assesment
Silicon Labs drives pro-active Risk Assessment activities.
General Requirements
Silicon Labs supports secure end-to-end product design and support.
Information and Instructions to the Users
Silicon Labs provides security guidance to customers.
技术文档
Silicon Labs provides helpful resources.
Reporting Requirements
Silicon Labs provides security vulnerability reports and patches.
See below for more on the CRA Key Topics as well as answers to FAQs.
Silicon Labs Assurance
Alignment with CRA Key Topics
Cyber Risk Assesment
- PSA 4 级认证: Series 3 Secure Vault establishes a high-assurance hardware root of trust and demonstrates independently validated resistance to sophisticated physical and software attacks. Click here to learn more about this achievement.
- ISO 27001:2022 Certified: Our Information Security Management System supports secure validation and governance across the company, with product security embedded throughout the design, development, and testing processes. View our ISO 27001 Certificate here.
General Requirements
- Secure Design: Hardware Design with security in mind by creating innovative solutions such as Secure Vault™. Software Development that follows industry-recognized secure coding standards and internal guidelines emphasizing code safety
- Vulnerability Management: A centralized system that tracks potential vulnerabilities and ensures prompt triage, remediation, documentation, and a feedback system that strengthens product resilience.
- Continuous Improvement: Security Testing (threat modeling, fuzz testing, regression testing, and periodic penetration assessments) performed throughout the product lifecycle, not just before release.
Information and Instructions to the Users
- Developer Documentation and Answers to Security Vulnerability FAQs: We provide product security resources (powered with AskAI), user guidance, and training resources to help developers implement secure products and maintain them through deployment. Visit our software documentation site, docs.silabs.com and our Security Vulnerability FAQs.
- Training Resources and Developer Enablement: Silicon Labs provides a broad public training ecosystem to help customers implement secure and compliant products, including Tech Talks, Works With on-demand sessions, webinars, and structured curricula across wireless, security, software, and application domains. Click on each link above to learn more.
技术文档
- Technical Documentation for Series 3: The Series 3 wireless platform page connects customers to product information, technical resources, software documentation, hardware documentation, and development tools. We also offer information on SDK Support Policy, SEMS, and Hardware Longevity Commitment, helping support secure implementation and lifecycle adoption for next-generation IoT designs. Learn more about the Series 3 platform.
- SBOM Generation in Simplicity Studio: Simplicity Studio can automatically generate SBOM artifacts in SPDX and CycloneDX formats for supported SLC projects, helping customers manage dependency visibility and software transparency. Learn more about SBOM Generation.
Reporting Requirements
- PSIRT and Vulnerability Disclosure Program: Silicon Labs operates a public vulnerability reporting channel, disclosure policy, and response targets to support coordinated vulnerability handling throughout the product lifecycle. Read our Vulnerability Disclosure Policy.
- CVE Numbering Authority (CNA) with MITRE: Silicon Labs has been a CNA with MITRE since 2021 年 11 月. To date, only 201 organizations from 32 countries participate in the CVE Program as CNAs. Browse the list of CVEs issued by Silicon Labs. Silicon Labs will be following the security reporting requirements directed by the EU, when its Single Reporting Platform becomes available in 2026 年 9 月.
- Addressing Security Vulnerabilities: Silicon Labs maintains updates to software including for fixes to security vulnerabilities. See SDK Release and Maintenance Policy for more information.
常见问答
This FAQ addresses practical questions about CRA readiness, product lifecycle alignment, documentation, and vulnerability handling.
The CRA is a European Union regulation that establishes cybersecurity requirements for products with digital elements placed on the EU market. It covers areas such as secure development, vulnerability handling, technical documentation, user information, and lifecycle support.
Yes. The CRA applies to several products, including those with digital elements, and/or process digital data, and can connect directly or indirectly to another device or network. For many customers, that means the silicon platform, firmware, SDK, and supporting software ecosystem all matter in the overall compliance picture. For more information, visit Cyber Resilience Act - Questions and Answers.
Our current approach includes secure development lifecycle controls, risk and threat analysis, vulnerability handling, security testing, update management, and supporting documentation. For more information, see the Information Security Management System Overview.
Current references include PSA Certified Level 4 for Series 3 Secure Vault, ISO 27001:2022 certification, the public vulnerability disclosure policy and reporting channel, SBOM generation support in Simplicity Studio, Series 3 technical resources, product security pages, and public training content, including Tech Talks, Works With, webinars, and curriculum materials.
The main CRA obligations apply to products placed on the EU market from 2027 年 12 月 11 日, onward. However, there are earlier reporting obligations beginning on 2026 年 9 月 11 日. See the European Commission’s CRA summary for definitions of “placing on the market” and “making available on the market,” as well as the CRA application dates.
Vulnerability handling is a core part of the readiness story. Silicon Labs operates PSIRT processes and public vulnerability disclosure mechanisms, and we are maturing coordinated vulnerability handling, advisory generation, and reporting readiness to support the stricter operational timelines introduced by the CRA.
Silicon Labs currently provides SBOM generation capability in Simplicity Studio for supported projects. SBOMs are an important transparency mechanism under CRA-related discussions because they help identify software components and dependencies used in product builds.
Silicon Labs’ public Product Longevity Commitment and SDK Release and Maintenance Policy help customers understand baseline hardware lifecycle expectations, software maintenance timing, and where extended maintenance options may be available.
-
培训
物联网安全培训:Works With 2022
我们的物联网安全培训回顾了法规和趋势,以及如何确保物联网设备在包括硬件、软件等各个方面的安全。
物联网安全讲座:
- SIOT-101: 物联网安全法规及其如何推动创新
- SIOT-102: 法规将要求对物联网设备提供安全保证
- SIOT-104: 无线协议栈与 TrustZone 和 Secure Vault 相集成
- SIOT-201: 应用安全功能来验证物联网产品的真实性
- SIOT-203: 采用物联网设备和安全管理
-
服务
-
资源
特色物联网安全资源
白皮书
Silicon Labs 博客
Silicon Labs 博客
Silicon Labs 博客
Silicon Labs 博客
-
报告漏洞
