AI and cloud infrastructure are broadening the security boundary. CPUs, XPUs, NICs, storage, memory, and management devices increasingly handle sensitive data, run privileged firmware, and participate in critical system operations. Trust, key protection, and cryptographic processing therefore need to be designed into the infrastructure from the start.
Standard security products provide a proven path when established capabilities meet the requirements. Custom security provides greater flexibility when security functions, performance, software, or system integration need to be aligned to a specific architecture.
Marvell combines custom silicon expertise with proven security technology. LiquidSecurity brings HSM and key-management capabilities. Additional capabilities include Root of Trust, secure boot, and firmware protection. Customization can extend from configuration and tailored firmware to integrated security functions and purpose-built silicon.
AI infrastructure expands the number of devices, workloads, and software layers that need protection, raising the demands on security across the system.
Protect a broader trust boundary | Keep security from limiting performance | Meet compliance across global deployments | Keep pace with changing security requirements |
CPUs, accelerators, controllers, adapters, and firmware create more components that must establish identity, integrity, and trust. | Encryption, authentication, signing, and other cryptographic operations must scale without consuming valuable host compute or constraining workload performance. | FIPS, PCI, and regional standards must be met consistently across millions of devices and across multiple jurisdictions. | New cryptographic algorithms, post-quantum migration, certification requirements, and regional standards must be addressed across the entire infrastructure lifecycle |
Hardware security modules protect keys and sensitive cryptographic operations within a controlled security boundary. Marvell LiquidSecurity provides a deployed foundation in cloud HSM technology, key management, multi-tenancy, remote administration, and cryptographic processing.
Custom implementations can extend these capabilities when key scale, tenant isolation, algorithms, performance, firmware, software, power, footprint, or placement need to align more closely with the infrastructure. The result can range from an adapted HSM implementation to security functions integrated into a broader custom design.
Technology choices:
Trust increasingly needs to be extended to the silicon and firmware inside each critical infrastructure component. Root of Trust establishes the hardware foundation for authenticating firmware, securing the boot process, and maintaining integrity as higher software layers initialize.
Custom implementations can incorporate Root of Trust into processors, accelerators, networking devices, storage controllers, management silicon, and other infrastructure devices. Marvell brings deployed experience in hardware Root of Trust and secure firmware through products such as QLogic Fibre Channel adapters. Custom designs can combine that experience with customer IP and standards-based security technology to align the trust architecture with the role of each device.
Technology choices:
High-volume encryption, authentication, signing, and key operations can consume host compute resources and limit infrastructure efficiency. Dedicated cryptographic hardware moves these operations to purpose-built engines, allowing general-purpose and accelerated compute to remain focused on application workloads.
Marvell NITROX brings established cryptographic offload expertise that can be used as a starting point for custom security architectures. Customization can align algorithm support, throughput, resource allocation, virtualization, firmware, and interfaces with the required workload. The result can be a dedicated security device or cryptographic capability incorporated into a broader custom ASIC. The Marvell standard security portfolio provides commercial experience in cloud HSM and cryptographic offload that supports this custom path.
Technology choices:
Security does not always require another standalone device. Trust, key protection, and cryptographic processing can be integrated alongside the infrastructure functions that consume them.
A custom security architecture can place these capabilities closer to CPUs, XPUs, networking, memory, storage, or management functions. The appropriate level of customization can vary by program. Some requirements can be addressed through firmware or software. Others may require hardware integration or purpose-built silicon. The Marvell broader custom ASIC platform provides access to security alongside compute, memory, networking, storage, high-speed interfaces, and advanced implementation capabilities, allowing security to be developed in the context of the complete system.
Implementation choices:
Established Marvell security products provide proven HSM, key-management, cryptographic, Root of Trust, firmware, and software capabilities. Custom development can build from that foundation rather than starting every security function from scratch.
Algorithms, keys, queues, partitions, tenants, QoS, performance, firmware, software, and feature sets can be shaped around deployment requirements. Functions that provide no value to the target architecture do not need to define the design.
Dedicated and integrated implementation options allow trust, key protection, and cryptographic processing to be positioned around the compute, networking, storage, memory, or management functions they protect.
Resource isolation, multi-tenancy, remote management, crypto agility, and fleet-scale operational requirements can be considered from the beginning rather than added after silicon architecture is established.
Custom security spans more than silicon. Firmware, software, validation, standards, certification, manufacturing, and lifecycle requirements are part of bringing a security architecture into production.
Press Release
Learn More
Press Release
Learn More
Blog
Learn More
Off-the-shelf products such as LiquidSecurity provide predefined, production-ready HSM capabilities for key management, encryption, multi-tenancy, remote administration, and compliance. Custom security is appropriate when the infrastructure requires different resource scaling, functionality, firmware, integration, performance, or system placement. Proven technology from standard products can also provide building blocks for custom designs.
Customization becomes valuable when a standard device cannot efficiently meet the required trust model, workload, tenancy model, performance target, software environment, integration approach, or infrastructure roadmap. The level of customization can range from firmware and configuration changes to purpose-built silicon.
Depending on the program, customization can include cryptographic algorithms, key capacity, queues, resource partitioning, virtual machines or tenants, QoS, performance, firmware, software, interfaces, customer IP, and the functions incorporated into the device.
No. Some requirements can be addressed through firmware, software, resource configuration, or integration changes. New hardware becomes relevant when the underlying security architecture, functionality, performance, interfaces, or system integration needs to change materially.
Yes. Root of Trust, key protection, cryptographic acceleration, secure boot, and other security functions can be incorporated into larger custom infrastructure devices. The Marvell custom ASIC platform already spans security alongside compute, networking, memory, and storage IP.
Crypto agility, updateable firmware and software, and appropriate hardware acceleration can provide flexibility as cryptographic algorithms and standards evolve. The architecture can also be planned around post-quantum migration and long infrastructure lifecycles.
Certification requirements should be established early because they can influence hardware, firmware, key handling, operational controls, and validation. The Marvell security portfolio includes experience with standards such as FIPS 140-3, Common Criteria, eIDAS, and PCI PTS HSM.
We believe better partnerships help to build better technologies. Let’s connect and see what we can design together!
We will be in touch with you soon!
Copyright © 2026 Marvell, All rights reserved.