Technical Whitepaper
DPSM — Distributed PUF Sealing Module Next Generation HSM
DPSM distributes a PUF (Physical Unclonable Function) hardware root of trust across chip, server, and region tiers, combining pre-commit authorization checks with post-commit sealing into a next-generation security module. It resolves the structural limits of traditional HSMs through distribution, self-verification, silicon sealing, and IRON-grade sealing .
Common Misconceptions
Three things people often get wrong about Axowl
Before the technical deep-dive, three patterns of confusion we hear most often — corrected up front so the rest of the whitepaper reads cleanly.
"Online" and "on-prem" are not different products.
Many readers assume RO-PUF security requires on-premise hardware shipping. It does not. The same RO-PUF + BCH ECC + HKDF circuit runs with identical security primitives on Roost chips that Axowl operates in colocation and on closed-network on-site units. Online deployment is not a weaker cousin of on-prem — it is the same silicon-grade trust anchor, delivered on Day 1 of sign-up .
Small startups already get nation-state-grade hardware.
The shared tier is often dismissed as "the cheap option for startups." In practice, a 5-person team on a shared Roost with the IRON sealed chain receives cryptographic guarantees that match or exceed every legacy HSM on the market — silicon-derived keys, quorum signing, sealed audit chain, and pre-commit conflict detection, all available at the Standard tier without buying a single appliance. Enterprise security is no longer reserved for companies that can afford a $100K HSM cluster.
Homomorphic encryption sounds great — but cannot ship in production.
Homomorphic Encryption (HE) is the most-hyped cryptography of the moment, yet its 100×–1,000× compute overhead , inability to mutate encrypted records, and catastrophic SaaS cost destroy the very workloads it promises to protect. Axowl reaches the same privacy goal — and adds integrity, mutability, and zero-latency processing — by anchoring trust in the silicon instead of in lattice math.
Read the full Axowl vs Homomorphic Encryption comparison
The Promise
Stolen data stays unreadable, and tampering always shows
Leaked data at rest cannot be read
In the DPSM design, data is encrypted with keys derived from the PUF. The PUF key is derived only inside the silicon and never stored anywhere . A database dump, an exposed backup, or a cloud breach yields ciphertext without a key. A compromised running application is a different case: data that the application legitimately decrypts is outside this defense. That path is narrowed by approval lines and personal seals on access itself.
Insider changes are exposed
Axowl staff and administrators cannot extract the PUF key either. Every audit event is sealed and linked into a hash chain, and at the highest tier (IRON) a hardware root of trust signs the seal. Any record changed after sealing is mathematically exposed at verification . Permissions pass separation-of-duties rules and an LLM conflict check before they are committed.
01 · Patents Filed
Three Core Patents
The core DPSM technologies are filed with the Korean Intellectual Property Office, and international filing (PCT) is in preparation. The portfolio comprises an extensive set of claims, and each patent combines into a unified trust system that covers the entire timeline rather than a single isolated tool. What is protected is the sealed transition itself — the hash chain across every state change — not the hardware beneath it. The protection attaches to that transition regardless of the substrate on which it runs, and the claims reach the method together with its software, SDK, and service embodiments.
Hierarchical Distributed Trust Fabric
Trust is distributed from a hardware root through odd-numbered quorums at the chip (L1), server (L2), and region (L3) tiers. No single node holds a complete system key.
Transition-Sealed Integrity System
Every state transition is sealed into a hash chain together with a logic watermark. A changed record is exposed at verification, and the chain preserves when and by whom it was changed. At the highest tier (IRON), a hardware root of trust signs the seal.
Pre-grant LLM Conflict Verification
Before a permission grant is committed, an LLM finds semantic conflicts in the permission combination and shows them. Known separation-of-duties rules are enforced in code; the LLM looks for combinations those rules miss. A person reviews the result and commits.
Filing numbers, claims, drawings, and algorithm details are provided separately under NDA. Please use the technical inquiry channel to request technical materials.
02 · PUF Limitations Solved · Built for FIPS 140-3 Validation
Known PUF Weaknesses, Solved by DPSM
A PUF (Physical Unclonable Function) is a powerful hardware root of trust, but on its own it has limits. DPSM resolves these weaknesses with multi-layer defenses — ECC, KDF, k-of-n quorum, drift tracking, AXI isolation — all designed to comply with FIPS 140-3, NIST SP 800-90B, and SP 800-108 .
PUF Weakness
Noise (BER)
Silicon variation flips 5-10% of response bits each read. The same chip risks producing different keys.
DPSM Solution
BCH ECC + majority voting
BCH(127, 64, T=10) encoder plus 8-sample majority voting (≥5/8) extracts stable bits. RTL implementation complete.
PUF Weakness
Aging · Drift
PUF responses gradually shift over the chip's lifetime, eroding reproducibility.
DPSM Solution
Drift-rate tracking
The time-series drift rate of PUF responses is monitored and re-enrollment is triggered at threshold. Covered by patent claims.
PUF Weakness
Modeling Attacks
ML can learn many challenge-response pairs to predict PUF behavior (Strong PUFs).
DPSM Solution
Weak PUF only
The challenge interface is never exposed externally (RO-PUF). Used only for key derivation — training samples cannot be collected at all.
PUF Weakness
Single-Chip Dependence
If the chip is damaged or lost, the key is gone forever. Backups are equally risky — a backup is a key disclosure.
DPSM Solution
k-of-n quorum + Hot-Shard
Odd-numbered quorum consensus across L1/L2/L3 tiers. The system runs through the loss of up to k-1 chips, with zero-downtime PUF replacement.
PUF Weakness
Side-Channel Attacks
Power or electromagnetic analysis can extract the PUF response. Physical access becomes a real risk.
DPSM Solution
No bus exposure · machine-identity gate · k-of-n split
The PUF response register is not connected to the external bus (AXI), so software cannot read it. Power and electromagnetic analysis, which bypass the bus, are met with two layers. First, key operations run only for requests that pass an allowed machine identity and the user's biometric check, so an attacker cannot freely repeat the operations or choose the inputs that such analysis needs. Second, the key is split across a k-of-n quorum: analyzing one chip does not yield the system key.
PUF Weakness
Helper-data Entropy Leak
The helper data of a fuzzy extractor can leak part of the PUF entropy.
DPSM Solution
HKDF-Extract + Salt
HKDF-SHA256 (RFC 5869) separates entropy extraction from key derivation, with a salt for domain separation.
Built for FIPS 140-3 Validation
Every mechanism above is designed to comply with FIPS 140-3 (PUF-based entropy source), NIST SP 800-90B (entropy-source validation — startup health and continuous health tests), and SP 800-108 / RFC 5869 (HKDF). In online environments, Roost chips that Axowl operates in colocation implement both the software and hardware domains. For closed-network deployments or formal Level 3 certification, please request a separate consultation .
03 · Why DPSM
Seven Structural Limits of Traditional HSMs
HSMs (Hardware Security Modules) were designed for ATM security in the 1980s, and their essence has not changed since. They carry structural limits that no longer match the threat models of the distributed era, the cloud era, or the LLM era.
Centralized Single Appliance
Keys live in a single device — theft or damage puts the entire system at risk.
Administrator Bypass
Vendor firmware updates and administrator privileges open paths to extract keys or bypass controls.
Local Audit Logs
An HSM's own logs can be modified by administrators — insider tampering goes undetected.
Vendor Lock-in
Incomplete PKCS#11 compatibility and vendor-specific quirks make replacement costs explode once you adopt one.
High Cost
$25k–$100k+ per appliance, multiplied by clustering, with separate operations headcount on top.
No Pre-commit Verification
Operates only after permissions are already granted — it cannot verify conflicts in the grant itself.
Slow Algorithm Updates
Adding a new algorithm (e.g. post-quantum) requires firmware updates and re-certification, taking years.
03 · Comparison
HSM vs DPSM — Superiority at a Glance
A visual comparison showing how DPSM outperforms HSMs across seven core evaluation axes. Scores (0-100) represent relative performance on each axis.
Insider Threat Defense
HSM
DPSM
HSM · admin firmware bypass possible
DPSM · admins cannot extract the PUF · silicon-internal
Distributed Consensus (k-of-n quorum)
HSM
DPSM
HSM · active-passive cluster only
DPSM · native L1/L2/L3 chip quorum
Audit-log Integrity
HSM
DPSM
HSM · local logs · admin-modifiable
DPSM · IRON sealed chain · instant detection
Pre-commit Verification
HSM
DPSM
HSM · feature absent
DPSM · LLM semantic-conflict detection + HW gate
Cloud Deployment Speed
HSM
DPSM
HSM · hardware shipping · weeks to months
DPSM · Day-1 on a shared Roost
Algorithm Update Speed
HSM
DPSM
HSM · firmware + re-certification, years
DPSM · RTL resynthesis + signed bitstream rollout, days
Freedom from Vendor Lock-in
HSM
DPSM
HSM · partial PKCS#11 · vendor lock-in
DPSM · open SDK · HMAC/HKDF/BCH standards
Maintenance · Replacement Cycle
HSM
DPSM
HSM · 5-7 year wholesale replacement · downtime
DPSM · partial hot-swap · zero-downtime quorum
Server Cost (TCO)
HSM
DPSM
HSM · $25k-$100k+ per appliance · multiplied by cluster
DPSM · 50% or less operating cost vs. legacy HSM
Scores are relative assessments per axis and may vary depending on the demonstration environment and the threat model. For closed-network deployments requiring formal FIPS 140-3 Level 3 certification, please request a separate consultation.
04 · Deployment
Deployment Options
Online · Standard · Defense Tier
Shared Roost — Available Immediately
Designed for startups and cost-sensitive environments. A Roost chip quorum that Axowl operates in a colocation data center signs your organization's seals. Three chips each regenerate their key from the silicon and sign 2-of-3, so there is no stored key and no master key. It is available from Day 1 without setup wait time.
The shared tier still preserves enough security to match or exceed legacy HSMs — silicon-derived keys, quorum signing, and the IRON sealed chain are applied identically, preserving the core values of audit, tamper-proofing, and tamper detection. The Defense tier adds TPM 2.0 · FIDO2 on members' devices and real-time integrity monitoring.
Available immediately (Day-0)
Suited for startups and cost-sensitive environments
No cloud account or hardware purchase needed
Identical IRON sealed chain
Online · IRON Tier
Dedicated Roost — Your Own Chip Quorum
For environments that require top-tier IRON sealing. Each organization gets a dedicated Roost chip quorum in its own rack at a colocation data center, never shared with another organization. The PUF + ECC stabilization + KDF circuit runs on Zynq UltraScale+ chips with Axowl's own RTL.
Both the software domain of FIPS 140-3 (SHA-256, HMAC, KDF) and the hardware domain are implemented on chips that Axowl operates. The same chip set can also be installed on-site as a Roost Box · Rack · Card.
Dedicated chip quorum per organization
Per-chip independent keys + k-of-n quorum demonstrated
Top-tier IRON sealing · same firmware as on-site units
Closed Network
FIPS 140-3 Certification — Separate Consultation
For closed-network (on-premise) environments in banking, government, defense, and healthcare that require FIPS 140-3 certification, we proceed via a separate consultation.
Deployment paths include an on-site Roost (Box · Rack · Card), SRAM-PUF-based ASIC mass production (e.g., Intrinsic ID Quiddikey), or a combination with a certified HSM.
Industrial ASIC · Custom Manufacturing
Robotics · Mobility · IoT Chips — MPW & Mass Production
For industrial domains such as robotics, mobility, IoT, medical devices, and defense, we offer ASIC chip manufacturing on a custom-order basis (OEM / Foundry-as-a-Service) . 8-inch wafer fabrication is the default , with 12-inch available on request.
Prototypes are validated at the MPW (Multi-Project Wafer) stage, then transitioned into commercial mass production .
12-inch
Three major Korean foundries · seven processes (SF4, SF5, 8LPU, 14LPU, etc. — Samsung Electronics, SK keyfoundry, and others)
8-inch
One foundry · four processes (LV BCD, HV BCD, etc. — DB HiTek)
Design House
We partner with Korean design houses to support the full RTL → GDS flow.
05 · Licensing & Partnership
Licensing & Partnership
DPSM is available for licensing as an OEM license, a technology-transfer agreement, or joint development. All three core patents are licensable, and split licensing by country, industry, or domain is open to discussion.
OEM License
Embed DPSM technology in your product and ship under your own brand.
Joint Development
Build industry- or country-specific solutions together on the core technology.
Regional / Industry License
Region-specific or industry-specific split licensing.