Best moments

PUFsecurity (a subsidiary of eMemory) and Carota Announce Strategic Alliance: Enhancing OTA Cybersecurity with PUF Technology to Enable the Software-Defined Era

[Hsinchu, August 28, 2025] – PUFsecurity Corporation, a subsidiary of eMemory Technology Inc., today announced a strategic alliance with Carota Corporation, a global leader in OTA (Over-The-Air) solutions for connected vehicles and AIoT devices. Carota has long provided stable, efficient, and automotive-grade OTA services to global automotive brands and AIoT sectors, with more than 320 million smart devices upgraded worldwide. Through this collaboration, PUFsecurity’s Physically Unclonable Function (PUF) technology will be integrated into Carota’s OTA platform architecture via a system-level PUF-based HSM Edge Server solution. This integration mitigates internal control and supplier data leakage risks, significantly strengthening the security of remote firmware updates and data transmission. It delivers multi-layered cybersecurity protection from the device to the cloud for automotive and next-generation smart mobility applications.

 

Integrating PUF-Based Hardware Root of Trust to Reinforce OTA Software Update Security

Carota’s proprietary differential algorithm in OTA software updates dramatically reduces data transmission volumes while ensuring high compatibility across automakers and platforms. By introducing the PUF-based HSM Edge Server into this collaboration, customers can securely entrust key management. This integration enhances Carota’s OTA workflow with stronger data protection, identity authentication, and firmware integrity verification mechanisms. It enables automakers to safely deliver firmware updates while securely capturing and storing vehicle operation data and driver privacy information—achieving comprehensive upstream and downstream cybersecurity protection.

With the integration of PUFsecurity’s PUF-based HSM Edge Server, 
Carota ensures end-to-end cybersecurity protection in OTA software updates.

The PUF-based HSM Edge Server solution is built on eMemory’s NeoPUF technology, which generates a unique and unclonable “chip fingerprint” during the semiconductor manufacturing process as the basis for secure key generation. Its modular cartridge design allows flexible computational resource expansion for various device requirements, significantly enhancing resilience and stability in key management. By integrating a PUF-based FIDO authentication mechanism, customers maintain full control over key access rights, ensuring end-to-end security and eliminating risks of supplier leakage or internal mishandling associated with traditional key deployment.

 

Establishing a New PUF-Based OTA Paradigm and Extending to Diverse Smart Devices

The “PUF-based OTA” service represents the first practical application of PUF technology in OTA scenarios and will expand to next-generation smart mobility and automation devices such as AI robots, drones, AGVs/AMRs, and flying cars. This establishes a stronger cybersecurity defense for connected vehicles and AIoT (Artificial Intelligence of Things) devices, while laying a secure foundation for the era of Software-Defined Anything (SDX).

For AI-powered connected endpoints in SDX environments, PUF technology ensures that all software, data, and configuration updates with remote OTA servers are executed in a trusted environment. PUF enables unique identity recognition and key generation frameworks that support zero-trust authentication, software signing, privacy protection, device-server binding, version auditing, sandbox testing, and more—addressing lifecycle trust and verification challenges in SDX.

 

Toward a SECaaS Vision: Building a PUF Cybersecurity Ecosystem

Dr. Tsung-Lin Lin, Special Assistant to the Chairman of PUFsecurity, stated:
“This collaboration with Carota marks an important milestone in realizing our vision of a ‘PUF-based Security-as-a-Service (SECaaS) platform.’ Our goal is to establish a complete cybersecurity ecosystem rooted in PUF technology—spanning from chip, module, system to platform—capable of addressing the evolving applications and security requirements of the SDX era.”

Wu Po-Yi, CEO and Founder of Carota, commented:
“Carota is committed to delivering stable, efficient, and automotive-grade OTA solutions, with security being one of our top priorities. By working with PUFsecurity to introduce the PUF-based HSM Edge Server, we reinforce the trust foundation for secure key custody and management, providing customers with comprehensive security support in connected vehicle and smart mobility applications. As SDX adoption accelerates, we will continue deepening collaborations with PUF-based cybersecurity ecosystem partners and extend applications into AI robotics, smart IoT, intelligent logistics, and new energy vehicles—ensuring that our global customers have forward-looking and sustainable OTA security services in the SDX era.”

 


About PUFsecurity

PUFsecurity is a leading provider of hardware root-of-trust technologies, specializing in security IP solutions built upon Physically Unclonable Function (PUF) technology. Leveraging eMemory’s NeoPUF and OTP technologies, PUFsecurity focuses on developing and deploying native key generation and full-stack security architectures to address the challenges of the quantum era. Its core IP solutions include PUFPQC (Post-Quantum Cryptography), PUFcc (Crypto Coprocessor), PUFrt (Root of Trust), and PUFhsm (Hardware Security Module). PUFsecurity is building a PUF-based Security-as-a-Service ecosystem to provide protection and authentication for the next generation of connected devices.

 

About Carota

Carota is a global one-stop provider of OTA upgrade and remote diagnostics solutions. Its offerings include OTA subscription services, smart cockpit software development, remote diagnostics, OTA testing tools, and AI-powered fleet management solutions. Serving both connected vehicle and IoT industries, Carota’s customers span Greater China, Europe, North America, Japan, Korea, and Southeast Asia.