Dover Microsystems provides CoreGuard silicon IP that acts as a bodyguard to host processors in embedded systems. This technology monitors instruction execution against defined security, safety, and privacy rules to stop unauthorized actions before they cause damage. The solution specifically immunizes devices against network-borne attacks and protects AI/ML components from exploitation.
Funding
$15.1M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


Founders
Product
Problem
Embedded systems and AI/ML applications are increasingly vulnerable to network-based cyberattacks that exploit software flaws, leading to significant financial losses and safety risks. Traditional software-based security measures are often insufficient to protect against sophisticated attacks, including zero-day exploits and adversarial AI examples. The growing complexity of these systems and the increasing reliance on AI/ML components exacerbate these vulnerabilities.
Solution
Dover Microsystems offers CoreGuard, a silicon IP solution that integrates directly with RISC architectures to provide hardware-level protection against network-based attacks. CoreGuard acts as a "bodyguard" to the host processor, monitoring every instruction executed to ensure compliance with a defined set of security, safety, and privacy rules, known as micropolicies. If an instruction violates a micropolicy, CoreGuard stops it from executing before any damage can occur. This approach immunizes processors against the exploitation of software vulnerabilities, including buffer overflows, code injection, and data exfiltration, and protects AI/ML components from adversarial attacks and IP extraction.
Target Audience
The primary target audience includes companies designing SoCs and embedded processors for industries such as industrial IoT, automotive, aerospace, and defense, as well as organizations developing AI/ML applications requiring robust security.
Features
- Hardware interlock that controls communication between the host processor and peripherals, ensuring verification by the CoreGuard Policy Enforcer.
- Updatable micropolicies installed on the SoC to distinguish between safe and malicious instructions.
- CoreGuard Policy Executor (PEX) that crosschecks instruction metadata against installed micropolicies.
- Base set of security micropolicies to stop prevalent network-based attacks without application alterations.
- Customizable micropolicies for tailored security, safety, and privacy requirements.
- CoreGuard SDK with FreeRTOS kernel, software simulator, compiler toolchain, and sample applications.
- CoreGuard Policy Enforcer RTL delivered as a set of hardware system Verilog design files.
- Protection against buffer overflows, code injection attacks, stack smashing, and data exfiltration.
- Safety micropolicies to enforce safety rules unique to the device and application.
- Privacy micropolicies to secure communications and prevent private data exfiltration.