The Secure Element Chip: How It Keeps Your Ledger Secure (2024)

By Ledger

Oct 23, 2019 | Updated Aug 28, 2024

Read 4 min

Medium

The Secure Element Chip: How It Keeps Your Ledger Secure (1)
KEY TAKEAWAYS:
— Hardware wallets require chips to operate: for storing private keys and signing transactions.

— Different hardware wallets will use different chips and may not implement them in the same manner.

— Ledger hardware wallets use a specialized chip called the Secure Element. These chips are tamper-proof and offer the highest level of protection for your digital assets.

When choosing a hardware wallet, its inner components are often overlooked. But the chip your hardware wallet uses and how it’s implemented impacts the security of your device. To explain, hardware wallets don’t store crypto, they store your private keys; the keys that grant access to your digital assets. If anyone gains access to your private keys, it’s game over.

So a hardware wallet’s main purpose is to keep your private keys safe from attackers attempting to extract them. But to store those private keys and sign transactions, your device requires a chip. And that chip needs to offer protection from both online and physical attacks as well as performance.

At Ledger, we only use one of the most advanced chips on the market: the Secure Element. This chip generates and stores your private keys, and is responsible for driving your Ledger device’s secure screen. The Secure Element also runs Ledger’s custom operating system BOLOS which keeps your apps isolated from one another.

In short, the Secure Element is one of the key reasons your Ledger hardware wallet is so secure. But why is it so important, and why is it so effective compared to other hardware wallet chips?

To understand fully, let’s dive into why hardware wallets need chips in the first place.

Understanding the Security of Hardware Wallet Chips

All hardware wallets rely on chips to store private keys, operate apps, and drive their screens.

Some hardware wallets will use a single chip, whereas others might use a combination of chips.

However, it’s important to note that not all chip types provide the same level of resistance against attacks. You wouldn’t want to protect your digital assets with a chip used in a vacuum cleaner or microwave, right? Even the chips used for smartphones and laptops aren’t designed to protect private keys. Simply, most chips are built for performance, not security.

With that in mind, let’s look at the types of chips that hardware wallets typically use and see how they measure up.

Microcontroller Unit

The Secure Element Chip: How It Keeps Your Ledger Secure (2)

A generic Microcontroller unit, or MCU in short, is found in devices such as microwaves and TV remotes. While these chips provide a lot of flexibility for their operations, they aren’t resistant to physical attacks. In particular, they tend to be vulnerable to inexpensive attacks such as voltage and clock glitching.

While introducing a passphrase feature on an MCU chip will help mitigate these risks, even that method introduces a single point of failure. If your passphrase is too simple, a hacker may be able to work it out. If your passphrase is too complicated, you risk forgetting it or recording it incorrectly.

Safe Memory Chip

The Secure Element Chip: How It Keeps Your Ledger Secure (3)

Another chip used in hardware wallets is the Safe Memory chip. These provide several countermeasures against physical attacks but they don’t have the certification you would get from an evaluation by a Security lab. Without this certification, you can’t be sure the chip is as secure as it claims. As a result, these chips aren’t suitable for bank cards or passports.

When it comes to hardware wallets, using a Safe Memory chip isn’t simple. To get a little technical, Safe Memory chips perform scalar multiplication on a single elliptic curve. This doesn’t work for signing Bitcoin transactions, so hardware wallets with Safe Memory chips will always need a second chip to handle the signing process.

This creates a vulnerability. Sending the private key out of its Safe Memory chip to the MCU opens up the perfect opportunity for side-channel attackers.

The Secure Element

The Secure Element is a highly specialized chip commonly used in passports and credit cards. You likely use these chips on multiple devices, in any environment where your most sensitive personal data needs to be secured and concealed.

Secure Element chips are the most secure option for a hardware wallet. They stand out for their security features, but also their versatility. A secure Element can store private keys and handle the signing process, plus, they can protect against physical attacks and have the certification to prove it.

Why Are Secure Element Chips So Secure?

Secure Element chips are so secure mainly due to two important factors: their ability to withstand attacks and their certification.

The Secure Element Protects Your Wallet From Attacks

If you’re not a developer (and most of us aren’t) you may be wondering exactly what kind of attacks the Secure Element protects you from. Some Secure Elements may protect you from even more attacks than just these, but let’s dive into some of the most common attacks.

Side channel attacks

A side-channel attack is when a hacker analyzes physical signals coming from a device’s operating system and embedded applications to get insights into how it behaves and which secret data it uses.

A Secure Element chip has complex countermeasures to hide its electromagnetic radiation and power usage, protecting it against those who want to listen in.

Fault Attacks

Fault attacks involve an attacker aiming to perturb the physical execution of functions by your operating system and embedded applications. For example, the attacker might use a laser beam to bypass security mechanisms such as forcing the device to accept an incorrect PIN code.

The Secure Element has an efficient fault detection system, including light detectors for laser fault injection, temperature sensors, and voltage glitch detectors.

Software attacks

Software attacks involve a bad actor manipulating your device’s operating system or embedded apps, hoping to cause unexpected behaviors.

The Secure Element prevents this attack as it is resistant to reprogramming. Once the chip is programmed, it can’t run any other software.

Secure Element Chips are Certified by Security Labs

Secondly, unlike Safe Memory chips, Secure Element chips are certified, having undergone testing by a third-party security lab. Certification is a crucial part of their security model. Typically, Secure Elements are rated according to the CC EAL standard (also known as EAL).

CC stands for Common Criteria and represents an international standard for evaluating hardware and software products. Then the EAL stands for Evaluation Assurance Level. This rating measures how secure a Secure Element is; from its physical resistance to attacks to vulnerabilities in its entire supply chain.

The rating is simple: the higher the EAL level, the more secure the Secure Element chip is. There are 7 CC EAL levels, from low security to the highest security assurance.

How Does Ledger Approach the Secure Element in its Devices

Ledger devices use the Secure Element to generate and store private keys for your crypto assets. While other hardware wallets use the Secure Element, Ledger has a unique approach to its implementation.

Ledger’s Secure Element Runs a Custom Operating System: BOLOS

The Secure Element in Ledger devices runs a custom operating system named BOLOS. Combined with the genuine-check mechanism in Ledger Live, users can verify they are running the legitimate operating system and embedded applications.

Secure Element drives the Secure Screen

Ledger devices are also unique for using the Secure Element to drive their screens. With Ledger, what you see is what you sign. The Secure screen on your device will always show the accurate intended address of your transaction. That means even if your internet-connected device, such as your laptop or smartphone, is infected with malware, you can trust the transaction details on your Ledger device.

Ledger’s Secure Element Chips Have EAL 5+ and EAL6+ Certifications

Ledger devices have an EAL 5+ or an EAL 6+ certification depending on which device you get. The Ledger Nano X uses a Secure Element that is EAL5+ certified, whereas the Ledger Nano S Plus and Ledger Stax use a Secure Element that is EAL6+ certified.

Both EAL5 and EAL6 certifications guarantee the chip has undergone extensive testing by a third party to meet high-security standards. As mentioned, the scale only goes up to EAL7+, so the Secure Element chips in Ledger hardware wallets are extremely secure, with measures in place to protect you from physical and remote hacking attempts.

The Secure Element: An Integral Component of Your Ledger Device

The chip your hardware wallet uses is incredibly important. When it comes down to making crypto transactions, you need three things to be fully secure.

Firstly, you need a secure enclave: a chip resistant to physical hacking. This is handled by the Secure Element for Ledger devices. Next, you need to implement cryptography in that enclave, which is exactly what Ledger’s custom operating system BOLOS does for the Secure Element. Finally, you need a way to verify the authenticity of the transaction’s intent. With Ledger’s Secure screen driven directly by the Secure Element, Ledger devices tick off all three prerequisites.

The inherent security features of a Secure Element, alongside Ledger’s proven security model, arm your Ledger device with the tools it needs to protect your digital assets. So what are you waiting for? Get yourself a Ledger hardware wallet and start transacting with confidence

The Secure Element Chip: How It Keeps Your Ledger Secure (2024)

FAQs

The Secure Element Chip: How It Keeps Your Ledger Secure? ›

Ledger devices are unique for using the Secure Element to drive their secure screens. Since the Secure Element chip drives the secure screen directly, no hacker can intercept this information or tamper with the transaction details it shows.

How does Secure Element work? ›

A secure element, also known as a hardware root of trust, is a dedicated hardware component that is designed to protect assets (e.g. cryptographic keys) from unauthorized access. It is typically a tamper-resistant and physically secure area, often a chip, that is isolated from the device's main processor.

What is the difference between trezor and Ledger Secure Element? ›

Ledger vs.

Trezor and Ledger are industry leaders in security, offering private keys that never leave their devices. Trezor models use a single chip base, while Ledger devices feature a double chip base, with the second chip being a bank-grade secure element (SE) for enhanced protection against hardware attacks.

How is the Bitcoin Ledger secured? ›

The Bitcoin network's security is multi-layered. Transaction hashing, mining, block confirmations, and game theory all work together to make Bitcoin's blockchain impenetrable. Since the first transaction block in 2009, the network has never once shut down – and no bitcoin has ever been stolen from the blockchain.

What is a Secure Element hardware wallet? ›

A Secure Element (SE) is a tamper-proof and hacking-resistant chip used in hardware wallets to provide an additional layer of security for your private keys. This specialized hardware protects your Bitcoin from a variety of threats including both software and physical attacks.

What is the difference between TPM and Secure Element? ›

Secure elements provide protection against counterfeit products such as battery replacement in applications like laptops, tablets, and robot vacuums. Trusted Platform Modules (TPM) bring hardware-based security to your embedded designs.

What encryption does element use? ›

Effortlessly Collaborate with Encrypted Messages, Files, and Videoconferences. Element is an additional encrypted team chat and file sharing capability available for Fognigma users that uses the Matrix encryption standard.

What is the safest Ledger wallet? ›

Ledger Stax™

The most premium secure touchscreen hardware wallet to protect and manage crypto and NFTs.

Is Ledger wallet safe in 2024? ›

Ledger hardware wallets offer heightened security by storing private keys offline, making them more resilient against hacking and malware than software wallets.

Does Ledger use a Secure Element? ›

Ledger devices store private keys on a Secure Element chip, an industry-leading computer chip often used in bank cards and passports since it can withstand common attack vectors like side-channel attacks and glitching.

Can a Ledger be hacked? ›

The Ledger Connect Kit hack was caught and fixed within hours, and now seems to have cost users less than half a million dollars in crypto. But autopsies of the attack have exposed deep problems with how Ledger managed its software—software with which the overriding pitch to users is that it's hyper-secure.

Can my crypto be stolen from Ledger? ›

Segregate Your Assets

Ledger devices can only protect you so far. If you sign a malicious transaction with your Ledger, your funds will still be at risk. To avoid someone stealing your crypto, the best thing you can do is segregate your assets correctly.

Can Ledger block your crypto? ›

Don't worry, losing your Ledger doesn't mean losing your crypto. Your assets are stored on the blockchain, which you can access using your Ledger. You can access, manage, and retrieve your assets as long as your secret recovery phrase is safe and accessible only to you.

What does a Secure Element do? ›

Secure Element (SE) is a chip that is by design protected from unauthorized access and used to run a limited set of applications, as well as store confidential and cryptographic data. Smartphones and tablets, hardware cryptowallets, and other devices use Secure Element.

What is the most secure hardware wallet for crypto? ›

This wallet nails it with style and safety. The Model T's touchscreen is incredibly smooth, letting you manage your crypto and confirm transactions directly on the bright 1.54” LCD screen. Your sensitive info is sealed tight in the device, safe from online threats.

What is the Secure Element in Apple pay? ›

After you authenticate your transaction, the Secure Element provides your Device Account Number and a transaction-specific dynamic security code to the store's point of sale terminal along with additional information needed to complete the transaction.

What is the Secure Element of a phone? ›

Secure Element (SE) is a chip that is by design protected from unauthorized access and used to run a limited set of applications, as well as store confidential and cryptographic data. Smartphones and tablets, hardware cryptowallets, and other devices use Secure Element.

What is the Secure Element in a SIM card? ›

Secure Elements (e.g. Smart Cards) are micro-processor equipped tokens, able to process and store a diverse range of applications and data. They are used as credit cards, banking cards in general, ID cards and especially as SIMs in mobile telecommunications.

How does SecureSafe work? ›

SecureSafe automatically fills in the username and password in the login fields. This way, you log in to apps and websites with just one click. The password generator suggests individual and secure passwords, allowing you to set a unique password for each account.

Top Articles
How online payments work | Barclaycard Business
Sensitive Periods in Montessori Education
Gomoviesmalayalam
Craigslist Niles Ohio
Le Blanc Los Cabos - Los Cabos – Le Blanc Spa Resort Adults-Only All Inclusive
Cash4Life Maryland Winning Numbers
1970 Chevelle Ss For Sale Craigslist
Retro Ride Teardrop
Best Transmission Service Margate
30% OFF Jellycat Promo Code - September 2024 (*NEW*)
Poplar | Genus, Description, Major Species, & Facts
Learn How to Use X (formerly Twitter) in 15 Minutes or Less
A.e.a.o.n.m.s
Walgreens On Nacogdoches And O'connor
180 Best Persuasive Essay Topics Ideas For Students in 2024
Suffix With Pent Crossword Clue
Craiglist Kpr
Bj Alex Mangabuddy
Paychex Pricing And Fees (2024 Guide)
Army Oubs
Candy Land Santa Ana
Stardew Expanded Wiki
Indiana Wesleyan Transcripts
Blue Rain Lubbock
Happy Life 365, Kelly Weekers | 9789021569444 | Boeken | bol
What Is The Lineup For Nascar Race Today
Kingdom Tattoo Ithaca Mi
E32 Ultipro Desktop Version
Hellraiser 3 Parents Guide
Restaurants In Shelby Montana
Access a Shared Resource | Computing for Arts + Sciences
Scott Surratt Salary
Harrison 911 Cad Log
Att U Verse Outage Map
Shaman's Path Puzzle
Bee And Willow Bar Cart
The Ride | Rotten Tomatoes
Telegram update adds quote formatting and new linking options
My.lifeway.come/Redeem
Craigslist Florida Trucks
Dogs Craiglist
Ross Dress For Less Hiring Near Me
Shoecarnival Com Careers
Paul Shelesh
Top 1,000 Girl Names for Your Baby Girl in 2024 | Pampers
Oakley Rae (Social Media Star) – Bio, Net Worth, Career, Age, Height, And More
The Jazz Scene: Queen Clarinet: Interview with Doreen Ketchens – International Clarinet Association
Helpers Needed At Once Bug Fables
Amourdelavie
32 Easy Recipes That Start with Frozen Berries
Ravenna Greataxe
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 6327

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.