Hardware Security Engine (HSE)

A Secure Enclave Built for Software-Defined Vehicles

Unlike traditional security add-ons (SHE, HSMs), the HSE is more than just a cryptographic engine: it is a hardware-isolated Secure Enclave that autonomously enforces trust and platform security – protecting cryptographic keys, managing secure boot and updates, and enabling trusted operation throughout the product lifecycle.

It provides scalability and portability across different systems and applications built on NXP products – while maintaining a consistent API and user experience.

Core Capabilities

HSE provides tightly integrated, hardware-backed security services.

Runtime security and key management

Seamless integration of security into applications and services.

Isolation of security-critical assets

Protects keys, credentials, and policies—even if software is compromised.

Platform security features

Including secure boot, secure debug, secure update, security monitoring, remote attestation, and configurable sanctions.




The HSE2 extends the Secure Enclave concept to support increasingly consolidated and virtualized vehicle architectures, and future-proof security. With full backward compatibility to the HSE API, HSE2 allows existing applications to be ported effortlessly, eliminating the need for redevelopment.

On-Chip resource control and isolation

Using software-defined, hardware-enforced policies to safely integrate multiple virtual ECUs on a single SoC.

Distributed security architecture

Enabling secure protocol offloading and line-speed cryptographic acceleration close to high-bandwidth interfaces.

Post-Quantum Cryptography (PQC) support

Enabling quantum-resistant secure boot, firmware and software updates, and secure communications designed for long-term security.

Key Benefits

By integrating security at the silicon level, HSE helps automotive developers reduce complexity while strengthening protection:

  • Complete, off the shelf Secure Enclave solution – no third-party security vendor required for firmware implementation, reducing cost and time-to-market
  • Optimized performance and robustness through hardware-firmware co design
  • Simplified integration, backed by NXP security expertise and documentation
  • Strong attack resistance, including protection against fault injection and side channel attacks
  • Proven solution, adopted in major OEM programs and validated against requirements from our broad customer base

  • Designed for compliance and future readiness

    Designed in alignment with ISO/SAE 21434; and supporting evolving cryptographic standards such as PQC.

    See ISO/SAE 21434 certificate
  • Independently verified by third party security laboratories

    SESIP certificates provide independent assurance of security and compliance for products in the S32 Automotive Platform.

    Look for SESIP certificates for NXP and S32