IT security scaled up millions of times over
No matter how quickly new technologies develop, hardware remains the first line of defence and therefore the primary target for attackers. In our hardware laboratory, we ensure that today’s devices remain secure tomorrow.
Request a non-binding quote

Safe and compliant – your products are ready for launch.
Welcome to our state-of-the-art hardware laboratory at TÜV Informationstechnik. Our laboratory is one of the largest of its kind in Europe. Many of the credit cards and identity documents you use every day have been tested here.
Using the very latest testing methods, we ensure that products remain secure in the long term – even when in the hands of attackers – and reliably protect your sensitive information and secrets.
In addition to high-security testing, we support our clients with comprehensive analyses and specific recommendations for action. In this way, we help to secure hardware and firmware in a targeted manner and avoid unpleasant surprises during subsequent use.

We combine expertise in semiconductor technology, computer science, physics and statistics to ensure that our highly specialised test set-ups always stay one step ahead of real attackers. Anyone who passes our tests is protected against any kind of hardware attack.
25 high-performance computers
15 side-channel measurement set-ups
20 error injection systems, including 12 infrared lasers

Side-channel analyses evaluate an integrated circuit by passively capturing and analysing information. This information may be based on physical effects, such as power consumption and electromagnetic emissions, or may be derived from timing behaviour. The information gathered is used first to assess the necessity and then the effectiveness of the countermeasures implemented.

Targeted faults induced by current glitches, clock manipulations, laser pulses or electromagnetic fields, with the aim of influencing the intended behaviour of a circuit or firmware. These techniques help us to identify vulnerabilities, evaluate countermeasures and assess resistance to physical attackers.
Security chips protect sensitive data. Yet even their power consumption can reveal secrets. Find out how side-channel analysis uncovers hidden vulnerabilities and how independent testing helps to safeguard chips against real-world attacks. We have summarised the key information and facts in this article.



Side-channel analysis and side-channel countermeasures for the NIST-standardised key encapsulation mechanism FIPS 203.
View publication
Side-channel attacks and side-channel countermeasures for the NIST-standardised digital signature scheme FIPS 204.
View publication
This paper demonstrates how to make efficient use of the RISC-V instruction set extension to build a side-channel-resistant component relevant to post-quantum cryptography.
An in-depth analysis of code-based fault injection countermeasures and an examination of the gap between theoretical and practical security.
The paper demonstrates that t-probing security does not always translate into practical side-channel resistance. It identifies high noise requirements, particularly with non-uniform shares, and provides design guidelines.

"Without side-channel analyses, we risk leaving our IT systems unprotected. We must act now to close security gaps before they are exploited by attackers."
Dr Timo Bartkewitz
Head of Hardware Laboratory
The Common Criteria (CC) is an international standard (ISO/IEC 15408) for the evaluation and certification of the security of IT products. Unlike other standards such as ISO 27001, the CC focuses on product evaluation rather than management systems and offers customisable security requirements.
More about the CC standard
The EMVCo standard defines globally interoperable security and payment requirements for chip cards, contactless payments and mobile transactions. Unlike proprietary systems, it offers global acceptance, strong cryptography and fraud protection, and differs from PCI-DSS (which focuses on data) and ISO 8583 (which focuses on message formats).
Find out more about the EMVCo standard
FIPS 140-3 is the US standard for cryptographic modules, based on ISO/IEC 19790:2012. Compared with FIPS 140-2, it incorporates internationally recognised security requirements, offers more flexible certification options and improves testing for software-based cryptographic implementations.
More about the FIPS standard
Verified IoT security
Contactless smartcard system for the Japanese market.
A globally recognised standard for the automotive sector.
We carry out independent analyses and assessments of your hardware and firmware components.



A hardware laboratory specialising in IT security provides the necessary equipment and expertise to carry out hardware penetration tests. This includes, amongst other things, lasers, oscilloscopes and electromagnetic probes.
Testing hardware security is important in order to assess the level of protection against attackers who have physical access to the product. This is particularly the case for products that are left unattended or unprotected for extended periods whilst in use.
In a hardware laboratory, any product containing an integrated circuit can be analysed.
A hardware laboratory carries out bespoke security tests, the intensity of which is varied according to the strength of the attacker. For example, a weak attacker model might only involve remote attacks, whereas a strong attacker model might involve physical attacks lasting several weeks.
The key attacks assessed in a hardware security evaluation are side-channel analyses, fault-based attacks, and the exclusion of logical attacks at the hardware and hardware-related firmware levels (e.g. Secure Boot).
SCA is an attack method used to extract sensitive information from unintended channels, such as power consumption or timing behaviour. This can occur particularly during the execution of cryptographic algorithms or the processing of sensitive data.
Targeted laser pulses or voltage spikes disrupt the computation of security-critical functions and trigger errors. This can, for example, cause important checks (such as authentication) to be bypassed or render the output of cryptographic algorithms insecure.
A hardware penetration test requires a genuine test sample to be sent to our laboratory. Depending on the test, we either use externally available interfaces or gain access to the interfaces or the surface of the integrated circuit. We then use side-channel analysis, error injection and timing analysis to penetrate the hardware or extract information.
For example, vulnerabilities may be discovered that allow the extraction of key material, or that enable an attacker to install a modified version of the firmware.

