A Hardware Root of Trust (HRoT) is an immutable, secure cryptographic engine physically embedded within a hardware component—such as a Trusted Platform Module (TPM), CPU secure enclave, or dedicated security chip. It provides the foundational, unspoofable source for cryptographic keys and integrity measurements, establishing a chain of trust for the entire system boot process and runtime state. This hardware-based anchor is resistant to software-level attacks and tampering.
