Journal

Why an AI server needs an FPGA when the GPU computes: control plane and root of trust

October 2, 2026· 9 min read

In AI servers the FPGA acts as a control and security device beside the compute: I/O aggregation, firmware protection and recovery, DC-SCM interfaces, post-quantum signatures. Sources: Lattice, OCP, NIST.

Summary

Sources describe FPGAs in AI infrastructure as control and security devices (firmware protection and recovery, I/O aggregation, DC-SCM LTPI), not as compute engines.

Overview

Context. Lattice Semiconductor and AMI, a Lattice company, announced on 28 September 2026 their participation in OCP Global Summit 2026 in San Jose. They plan to show an "open control plane" for AI infrastructure "from silicon to rack": technical presentations on 12-15 October, demonstrations at booth A53-A54 on 13-15 October, and a keynote on 13 October at 9:58 a.m. PT by Ford Tamer and Sanjoy Maity. The release names demonstrations of platform firmware resiliency, flash-less boot, rack-scale management and telemetry, quantum-resistant security and AI-enabled sensor aggregation. This is a vendor announcement; it contains no measurements.

Management controllers. The OpenBMC project describes itself in its README as a Linux distribution for management controllers used in devices such as servers, top of rack switches and RAID appliances. The Lattice release lists "open BMC" among its keywords but does not describe the role of a BMC, so we do not either.

Where the FPGA comes in. Lattice positions MachXO5-NX as a "secure control FPGA" family for system control and management. Its product page gives examples: hardware management functions, aggregation of control signals over PCIe in a network switch with SFP monitoring offloaded from the network CPU, and a secure control module with LTPI. The page lists up to 378 programmable I/O with 1.0/1.2/1.5/1.8/2.5/3.3 V levels. Editorial conclusion: tasks such as polling sensors, handling power signals and bridging interfaces are natural to keep on a separate small control device rather than on the accelerator; the sources do not state this directly and give no share of FPGAs in AI servers.

Platform firmware resiliency. NIST SP 800-193 (May 2018) provides guidelines supporting resiliency of platform firmware and data against potentially destructive attacks, built on three activities: protecting against unauthorized changes, detecting them, and recovering rapidly and securely. NIST defines the platform as the collection of hardware and firmware components needed to boot and operate a system.

Lattice devices. Lattice describes Mach-NX as a secure system control FPGA with a hardware root of trust and dual boot, a secure enclave supporting 384-bit cryptography (SHA, HMAC, ECC), up to 8.4K logic cells and 2669 kbit of user flash, and states that PFR solutions compliant with NIST SP 800-193 can be developed with it. For MachXO5-NX Lattice lists up to 100K logic density, 7.3 Mb internal memory, 55 Mb user flash, AES256 bitstream encryption and bitstream authentication up to ECDSA-521 and RSA4K. These are vendor claims; the pages do not link certification documents.

Root of trust inside the SoC. The Caliptra project describes IP and firmware for an integrated Root of Trust for Measurement block inside datacenter-class SoCs such as CPUs, GPUs, DPUs and TPUs, providing identity, measured boot and attestation; it originated at the Open Compute Project and its source lives in CHIPS Alliance. Editorial hypothesis: an in-SoC root of trust and a board-level control device with its own root of trust address different layers and can coexist; the sources do not compare them.

DC-SCM and LTPI. Lattice states that the Open Compute Project included the LVDS Tunneling Protocol and Interface specification (LTPI) in the DC-SCM 2 specification, and captions its application example "Datacenter-ready Secure Control Module". The official OCP pages on DC-SCM were blocked for automated access, so we rely on the OCP repository and the Lattice page here.

Open implementation. The repository opencomputeproject/HWMgmt-Module-DCSCM-LTPI contains Verilog source of a standalone LTPI IP (SCM and HPM), an Intel Quartus example project for the Intel MAX 10 CPLD and a set of LTPI unit tests; the IP is compliant with the DC-SCM 2.x LTPI specification developed in the OCP Hardware Management Module sub-project. Code is under the MIT licence and documentation under CC BY 4.0; revision 1.20 follows LTPI specification 1.2, with the latest listed update on 13 January 2026. Lattice adds that LTPI is also supported on MachXO3, MachXO3D and Mach-NX.

Flash-less boot. For flash-less boot the Lattice release gives only titles: a demonstration of flash-less boot architectures and a session on 15 October at 1:05 p.m. PDT, "Advancing Flash-less Boot in OCP Systems: A Streaming Firmware Architecture for Secure and Scalable Infrastructure". The mechanism, latencies and link requirements are not disclosed in the sources, so we do not describe them.

Rack telemetry. The release names a demonstration of rack-scale management and telemetry and a session "A Unified Power Management Solution for AI and Legacy Data Centers" on 13 October at 3:45 p.m. PDT; metrics and interfaces are not listed. Experiment protocol (not performed by us): measure platform boot time with streamed firmware versus local flash; behaviour when the link drops during boot; time to detect a tampered image and to recover under a protect-detect-recover scenario; polling period and latency of rack telemetry under load; the number of lines and voltage levels that must be routed to the control device.

NIST standards. FIPS 203 specifies ML-KEM, a key-encapsulation mechanism, and FIPS 204 specifies ML-DSA, a digital signature algorithm; NIST states that both are believed secure even against adversaries with a quantum computer. Both were published on 13 August 2024. NIST pages carry notes about errata to be corrected in future revisions (FIPS 203 note of 17 November 2025, FIPS 204 note of 31 July 2026), so track the current revision.

What Lattice claims. Lattice says MachXO5-NX TDQ devices offer root-of-trust features supporting classical cryptography and CNSA 2.0 approved post-quantum cryptography (PQC), with a "full suite" of CNSA 2.0 prescribed PQC algorithms. The page does not list algorithms or parameter sets, and the link to FIPS 203 and FIPS 204 is not shown there; map them from technical documentation. A separate video note calls a post-quantum capable MachXO5D root-of-trust controller with AMI Tektagon a "preview", not a shipping product.

Editorial conclusion. Taken together, the sources describe the FPGA in an AI server as a control and security device next to the compute, not as a compute engine: I/O aggregation, firmware verification and recovery, and open interfaces such as LTPI. NIST SP 800-193 supplies the vocabulary (protect, detect, recover); FIPS 203 and 204 supply the algorithms; Lattice and OCP supply example implementations. What is missing is independent evidence from real servers.

Checklist for a design review. Ask which firmware images the control device verifies and how recovery works; which PQC algorithms and parameter sets it implements, with the datasheet revision; how LTPI links behave on loss; and what telemetry the rack needs and at what rate. We have not tested any device named here.

Verified facts

Lattice and AMI will show an open control plane at OCP Global Summit 2026, with demonstrations including platform firmware resiliency, flash-less boot, rack-scale telemetry and quantum-resistant security. Source: https://www.latticesemi.com/en/About/Newsroom/PressReleases/2026/Lattice-to-Showcase-Open-Control-Plane-Innovations-for-AI-Infrastructure-at-OCP-Global-Summit-2026. Checked: 2026-10-02. Confidence: 5/5.

MachXO5-NX is a secure control FPGA family with TDQ devices claiming CNSA 2.0 approved PQC support. Vendor statement; no independent test or certification document is linked on the page. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02. Confidence: 4/5.

Mach-NX offers hardware root of trust and dual boot with a 384-bit secure enclave. Vendor statement; no independent test or certification document is linked on the page. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/Mach-NX. Checked: 2026-10-02. Confidence: 4/5.

The OCP repository holds MIT-licensed Verilog LTPI IP compliant with the DC-SCM 2.x LTPI specification. Source: https://github.com/opencomputeproject/HWMgmt-Module-DCSCM-LTPI. Checked: 2026-10-02. Confidence: 5/5.

NIST SP 800-193 defines resiliency guidelines built on protection, detection and recovery. Source: https://csrc.nist.gov/pubs/sp/800/193/final. Checked: 2026-10-02. Confidence: 5/5.

FIPS 203 specifies ML-KEM and FIPS 204 specifies ML-DSA; both were published on 13 August 2024. Source: https://csrc.nist.gov/pubs/fips/204/final. Checked: 2026-10-02. Confidence: 5/5.

Caliptra provides an integrated Root of Trust for Measurement block with identity, measured boot and attestation for datacenter-class SoCs. Source: https://chipsalliance.github.io/Caliptra/. Checked: 2026-10-02. Confidence: 5/5.

OpenBMC is a Linux distribution for management controllers in servers, top of rack switches and RAID appliances. Source: https://github.com/openbmc/openbmc. Checked: 2026-10-02. Confidence: 5/5.

Engineering benefit

Lattice lists hardware management, SFP monitoring offload from the network CPU and LTPI aggregation of low-speed serial interfaces as MachXO5-NX example applications, which are control-plane tasks that do not need the accelerator. Inference: that these tasks do not need the accelerator is our reading; the page does not say so. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02. Confidence: 4/5.

An open Verilog LTPI IP with unit tests (MIT licence) exists in the OCP repository, so engineers can study and simulate the DC-SCM link layer. Source: https://github.com/opencomputeproject/HWMgmt-Module-DCSCM-LTPI. Checked: 2026-10-02. Confidence: 5/5.

Commercial benefit

NIST SP 800-193 is a public reference that OEMs and component suppliers can cite for platform firmware resiliency requirements, and Lattice states that its Mach-NX supports developing solutions of this kind. Vendor statement; no independent test or certification document is linked on the page. Source: https://csrc.nist.gov/pubs/sp/800/193/final. Checked: 2026-10-02. Confidence: 4/5.

Community benefit

OCP, CHIPS Alliance (Caliptra) and OpenBMC publish specifications, IP and source code openly, which lets universities and small teams work on the same control-plane building blocks. Inference: openness of the artifacts is documented; the educational benefit is our reading. Source: https://chipsalliance.github.io/Caliptra/. Checked: 2026-10-02. Confidence: 4/5.

Critical review

The Lattice release is an event announcement: demonstrations and session titles are plans, and it gives no measurements, customers or server models. Source: https://www.latticesemi.com/en/About/Newsroom/PressReleases/2026/Lattice-to-Showcase-Open-Control-Plane-Innovations-for-AI-Infrastructure-at-OCP-Global-Summit-2026. Checked: 2026-10-02. Confidence: 5/5.

Security and PQC statements on Lattice pages are vendor claims; the pages do not list algorithms or parameter sets and do not map them to FIPS 203 and FIPS 204. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02. Confidence: 5/5.

The official OCP DC-SCM pages could not be fetched (access blocked), so DC-SCM statements rely on the OCP GitHub repository and a vendor page. Source: https://github.com/opencomputeproject/HWMgmt-Module-DCSCM-LTPI. Checked: 2026-10-02. Confidence: 4/5.

The MachXO5D post-quantum root-of-trust controller is described as a preview, not a shipping product. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02. Confidence: 4/5.

The NIST documents and the OCP repository are primary, public and versioned, so the standards and open IP parts of the article are independently checkable. Source: https://csrc.nist.gov/pubs/fips/204/final. Checked: 2026-10-02. Confidence: 5/5.

Practical recommendations

Before the next design review, print the datasheet revision next to every PQC claim; "supports post-quantum" without an algorithm list is a sentence, not a specification.

If you want to try LTPI without a server, the OCP repository ships unit tests and an Intel MAX 10 example, which is cheaper than a rack and far quieter.

Do not take a conference announcement as a design input: wait for the session materials and verify them against a datasheet.

Official links

Lattice at OCP Global Summit 2026 (press release)

Lattice MachXO5-NX

Lattice Mach-NX

OCP DC-SCM LTPI reference implementation (GitHub)

OpenBMC

Caliptra (CHIPS Alliance)

NIST SP 800-193

NIST FIPS 203 (ML-KEM)

NIST FIPS 204 (ML-DSA)

Evidence

Lattice and AMI announced on 28 September 2026 their participation in OCP Global Summit 2026: keynote 13 October 9:58 a.m. PT, technical presentations 12-15 October, demonstrations at booth A53-A54 on 13-15 October, San Jose Convention Center. Source: https://www.latticesemi.com/en/About/Newsroom/PressReleases/2026/Lattice-to-Showcase-Open-Control-Plane-Innovations-for-AI-Infrastructure-at-OCP-Global-Summit-2026. Checked: 2026-10-02.

Lattice demonstrations include platform firmware resiliency, flash-less boot architectures, rack-scale management and telemetry, quantum-resistant security and AI-enabled sensor aggregation. Source: https://www.latticesemi.com/en/About/Newsroom/PressReleases/2026/Lattice-to-Showcase-Open-Control-Plane-Innovations-for-AI-Infrastructure-at-OCP-Global-Summit-2026. Checked: 2026-10-02.

MachXO5-NX is described by Lattice as a secure control FPGA family; TDQ devices offer root-of-trust features with classical cryptography and CNSA 2.0 approved PQC; up to 378 programmable I/O; AES256 bitstream encryption; authentication up to ECDSA-521 and RSA4K. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02.

Lattice says the Open Compute Project included LTPI in the DC-SCM 2 specification and that LTPI is also supported on MachXO3, MachXO3D and Mach-NX. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/MachXO5-NX. Checked: 2026-10-02.

Mach-NX: hardware root of trust, dual boot, secure enclave with 384-bit cryptography (SHA, HMAC, ECC), up to 8.4K LC and 2669 kbit user flash; Lattice states NIST SP 800-193 compliant PFR solutions can be developed. Source: https://www.latticesemi.com/en/Products/FPGAandCPLD/Mach-NX. Checked: 2026-10-02.

The opencomputeproject/HWMgmt-Module-DCSCM-LTPI repository contains Verilog LTPI IP (SCM and HPM) compliant with the DC-SCM 2.x LTPI specification, an Intel Quartus example for MAX 10, unit tests; MIT code licence and CC BY 4.0 documentation; revision 1.20 follows LTPI 1.2. Source: https://github.com/opencomputeproject/HWMgmt-Module-DCSCM-LTPI. Checked: 2026-10-02.

OpenBMC is a Linux distribution for management controllers used in devices such as servers, top of rack switches or RAID appliances. Source: https://github.com/openbmc/openbmc. Checked: 2026-10-02.

Caliptra provides IP and firmware for an integrated Root of Trust for Measurement block in datacenter-class SoCs, giving identity, measured boot and attestation; it originated at OCP and lives in CHIPS Alliance. Source: https://chipsalliance.github.io/Caliptra/. Checked: 2026-10-02.

NIST SP 800-193 (May 2018) provides guidelines for platform firmware resiliency: protect, detect and recover. Source: https://csrc.nist.gov/pubs/sp/800/193/final. Checked: 2026-10-02.

NIST FIPS 203 specifies ML-KEM (key encapsulation) and FIPS 204 specifies ML-DSA (digital signatures); both published 13 August 2024. Source: https://csrc.nist.gov/pubs/fips/203/final. Checked: 2026-10-02.

Source

More from this section