EN / 中文

From Identity Cards to Power Banks & Automotive: The Paradigm Shift of China’s Security Chip Track

by bandaotichanyezongheng·October 8, 2026

Author: Fang Yuan

The security chip industry has encountered a subtle contradiction in 2026. The global embedded security market continues to expand at a compound annual growth rate (CAGR) of over 12%, and is expected to reach USD 14.3 billion by 2030, with a significant increase in the market share of new security computing units based on Post-Quantum Cryptography (PQC) and homomorphic encryption accelerators.

This growth rate is not low in the semiconductor industry, but if you look at the interim reports of several leading Chinese security chip companies, you will see a different picture. Unigroup Guoxin's smart security chip business generated CNY 1.408 billion in revenue in the first half of the year, with a year-on-year growth rate of less than 1%. Its gross profit margin dropped from over 44% to 39.08%, and the company stated directly in its financial report that "competition at home and abroad is increasingly fierce, and the prices of some products are under pressure." The revenue of Fudan Microelectronics' security and identification product line reached CNY 472 million, a year-on-year growth of about 20%, performing slightly better, but this scale is not particularly outstanding in the entire IC (Integrated Circuit) design industry. Datang Microelectronics' security chip business achieved CNY 271 million in revenue and CNY 65.34 million in net profit in the first half of the year. The profit margin is considered quite good in the industry, but the growth stems from the stable supply of identity recognition business and the continuous increase in the financial market share.

Scale is expanding, profits are shrinking, and participants are still increasing. The top five global security chip manufacturers collectively hold about 67.8% of the market share, while the combined share of Chinese domestic manufacturers continues to climb. Market share is shifting, but not uniformly. The business model that the security chip industry relied on in the past was to obtain certifications, enter the supply chain, and then enjoy long-term stable orders. However, this model is now being diluted, and the dilution varies across different scenarios.

01. Certification Barriers Are No Longer Profit Barriers

The most solid business in the security chip industry over the past two decades has been identity authentication. ID cards, social security cards, SIM cards, and financial IC cards share common characteristics in these scenarios: extremely high standardization, extremely long certification cycles, and extremely high replacement costs once entering the supply chain. To enter these markets, companies need to pass a series of qualification certifications from UnionPay, the Ministry of Human Resources and Social Security, telecom operators, etc., with certification cycles often taking two to three years. Once passed, customers rarely change suppliers.

However, from another perspective, the replacement cycle for ID cards is measured in decades, SIM card shipments fluctuate with the mobile phone market, and the penetration rate of financial IC cards has long been saturated. When multiple companies obtain the same certification qualifications, the certification itself no longer constitutes differentiation. The change in Unigroup Guoxin's gross profit margin also indirectly confirms this shift; the gross profit margin of its smart security chips dropped by more than 5 percentage points within a year, which the company attributed to increasingly fierce competition at home and abroad. Although Datang Microelectronics' security chip business has remained profitable, its growth is essentially a battle for market share in a stock market. The identity recognition business maintains a stable supply, and the financial market share continues to increase, which essentially translates to grabbing market share from others in the original old market.

Besides, there is another easily overlooked reason: security functions are being integrated into main control chips. In the past, a security chip was an independent security unit, but now more and more MCUs (Microcontroller Units) are starting to build in security modules. Industry forecasts predict that in 2026, the shipment volume of SoC (System on Chip) products integrating functional safety and information security will exceed that of independent security chips for the first time, accounting for 52.7%. Basic security functions in consumer electronics and IoT (Internet of Things) continue to be integrated internally into MCUs and application processors. This means that when the main control chips purchased by customers already possess security capabilities, they no longer need to purchase a separate security chip. The question that independent security chip companies need to answer is: when security is no longer an independent category, where does your value ?

02. Incremental Growth Hides in Inconspicuous Places

If we only look at the financial reports of a few leading companies, it is easy to draw the conclusion that "the security chip industry lacks growth momentum." However, if we shift our focus to the real demands of terminal devices, the situation is actually much more complex.

Power banks are a typical example, as news of power banks catching fire or exploding has been frequently seen in the past two years. In April, the Ministry of Industry and Information Technology (MIIT) released the "Safety Technical Specification for Power Banks" (GB 47372-2026), introducing needle penetration test requirements for consumer batteries for the first time, and implementing unique product coding management. It requires each power bank to have an exclusive identity code containing the battery manufacturer's information, enabling full-process traceability from production to disposal. This means that every compliant power bank requires a traceable identity mark, and the underlying hardware carrier of the identity mark is precisely a security chip or an NFC authentication chip.

Huayi Microelectronics' HYM4616 NFC security chip has passed the official ITMA evaluation. Integrating the national cryptographic SM1/SM4 and international dual encryption systems, it has become one of the domestic NFC chips adapted to the new national standard power bank scenarios. Giantec Semiconductor has also launched the GT series NFC chip solutions adapted to the new national standard, using a "tap-to-interact" method to achieve security authentication between power banks and mobile phones. The value of a single chip in this scenario is not high, possibly only a few cents to one or two CNY, but the shipment volume is huge. Moreover, the entry barrier is more reflected in the rapid response to the new national standard compliance needs of terminal manufacturers, rather than the lengthy automotive-grade or financial certification cycles.

The security requirements for smart door locks are also undergoing a qualitative change. In the past, the security focus of door locks was the physical protection of the lock body itself, but now it is gradually shifting towards preventing the leakage and forgery of biometric data. GB 21556.2-2025 "Safety Technical Requirements for Locks - Part 2: Anti-theft Locks" was officially and mandatorily implemented on March 1, 2026, which clearly requires that Class C electronic anti-theft locks must use security chips, and the security chips should obtain the National Cryptography Level 2 certification. Nationz Technologies' N32S003 security chip, built with a cryptographic algorithm hardware acceleration engine and a TRNG (True Random Number Generator), has obtained National Cryptography Level 2 and EAL4+ certifications. It also provides an open-source SDK, allowing the door lock MCU to directly make API calls. Door lock manufacturers can achieve underlying security capability access without complex security chip firmware development. Link Coresafe' security chip solution has also obtained the Commercial Cryptography Level 2 certification and EAL4+ certification, becoming a core security SE supplier for mainstream domestic smart door lock brands. Hongsi Electronic' security chip solutions also comply with the GB 21556.2-2025 standard. In the smart door lock market with an annual shipment volume of tens of millions of sets, these companies use security chips to solve a real pain point: the local encrypted storage and transmission of biometric data.

Automotive electronics is another rapidly expanding scenario. The global installation rate of security chips in new cars is expected to exceed 48%. In 2026, the installation rate of embedded security modules for connected vehicles will break through 79% for the first time, and the number of security chips installed in L3 and above autonomous driving vehicles can reach 9 per vehicle. In the first half of 2026, C*Core's automotive-grade security MCU shipments exceeded 1.9 million units, a year-on-year growth of 80%, with a cumulative shipment of over 34 million automotive electronic chips, supplying in bulk to automakers such as BYD, Chery, Geely, and SAIC; its CCRC4XXX high-end automotive-grade MCU has been sampled, which is the first domestic automotive-grade chip integrating AI computing power and post-quantum security. On the international front, Infineon's TEGRION SLI22 adopts a 28nm process, integrates PQC, and has obtained CC EAL6+ certification; AURIX TC49 also supports PQC; NXP is deploying PQC on the S32K5 and S32N platforms. In the global automotive-grade security MCU market, NXP, Infineon, Renesas, and STMicroelectronics collectively hold about 65% of the market share. Domestic automotive-grade security chips are also gradually penetrating from peripheral scenarios to core domain controllers. This process takes time, but the direction is clear.

The common characteristics of these fragmented scenarios are: security demands genuinely exist and are driven by compliance or functionality, but the demand volume of a single scenario is far less than that of ID cards or SIM cards, and they are extremely sensitive to costs. They will not breed a giant pattern where "one company takes half," but they are providing a new way of survival for the security chip industry, which does not rely on a single large customer or a single certification cycle, but disperses risks through a combination of multiple scenarios and multiple categories. This is somewhat like the economic theory: do not put all your eggs in one basket.

03. PQC and RISC-V Are Redividing the Track

Fragmented scenarios will inevitably bring more participants, but starting this year, these two trends in the security chip industry are raising the technical threshold to a place that small and medium-sized enterprises cannot reach: Post-Quantum Cryptography (PQC) has moved from technical reserves to product implementation; the RISC-V architecture in security chips has moved from proof of concept to mass production. Looking at these two things individually, they are both incremental innovations, but put together, they are cutting the security chip industry into two layers. Enterprises capable of forward-looking investment enter the procurement lists for automotive, financial, and high-end IoT; those incapable retreat to the power bank chip market where chips cost only a few cents each.

Let's look at PQC first. In June, STMicroelectronics launched the ST54M, integrating an NFC controller, embedded secure element, eSIM, and PQC hardware accelerator into a single chip. It supports ML-KEM and ML-DSA algorithms and has passed Common Criteria 2022 EUCC and EMVCo certifications. The key to this product is not "supporting PQC," but cryptographic agility, meaning the cryptographic suite can be adjusted through firmware updates during the device's lifecycle. In other words, even after the device is sold, the security policy can still be changed. In the same month, the US government issued Executive Order 14412, advancing the PQC migration timeline for high-value assets in government systems to 2030-2031. Infineon's TEGRION SLI22 automotive security controller implements PQC algorithms in the security controller and has passed CC EAL6+ certification. The anti-quantum financial POS machine chip CUni360SQ-ZX, jointly developed by C*Core and ZXInfo Tek, is the first domestic anti-quantum financial payment chip to pass the PCI PTS 7.0 security evaluation, with a cumulative shipment of over 100,000 units.

The impact of PQC implementation is multi-layered. The most direct layer is the increase in hardware resources; the hardware implementation of ML-KEM and ML-DSA algorithms requires more logic resources and storage space, and both chip area and power consumption will rise. For IoT security chips that take low power consumption and low cost as their core competitiveness, this is not an easy design migration. A deeper impact lies in the reconstruction of the certification system. The EUCC certification obtained by STMicroelectronics' ST54M is an early passer under the new standard, and Infineon's SLI22 CC EAL6+ certification is also the first of its kind in the field of PQC security controllers. Whoever completes the certification closed-loop of PQC products first will be able to occupy a first-mover position in the future procurement of automotive and mobile payment security chips. Those enterprises that lack the ability to complete PQC hardware integration and certification in the short term will be forced to retreat to the low-end market where there are no mandatory requirements for PQC.

The penetration of RISC-V in security chips is also accelerating. By the end of 2025, security chip design solutions based on the RISC-V architecture have obtained 23 mainstream standard certifications, gradually forming substitution pressure on the traditional ARM architecture. Hongsi Electronic released the HSRU3 series SoC security chips based on the XuanTie E906 core, with a maximum operating frequency of 250MHz. Under the same power consumption and size, the algorithm processing performance is improved by more than 30% compared to similar products, achieving full-stack compatibility of post-quantum algorithms and traditional algorithms. The CCRC4XXX series launched by C*Core is the first domestic high-performance automotive central chip integrating "RISC-V architecture + AI capabilities + anti-quantum security." It adopts a 22nm RRAM process, integrates multi-core RISC-V CPUs, NPUs, and hardware security modules, supports PQC anti-quantum algorithms and traditional cryptographic algorithms, and is designed according to the ISO 26262 ASIL-D functional safety level.

The value of RISC-V in the field of security chips lies not in performance, but in customizability. Manufacturers can customize instruction set extensions according to their own security needs, achieving side-channel protection optimization or algorithm acceleration that is difficult to achieve under the traditional ARM architecture. However, the ecological maturity of RISC-V remains a variable, and the perfection of toolchains, operating system adaptation, and certification systems all require time.

04. Rules First, Business Later

The localization logic of the security chip industry has been discussed more in the narrative framework of IT application innovation and independent controllability in the past few years. However, a more specific and market-oriented driving force has emerged this year: the compliance of terminal products.

The mandatory enforcement of Article 3.2 of the EU RED Directive has brought a pulsed surge in security certification demands for consumer-grade IoT devices. It is expected that in 2026, the growth rate of the relevant testing and certification supporting market in this region will reach 14.6%, the highest globally. The obligation to report vulnerabilities and cybersecurity incidents under the EU Cyber Resilience Act will take effect in September, and the complete regulation will fully come into effect in December 2027. In the US, EO 14412 advances the PQC migration timeline for government systems to 2030-2031. In China, the new national standard requirements for power banks, the upgrade of encryption standards for smart door locks, and the requirements of the Data Security Law for terminal data protection are all turning security chips into a mandatory option. Globally, 47 countries and regions have issued mandatory regulations targeting the security baseline of IoT devices. Within 2026, about more than 30 countries and regions globally will introduce or revise technical regulations directly related to the security of embedded devices.

This is an opportunity for domestic security chip companies to achieve significant results. Huayi Micro's rapid response in power bank NFC chips is an example, quickly understanding the requirements of the new national standard and launching adapted products. Datang Microelectronics' layout in power IoT terminal identity authentication solutions follows a similar logic. The large-scale access of terminals in the new power system has brought real security authentication demands, and the standard-setting and implementation pace of such demands are highly localized. Datang Microelectronics is also promoting security chips in the low-altitude economy field, focusing on the secure storage of unique identification codes for drones and the encrypted transmission of flight control instructions. The market scale of this scenario is currently negligible, but it reveals a line of thinking: security chip companies no longer wait for a mature large market to appear before fighting for market share, but intervene during the rule-making stage of new scenarios.

However, compliance-driven growth also has its limitations. Compliance demands create a market where products must be bought, rather than a market where customers are willing to pay more. The unit price of security chips for new national standard power banks may only be a few cents to one or two CNY, and the unit price of security SE chips for smart door locks is also far lower than that of financial IC cards. The incremental growth driven by compliance is real, but the profit margin it brings is far less than that of traditional identity authentication scenarios. Security chip companies need to find a sustainable profit model in this new normal of high volume and low price.

The competition in security chips is shifting to a new dimension. It is no longer about who has more certifications, but about who understands the scenarios better. PQC requires chips to continuously update cryptographic suites within their lifecycle; RISC-V allows manufacturers to customize security protection at the instruction set level; compliance requires chips to take on the obligation of vulnerability reporting. With these three things superimposed, chips are no longer just procured components, but architectures to be fought for.