Google, AMD, NVIDIA, and Microsoft have developed an open chip design block (IP block) for embedding trustworthy hardware components (RoT, Root of Trust) as part of the Caliptra joint project. Caliptra is a separate hardware block with its own memory, processor, and implementation of cryptographic primitives, ensuring the verification of the boot process, the firmware used, and the configuration stored in non-volatile memory.
Caliptra can be used for integration into various independent hardware blocks that perform integrity checks and ensure that the device uses verified and authorized firmware by the manufacturer. Caliptra can significantly simplify and standardize the integration of built-in cryptographic verification mechanisms in CPUs, GPUs, SoCs, ASICs, network adapters, SSDs, and other equipment.
The platform's cryptographic verification tools for integrity and authenticity will protect hardware components from malicious alterations to firmware and secure the boot and configuration storage processes to prevent compromise of the main system due to attacks on hardware components or the insertion of malicious changes in the chip supply chains. Caliptra also provides the ability to verify the authenticity of firmware updates and related platform data (RTU, Root of Trust for Update), detect firmware and critical data integrity issues (RTD, Root of Trust for Detection), and recover damaged firmware and data (RTRec, Root of Trust for Recovery).
The development of Caliptra is being carried out in the context of the Open Compute joint project aimed at developing open hardware specifications for data center equipment. The specifications related to Caliptra are distributed under the Open Web Foundation Agreement (OWFa), designed for the dissemination of open standards (similar to open-source licenses for specifications). The application of OWFa allows for the creation of products and derivative implementations based on the specifications without royalty payments and enables any organization to participate in the development of the specifications.
The basic implementation of the IP block is based on the open RISC-V processor SWeRV EL2 and is equipped with 384KB of RAM (128KB DCCM, 128KB ICCM0, and 128KB SRAM) and 32KB of ROM. Supported cryptographic algorithms include SHA256, SHA384, SHA512, ECC Secp384r1, HMAC-DRBG, HMAC SHA384, AES256-ECB, AES256-CBC, and AES256-GCM.


Source: opennet.ru
