Hoʻolaha ʻo Google i ka papahana OpenTitan e hana i nā ʻāpana hilinaʻi

Google hōʻike ʻia papahana wehe hou OpenTitan, he kahua ia no ka hana ʻana i nā ʻāpana lako pono (RoT, Root of Trust). Hoʻokumu ʻia ʻo OpenTitan i nā ʻenehana i hoʻohana ʻia i nā hōʻailona USB cryptographic ʻO Google Titan и TPM chips e hāʻawi i nā hoʻoiho i hōʻoia ʻia i hoʻokomo ʻia ma nā kikowaena ma ka ʻōnaehana Google, a me nā Chromebook a me nā polokalamu Pixel. ʻO nā code pili i ka papahana a me nā kikoʻī kikoʻī hoʻopuka ʻia ma GitHub ma lalo o ka laikini Apache 2.0.

ʻAʻole like me ka hoʻokō ʻana o Root of Trust, ke kūkulu ʻia nei ka papahana hou e like me ka manaʻo o ka "palekana ma o ka ʻike", e hōʻike ana i kahi kaʻina hana hoʻomohala ākea a me ka loaʻa ʻana o nā code a me nā schematics. Hiki ke hoʻohana ʻia ʻo OpenTitan ma ke ʻano he mākaukau i hana ʻia, hōʻoia ʻia a hilinaʻi hoʻi e hiki ai iā ʻoe ke hoʻonui i ka hilinaʻi i nā hoʻonā i hana ʻia a hoʻemi i nā kumukūʻai i ka wā e hoʻomohala ai i nā pōpoki palekana kūikawā. E hoʻomohala ʻo OpenTitan ma kahi kahua kūʻokoʻa ma ke ʻano he papahana hui, ʻaʻole pili i nā mea hoʻolako kikoʻī a me nā mea hana chip.

E mālama ʻia ka hoʻomohala ʻana o OpenTitan e kahi hui waiwai ʻole haahaaRISC, e hoʻomohala ana i kahi microprocessor manuahi e pili ana i ka hoʻolālā RISC-V. ʻO nā hui G + D Mobile Security, Nuvoton Technology a me Western Digital ua hui mua i ka hana hui ma OpenTitan, a me ETH Zurich a me ke Kulanui o Cambridge, nā mea noiʻi e hoʻomohala nei i kahi papa hana paʻa. CHERI (Nā ʻōlelo aʻoaʻo RISC i hoʻonui ʻia i ka hiki) a i kēia manawa loaʻa he haʻawina o 190 miliona euros e hoʻololi i nā ʻenehana pili i nā kaʻina hana ARM a hana i kahi prototype o ka ʻenehana hou Morello.

Hoʻopili ka papahana OpenTitan i ka hoʻomohala ʻana i nā ʻāpana loiloi like ʻole i koi ʻia i nā pahu RoT, me kahi microprocessor wehe. haahaaRISC Ibex e pili ana i ka RISC-V architecture, cryptographic coprocessors, hardware random number generator, hierarchy of key and data storage in permanent and RAM, security mechanisms, input/output units, secure boot tools, etc. Hiki ke hoʻohana ʻia ʻo OpenTitan ma kahi e pono ai e hōʻoia i ka pono o nā lako lako polokalamu a me nā lako polokalamu, me ka hōʻoia ʻana ʻaʻole i hoʻopili ʻia nā ʻāpana ʻōnaehana koʻikoʻi a ua hoʻokumu ʻia ma ke code i hōʻoia ʻia a i ʻae ʻia e ka mea hana.

Hiki ke hoʻohana ʻia nā chips e pili ana i OpenTitan
nā motherboards server, nā kāleka pūnaewele, nā mea kūʻai aku, nā mea ala, nā pūnaewele o nā mea no ka hōʻoia ʻana i ka firmware (ka ʻike ʻana i ka hoʻololi ʻana o ka firmware e ka malware), ka hāʻawi ʻana i kahi ʻōnaehana hoʻonohonoho cryptographically kūʻokoʻa (pale i ka hoʻololi ʻana i nā lako), pale i nā kī cryptographic (ka hoʻokaʻawale kī i ka hihia. loaʻa i ka mea hoʻouka ke komo kino i nā mea hana), hāʻawi i nā lawelawe e pili ana i ka palekana a me ka mālama ʻana i kahi log loiloi kaʻawale ʻaʻole hiki ke hoʻoponopono a holoi ʻia.

Hoʻolaha ʻo Google i ka papahana OpenTitan e hana i nā ʻāpana hilinaʻi

Source: opennet.ru

Pākuʻi i ka manaʻo hoʻopuka