ProHoster > ΠΠ»ΠΎΠ³ > Kev tswj hwm > Qhib qhov chaw OpenTitan nti yuav hloov cov hauv paus ntawm kev ntseeg siab ntawm Intel thiab ARM
Qhib qhov chaw OpenTitan nti yuav hloov cov hauv paus ntawm kev ntseeg siab ntawm Intel thiab ARM
Lub koom haum non-profit lowRISC nrog Google thiab lwm tus neeg txhawb nqa Lub Kaum Ib Hlis 5, 2019 ΡΠ΅Π΄ΡΡΠ°Π²ΠΈΠ»Π° peb tes num QhibTitan, uas hu ua "thawj qhov chaw qhib qhov project los tsim ib qho qhib, zoo siab chip architecture nrog lub hauv paus ntawm kev ntseeg siab (RoT) ntawm qib kho vajtse."
OpenTitan raws li RISC-V architecture yog lub hom phiaj tshwj xeeb rau kev teeb tsa ntawm cov servers hauv cov chaw khaws ntaub ntawv thiab hauv lwm yam khoom siv uas tsim nyog los xyuas kom meej khau raj qhov tseeb, tiv thaiv lub firmware los ntawm kev hloov pauv thiab tshem tawm qhov muaj peev xwm ntawm rootkits: cov no yog cov motherboards, network cards, routers, IoT li, mobile gadgets, thiab lwm yam.
Ntawm chav kawm, zoo sib xws modules muaj nyob rau hauv niaj hnub processors. Piv txwv li, Intel Hardware Boot Guard module yog lub hauv paus ntawm kev ntseeg siab hauv Intel processors. Nws txheeb xyuas qhov tseeb ntawm UEFI BIOS los ntawm kev ntseeg siab ua ntej thauj khoom OS. Tab sis cov lus nug yog, ntau npaum li cas peb tuaj yeem tso siab rau cov hauv paus ntawm kev ntseeg siab, muab tias peb tsis muaj kev lees paub tias yuav tsis muaj kab hauv kev tsim, thiab tsis muaj txoj hauv kev los xyuas nws? Saib tsab xov xwm "SchrΓΆdinger's Trusted Download. Intel Boot Guard" nrog rau cov lus piav qhia ntawm "yuav ua li cas cov kab laum uas tau cloned rau ntau xyoo hauv kev tsim tawm ntawm ntau tus neeg muag khoom tso cai rau tus neeg tawm tsam tuaj yeem siv cov thev naus laus zis no los tsim cov cuab yeej zais zais hauv lub kaw lus uas tsis tuaj yeem tshem tawm (txawm tias nrog tus programmer).
Qhov kev hem thawj ntawm kev sib haum xeeb ntawm cov khoom siv hauv cov saw hlau yog qhov xav tsis thoob tiag: pom tau tias, txhua tus kws tshaj lij hluav taws xob ua haujlwm pib tuaj yeem ua cov kab laum rau hauv server motherboardsiv cov cuab yeej raug nqi tsis tshaj $200. Qee cov kws tshaj lij xav tias "cov koom haum nrog kev siv nyiaj ntau pua lab daus las tuaj yeem ua qhov no tau ntau xyoo." Txawm hais tias tsis muaj pov thawj, nws yog theoretical ua tau.
"Yog tias koj tsis tuaj yeem ntseeg lub hardware bootloader, nws dhau los ua si," hais tias Gavin Ferris, tus tswv cuab ntawm pawg thawj coj ntawm lowRISC. - Nws tsis muaj teeb meem dab tsi lub operating system ua - yog hais tias los ntawm lub sij hawm lub operating system loads koj muaj kev cuam tshuam, ces tus so yog ib tug teeb meem ntawm technology. Koj twb tiav lawm."
Qhov teeb meem no yuav tsum tau daws los ntawm thawj ntawm nws hom qhib hardware platform OpenTitan (GitHub repository, cov ntaub ntawv, hardware specifications). Kev txav deb ntawm cov tswv cuab daws teeb meem yuav pab hloov "kev lag luam RoT qeeb thiab tsis zoo," Google hais.
Google nws tus kheej pib tsim Titan tom qab tshawb pom Minix operating system ua rau Intel Management Engine (ME) chips. Qhov no complex OS nthuav dav qhov chaw nres nyob rau hauv unpredictable thiab uncontrolled txoj kev. Google sim tshem tawm Intel Management Engine (ME), tab sis ua tsis tiav.