lowRISC / lowRISC/opentitan

[rom_ext] Ownership Transfer configuration

Open
#19,595 0 comments 0 reactions 1 assignee View on GitHub

@cfrantz is already working on this.

Since Sep 1, 2023.

Priority:P2 SW:ROM_EXT Type:Task
Dominant language
SystemVerilog
Stars
3.6k
Forks
1.1k
Avg merge
2d 22h
Merged PRs (30d)
141

Description

- [ ] Create and document an ownership transfer payload. Includes:
- Owner validation public keys, unlock keys and next_owner endorsement keys.
- Keymgr diversification constants
- Flash lockdown & configuration preferences (scrambling, high-endurance, etc).
- Other owner lockdown preferences.
- Review current [Ownership Transfer docs](https://opentitan.org/book/doc/security/specs/ownership_transfer/index.html).
- [ ] Read & validate current owner INFO page.
- [ ] Use owner public keys for next-stage validation.
- [ ] Diversify keymgr with diversification constants.
- [ ] Configure flash_ctrl based on owner flash preferences.
- [ ] Lockdown other portions of the chip as requested (ie: allow SRAM_EXEC?).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.