lowRISC / lowRISC/opentitan

[otbn] Protect scrambling keys at rest

Open
#20,162 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component:Security IP:otbn Priority:P3 Type:Enhancement Type:FutureRelease
Dominant language
SystemVerilog
Stars
3.6k
Forks
1.1k
Avg merge
2d 22h
Merged PRs (30d)
141

Description

### Description

It has previously been discussed that scrambling keys are obtained from OTP and then stored in local registers without integrity protection for use withing the scrambling device (see #12111 as well as Security Working group meeting of Sept 14 2023). For OTBN, the option of adding integrity protection has been discussed. But since other, algorithmic countermeasures will be needed for Earl Grey anyway, the implementation of ECC for the scrambling keys has been postponed to a future release.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by reviewing issue #12111 and the Security Working Group meeting of September 14, 2023, then examine OTBN's scrambling-key flow from OTP into local registers; done requires a defined and implemented ECC integrity-protection approach for a future release.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.