Google and partners including Western Digital today announced a first-of-its-kind open source project, called OpenTitan, that tackles silicon root of trust (RoT). The new group says it will produce a RoT silicon reference design and integration guidelines for use in data center servers, storage, and other devices.
Root of trust is extremely important because it embeds security mechanisms at the silicon level and ensures the compute module is always trusted by the operating system. Silicon RoT technology can be used in a variety of hardware, from server motherboards and network cards to mobile phones and IoT devices. Google developed its own RoT chip called Titan to establish hardware root of trust for Google Cloud servers. In fact, all of the hyperscale cloud providers as well as major data center infrastructure vendors like Cisco and Hewlett Packard Enterprise have their own RoT technology — but therein lies the problem, according to Google and friends.
Silicon root of trust is “a highly proprietary space,” said Dominic Rizzo, OpenTitan lead at Google Cloud in a press briefing ahead of today’s launch. “So what we are doing is opening everything up so you can establish security in the lowest levels [of hardware] available without the blind trust in a proprietary design… We believe that transparency is fundamental to security.”
And the way to do this, Rizzo said, is through open source silicon.
It’s also important to note that Google is not open sourcing its Titan chip. Instead, the project participants will develop a vendor- and platform-agnostic silicon RoT design.
OpenTitan PartnersUnited Kingdom based lowRISC, a not-for-profit engineering company, will manage OpenTitan. Other partners at launch include Swiss university ETH Zürich, mobile security management firm Giesecke & Devrient Mobile Security, semiconductor company Nuvoton, and data storage firm Western Digital.
Professor Luca Benini's research group at ETH Zürich contributed the Zero-riscy RISC-V microprocessor core — a key OpenTitan building block — to lowRISC. Nuvoton plans to bring OpenTitan RoT embedded controller products to market. And Western Digital has been a major contributor to OpenTitan’s design and design verification efforts.
“The security of storage devices, whether implicitly or explicitly, is fundamental to overall security,” said Richard New, VP of research and development at Western Digital. His company also made several contributions to the Linux kernel specifically related to the storage stack, he added. “We are working with our partners here today to help define the architecture of the OpenTitan platform to ensure it can meet the future requirements for our storage devices and projects.”
Western Digital is also active in the RISC-V (pronounced “risk-five”) community, which is working on an open source silicon instruction set. “For us, the OpenTitan project is a natural extension of that,” New said.
RISC-V is also the basis of the Linux Foundation’s new CHIPS (Common Hardware for Interfaces, Processors and Systems) Alliance, which launched in March. Western Digital and Google are members of this open source silicon group as well.
Comments