The chip also uses resistive RAM, or RRAM, a type of nonvolatile memory that Huang says is designed to make physical extraction of stored data more difficult than conventional flash memory. With flash memory, he says, “if you de-layer it down to the actual flash cells … you can just see the ones and zeros literally on these chips.”
Huang is cautious, however, about overhyping the chip’s security capabilities. He estimates that it could withstand attacks involving tens of thousands of dollars in resources, but says an adversary with millions of dollars and a sophisticated hardware-analysis lab could likely defeat it.
“I actually think it’s one of the most secure chips you can get out there, but I [also] think most chips have been oversold in terms of security,” he says.
Huang says he likes the fact that the chip will be stress-tested by Defcon attendees and knows they will likely hack them and expose flaws that will help him make them even more secure.
“I fully expect there will be zero-days [that people find in the code]. It’s actually … one of the features … of launching at Defcon,” he says of designing an open source chip capable of being examined.
Today the chip can function as a YubiKey-like security token; but in the future, he says, it could become an HSM or run other software such as Linux. The hardware uses a 350 MHz RISC-V processor with 2 megabytes of SRAM and 4 megabytes of RRAM, which he says puts it “on the edge of being able to run Linux,” and it has 4x 700MHz PicoRV32 cores for doing input-output. It already runs MicroPython and has C and Rust development kits.
Huang plans to expand the chip’s features himself, but he also expects DefCon participants to build on what he’s provided and make the chips their own.
This story originally appeared on wired.com.
Leave a Reply