Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange  ·  activity timestamp 3 days ago

Yay, the embargo was finally lifted yesterday so we can talk about the UK Government funding for #CHERIoT!

They funded us (SCI) to do two projects, for a total of £7.7M:

  • Bring #Rust on CHERIoT to production qualities.
  • Build our second-generation chip with a dual-issue core, post-quantum crypto hardware, and an edge inference accelerator.

#CHERI

  • Copy link
  • Flag this post
  • Block
Simon Tatham
@simontatham@hachyderm.io replied  ·  activity timestamp 3 days ago

@david_chisnall I'm curious about the post-quantum accelerator. Where I come from (the SSH community) people are still arguing about which PQ algorithms to use. But surely a hardware accelerator has to be specific to particular algorithms. Which ones have won the lottery?

  • Copy link
  • Flag this comment
  • Block
Flippin' 'eck, Tucker!
@losttourist@social.chatty.monster replied  ·  activity timestamp 3 days ago

@david_chisnall I have no idea what "a dual-issue core, post-quantum crypto hardware, and an edge inference accelerator" means, but it sounds incredibly impressive and huge congratulations on your funding.

  • Copy link
  • Flag this comment
  • Block
Leigh Garland
@toychicken@mastodon.social replied  ·  activity timestamp 3 days ago

@david_chisnall congratulations 🎉

  • Copy link
  • Flag this comment
  • Block
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 3 days ago

@david_chisnall Congratulations!

  • Copy link
  • Flag this comment
  • Block
Jesse Spielman
@heavyimage@mastodon.social replied  ·  activity timestamp 3 days ago

@david_chisnall ah I am also working on a different aspect of this project. Just posted a link last night to the same news piece. Small world!

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 3 days ago

@heavyimage Nice! Which project?

  • Copy link
  • Flag this comment
  • Block
Jesse Spielman
@heavyimage@mastodon.social replied  ·  activity timestamp 3 days ago

@david_chisnall I’m with the University of Birmingham team working on Zephyr.

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 3 days ago

@heavyimage Ah, I hope you've read my posts in why we wrote a new RTOS for CHERIoT (TL;DR: retrofitting CHERI to existing RTOS designs will require either a load of breaking changes or leaving most of the security benefits of a CHERI platform on the floor.)

It will be very interesting to see if you can get anything useful out of Zephyr. Are you at CHERITech?

  • Copy link
  • Flag this comment
  • Block
Jesse Spielman
@heavyimage@mastodon.social replied  ·  activity timestamp 3 days ago

@david_chisnall no, sadly. Link to those posts?

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 3 days ago

@heavyimage

Part 1

Part 2

This one also probably has useful detail

CHERIoT Platform

How CHERIoT uses Sealing

Sealing is one of the oldest parts of CHERI and one of the most powerful. When I joined the project in 2012 it was integral to the early prototype call-gate mechanism. You can find this version in our 2014 tech report. It included CSealCode and CSealData instructions that assembled a pair of capabilities that could be used with the CCall instruction to perform a cross-compartment call. By our IEEE Security and Privacy 2015 paper, this had been replaced with the modern sealing mechanism that we use today.
  • Copy link
  • Flag this comment
  • Block
1 more replies (not shown)
dch :flantifa: :flan_hacker:
@dch@bsd.network replied  ·  activity timestamp 3 days ago

@david_chisnall congrats that’s fantastic news! I only understood it as far as rust, any public facing info might need some more clarification.

  • Copy link
  • Flag this comment
  • Block
dch :flantifa: :flan_hacker:
@dch@bsd.network replied  ·  activity timestamp 3 days ago

@david_chisnall and the press release omfg pure garbage. Not yours obviously but somebody made a dogs breakfast out of it.

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 3 days ago

@dch Yup, we'll do a proper press release soon. They didn't actually tell us the embargo was lifted, they just pushed out the press release. The minister changed just as the projects were starting, so everything needed more review. But I do enjoy the quotes:

Someone from the government saying these projects are important.

Someone from SCI saying the SCI project is important.

Someone from Microsoft saying the SCI project is important.

Someone from Google saying the SCI project is important.

  • Copy link
  • Flag this comment
  • Block
dch :flantifa: :flan_hacker:
@dch@bsd.network replied  ·  activity timestamp 3 days ago

@david_chisnall got it. Very Important Project.

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login