RK
Radim Krčmář
— On the schedule —
Hardware-enforced cryptographic contexts that RISC-V software can use but never read
The talk gives an opportunity to shape a proposed RISC-V ISA extension for operating with cryptographic keys along their metadata without exposing the key in plain text to software. After a brief introduction to how RISC-V develops its ISA, the talk will cover the ISA concepts and mechanisms, including the stated stored in new context registers, atomic cryptographic execution, supported algorithms, sealed contexts in memory, import/export of contexts, and coupling cryptographic contexts to hardware+software contexts. It will also discuss the expected division of responsibility between hardware, operating systems, trusted provisioning components, applications, and cryptographic libraries. The architectural overview will help you asses how the RISC-V extension could integrate in your system. More importantly, it provides a chance to identify shortcomings and share feedback during the talk, in the hallways, or through RISC-V International, rather than cursing later.
— Compositor's note —
Radim Krčmář is an engineer at Qualcomm, working at the boundary between RISC-V software and hardware. He is a contributor to the High Assurance Cryptography Task Group, which is developing a secure and interoperable hardware solution for opaque keys on RISC-V.