OpenTrust Initiative for Silicon Security – Dom Rizzo, zeroRISC
ZeroRISC CEO Dom Rizzo, in the wake of picking up $5 million in funding, explains how an open source OpenTrust cybersecurity initiative for silicon will ultimately make IT environments more secure in a way that also reduces costs.
Transcript
This is Textron tv. Hey guys, thanks for the throwaway here with Dom Rizzo, who is CEO for zero risk, and we're talking about an open Titan effort to better secure silicon, which should have all kinds of interesting benefits downstream. Dom, welcome to the show.
Uh, thanks, thanks for having me. Very excited to, uh, have this discussion. All right, you guys just picked up some funding for this effort, but describe what it is you guys are trying to do, and why haven't we done it before?
Yeah, absolutely. So, uh, I it's worth clarifying that I am, as you say, I'm the CEO of zero risk. Now, zero risk is actually a partner in the Open Titan Project, along with a lot of other partners.
Um, uh, so the project itself is a open source secure silicon effort. Um, I'll get a little bit more into that in a second. But, um, what's really important to understand is, uh, it's actually being, uh, hosted and, and sort of managed from a governance perspective by an independent, uh, nonprofit, the low risk organization in, uh, Cambridge uk.
And so we, along with, uh, other folks, Kasi and Devian, uh, wind Bond Vuitton, Google, um, Seagate, Western Digital, we're all partners in this effort together, right? So we're all contributing and we're all benefiting from it. And what the effort itself is, the, the Open Titan project, uh, it is, uh, basically an effort to democratize and make accessible, uh, high quality, secure silicon technology.
Now, we often talk about it as a, a root of trust effort that's actually kind of a lighting a little bit of the high level base. What, what it really is, is a, um, open source silicon ecosystem. Um, it's something that I've founded about five years ago, uh, and, and we've grown it to a pretty significant effort at this point.
I think on any given day, there's somewhere between 40 50 active individual contributors. Um, there are kind of, there are not just individual, uh, sort of, you know, IP blocks, little crypto accelerators, things like that. It's actually, uh, really been focused the last five years on producing, um, a first, uh, discreet device.
So what is basically a secure microcontroller, which itself can serve as a root of trust for say, critical infrastructure, servers, operational technology, that sort of thing, right? Mm-Hmm. Um, but, oh, sorry.
Go, go ahead, please. Well, It sounds like almost to me that we have been layering all kinds of stuff in software to make up for the fact that, you know, we didn't address some of these issues in hardware. So, um, how exactly will all this manifest itself and what will be the downstream impact from your perspective?
Right. So the first thing, uh, well, for one, I can say that I know that a, a lot of folks have actually picked up the silicon IP because, you know, you can look at the, the testing, the design verification dashboards. So we know people have already integrated it into a fair number of, uh, SOCs.
Uh, the first thing that you can expect to see commercially is with our partners Vuitton. Uh, there is going to be an open market, uh, part made available, right? So something where the silicon design, uh, in the instantiated chip actually matches, uh, what is upstream in the open source repository, which has never been done before, to my knowledge.
And you're absolutely right when you say that we've been, you know, I would say that we have focused a lot on security at the operating system, uh, layer. But, um, as we're seeing with some of the recent attacks, I think, uh, there was a Barracuda Secure email gateway that I think got hit at the firmer level, which is, again, below the operating system. I think, uh, something similar happened with, uh, the Cisco iOS, uh, XE devices the last couple weeks.
So we're seeing like a real increase, uh, not just in the sophistication of, uh, threat actors, but also kind of as they're working their way down the stack, right? So we're seeing these attacks come in and really have a material impact. And once you're, you know, without a silicon root of trust, without that, that starting, uh, security in the hardware, you basically have to throw the machine out.
You can't trust it anymore from that point, right? Because any, any security you layer in the oss, it could be lying to you, you just don't know, Hmm. Are the bad guys getting better at making attacks against firmware and that level of infrastructure?
'cause so much of what they have done historically has been trivial in comparison. Um, I don't know if I would say they're, they're, they're getting better. I mean, these folks are pretty skilled actors, um, and, and need to be taken seriously.
I just think that either it's becoming more apparent that these things are happening or, um, you know, there, there's a, there's just a general increase in, uh, cyber threats as it, you know, they, they go to where the, the soft spots are. Right? And it sounds like we're kind of working our way down the stack, and we know for a fact that the security does actually begin in the silicon.
So if you're not doing it intentionally with something like Open Titan, um, you're, you're gonna be left vulnerable. So what is the role of your company in this ecosystem? What specific part are you focused on?
So, uh, what we are focused on is we, uh, we are focused on, um, working with our partners to enable integrations of the Open Titan Silicon ip, the Open Titan Silicon designs, uh, in their devices. That's one thing that we do. So we do a lot of both, uh, upstream contributions, you know, showing leadership in the open source project, um, but also working with partners downstream to both, uh, integrate, you know, the, the IP for the discrete design into, say the new Vuitton part that's coming out, or, or working with other partners to integrate this, um, this variant of the, uh, of, of the secure execution environment we've built into their larger SOCs, right?
So, so that's part of it. Um, but then we provide a layer of, you know, secure operating system, uh, that's certification compliant, be it common criteria or NIST FIPs level certifications, uh, as well as the kind of, uh, cloud infrastructure that plugs into all of that and kind of makes it, um, gives us the ability to provide sort of an, uh, a very serious layer or level of, shall we say, um, uh, integrity protection for these devices throughout the entire supply chain. Mm-Hmm.
So it's kind of a fab to field, right? We, we cover the entire spectrum, and it all starts with the silicon root of trust. Do you think ultimately we'll just have better security, or will we see the total cost of cybersecurity decline over time if we do more at the silicon level?
Uh, I think that's a good question. Um, I mean, I think this is, is one of a number of efforts that I think is gonna help raise all boats across industry, right? You know, it's, it's notoriously difficult to, uh, uh, convince folks to pay ahead of time for security, but then, um, they often come to, to regret that lack of investment later, right?
So one of the things we've done is, uh, and this is more on the open Titan side, obviously, uh, really try to make something that is transparent and trustworthy and available for everyone, right? You know, we, we want to encourage adoption by really lowering, uh, the, the cost, right? By providing something of value.
Um, will this lower, I think what this will lower is the costs of long-term. It'll lower the costs of, I would say, recovery from something like a ransomware attack, because with the, the silicon root of trust, you can actually flip a bit and, you know, um, uh, basically guarantee that what you're, what you're booting is the right image. Um, I think it will, it'll certainly raise the bar, it'll make it more difficult for, for remote attacks, remote code exploits, things of that nature.
Do you think that somewhere along the line in the history of chip and processor development, that we were so zoned in on performance that we forgot to think through the security equation and we're coming around full circle to revisit that? I, I think that's absolutely true, and I wouldn't say this is not for very reasonable reasons. I would say, say we were focused on performance because we followed this curve called Moore's Law for a very, very long time.
And that said that the money was in the performance and, and, you know, people have mortgages, right? And so we really followed that curve. Now, I think there's an opportunity now to kind of, um, you know, you look at open ISAs like risk five, I think there's an opportunity now to start to revisit some of these things in a more open and transparent way where, um, it really enhances security, right?
You know, security should not be this kind of proprietary, difficult to inspect. You have to take it on faith kind of thing. And I think we're kind of seeing both, uh, more availability of high quality open, uh, secure systems, but also, as you say, that kind of, there, there's kind of cascade of, of incidents, right?
And they, and they feel like they're getting more and more serious as everything becomes more and more connected. Um, and I think there's a, a, a genuine concern, a genuine motivation. Uh, you see this especially with say, um, cisa secure by design, secure byol default efforts where, um, we're really paying attention to the lower levels.
We're really paying attention to, um, closing some of these weaknesses, closing some of these vulnerabilities. Do you think the governments around the world are gonna wake up one day and start making requirements and regulations for this type of security at the silicon level? Because they're gonna realize that, um, it is where it all starts.
I, I, the, I mean, realistically, I think they've already started. I think, uh, we're seeing this, uh, in Europe in particular with the NAS two guidance, um, uh, which is, I believe already been passed by the, the, uh, European Commission and is now being, uh, turned into regulations at each of the individual member state levels. And I believe that comes into force later in 2024.
And that has real financial penalties attached to it. We also see it with the Cybersecurity Resiliency Act, uh, the CRA, which is another, another European effort, um, where again, there are real financial penalties now being, uh, put upon device makers, device integrators, uh, that we didn't really have in the past. And obviously with the, um, not obviously, but the other, the other element we're seeing is the, uh, uh, Biden Harris Cybersecurity Act, uh, that was released, uh, earlier this year.
It too, is starting to talk about a shift, a general shift in liability from the end user or the consumer onto the device maker. Um, but then also doing a lot of work to put out good guidance on securing these devices, right? Put out, uh, requests for comments on things like memory safe, uh, languages, right?
So you're kind of, you're starting to see this happen in all layers of the stack too, right? Ultimately it's kind of the IT folks and the purchasing managers and maybe even the individual end users to buy things that are secure. So do you think as we go along, we're gonna start having, um, I don't know, requirements from the purchasing department that says, anything we buy needs to have this type of silicon in it?
I, I certainly think, at least from a liability mitigation perspective, we're definitely gonna start to see some kind of requirements. Now, I don't know if it's, I would expect there to be some requirements around root of trust, uh, security and silicon. 'cause the reality is just, just because of the way modern systems work or all systems work, your security starts in the silicon, whether or not you realize it, right?
So it's much better to be explicit about it, to understand what's there, to have a, a non-black box solution, to have something that you can actually build your own confidence, uh, in the, the security, the trustworthiness of right now, I wouldn't say it's gonna be this specific design per se, um, but I certainly think we've made it, uh, uh, straightforward cost-effective, um, transparent, trustworthy, all these, all these good things, uh, to leverage this particular design or even reconfigure this particular design. 'cause it is all permissively licensed, uh, as, as necessary to meet, you know, individual, uh, requirements or needs. So I think we've spent the better part of the last three and a half decades digging this particular cybersecurity hole.
So how long will it take us to dig our way outta it? Well, you know, uh, supply chains, uh, take a little while for things to propagate through. I think one thing that is interesting about Open Titan is we are about five years in and we have actually, uh, taped out and produced the first piece of engineering sample silicon that is aligned to an upstream design.
So I think this could actually all happen quite a bit, uh, faster than we might expect. Um, it's not a, it's not a question of is open silicon coming or is trustworthy silicon coming, or are there viable root of trust designs out there that are accessible? It, it's already here, right?
So I think that actually, um, for once puts us a little bit ahead of the curve. Um, although I will say, you know, the, the Cisco iOS xe, um, attack, that was weeks ago, right? So, you know, these things are becoming more present, shall we say.
So, but I also think we have a good handle on how to solve the problem technically. And I will say that the regulatory environment seems to be, certainly in my lifetime, have changed pretty dramatically in the last three, four or five years. Uh, and I do think that there is the right attention on this, that, that, that it is a addressable problem, but we can't solve it at the OSS layer.
We can't solve it at the network layer. It, it's belt and suspenders, turtles all the way down, whatever, whatever expression you want to, you want to use. But we do really have to go lower than, than we have before.
All right folks. Well, you heard it here. The history of computing, in case you don't know, has generally been things that start up at the top end of the stack, find their way down into the silicon and the instruction set to make it universally accessible for everybody.
And security, it looks like might be no exception. Dom, thanks for being on the show. Absolutely.
Thanks for having me.