zeroRISC CEO Dom Rizzo on Fueling Open Source Silicon for Cybersecurity with $10 Million Seed Funding
zeroRISC CEO Dom Rizzo dives into how $10 million in seed funding will be used to drive commercial adoption of open source silicon optimized for cybersecurity software.
Transcript
Hey guys, thanks for the throw. We're here with Don Rizzo, who's the CEO for zero Risk, and they're fresh offer raising $10 million in additional funding. And a lot of that is gonna go into the commercialization of an open source silicon project known as Open Titan.
And then I'm gonna let Dom explain what it is that does Dom, welcome to show. Absolutely. Thank you for having me.
Really appreciate it. All right. So, uh, Let's start at the beginning as they say.
What exactly is Open Titan? So, open Titan, uh, is actually a, a project that I, I started almost, uh, 10 years ago. Uh, and then eventually really got it off the ground when I was at, uh, Google about seven years ago.
Uh, and since then, it has really grown to become the first kind of commercially relevant open source silicon project. And so what we do is we are major contributors to Open Titan, but we also take the IP that we developed under that project, and we work with customers to both integrate it into their designs, but then also provide the sort of supply chain integrity services, the sort of manageability of these devices in the field, which is really where a lot of our focus is, because a lot of the work, broken Titan is, is fairly mature at this point. Where are we on the adoption of this?
I mean, are we still building out the silicon or are we seeing use cases for this already? And what are they? Well, so the silicon itself has been adopted by Google and their Chromebook and, uh, data center is in the process of being adopted by them.
Uh, we also know, and I think this is, this is public, is that Voss is using it as the silicon root of trust in all of their triplets. I think there is a really, uh, really exceptional talk given at the Risk five Summit in Paris a few weeks ago by a Voss employee, a fellow named, uh, Robert Shilling. Just done some really exceptional work in taking the first kind of discreet open Titan design and adapting that to be a, a sort of secure element that's much more suitable for inclusion into any kind of device.
Where does zero risk fit in? What are you guys doing? And, and, and are you, I'm assuming providing some level of support, but what else are you doing?
Yeah, so we do a, a couple different things. Basically three different tranches. Uh, we are major, like I said, major contributors to the upstream, uh, open Titan project, uh, primarily around cryptography, post quantum cryptography, certifiable cryptography.
Uh, we do also work with customers to, uh, help with integration and support of the open source project. I mean, as we kind of know, uh, open source isn't free. It does require some often level of support from the people who know it.
But then what one of the things that we really focus on is we are deploying hardware into the, uh, uh, sort of silicon manufacturing facilities to establish trust in these devices from, from the, from the get go. And what we do with that, that sort of initial trusted, uh, relationship is we're then able to, uh, manufacture and assemble anywhere, uh, while still retaining, uh, ownership and control of the silicon and the devices it goes into for customers. What Leads people to conclude that they need a new process or architecture?
Is it just some new project, or are there other forces at play here where people are starting to reevaluate the legacy architectures they have? Well, I think it's, it's not just about legacy architectures. It's about, uh, secure security.
And silicon has traditionally been kind of a high end feature. It's been a, a premium feature. And I think something like, uh, open Titan, other projects, uh, really the, the ecosystem of IP that's been created by Open Titan enables the ability to bring security everywhere, right?
If you have to pay a huge licensing fee to add a secure element to a commodity chip, a 40 cent chip, you're not, you're not gonna do that, right? Because why would you increase the cost basis of that device if the security is borderline free? Why wouldn't you do it, right?
It, it makes, it makes the, the designs more trustworthy, more transparent, more controllable by, by the end user. So that's just a net good for everyone involved. Is the concern about, uh, post quantum encryption also gonna change the conversation as well?
Because I think some of the cryptography we're gonna run maybe is a little more Comput intensive. I think it can be. So I will say post quantum is very, very important, uh, regardless of what your stance is on, on when we're gonna have a cryptographically relevant post quantum computer, uh, the reality is, is that everyone is transitioning to that and, uh, that is going to be quite a significant investment.
So, uh, our, uh, we, our, our principal cryptographer Jade Philipo, has done really exceptional bleeding edge work on not just the secure verified boot, but also sort of computationally efficient implementations of the latest NIST lattice based standards, right? So there's, there's still, uh, kind of some open research questions there, especially around the fault injection resistance, the side channel, uh, resistance. And later this year we're gonna actually be releasing, um, some pretty impressive kits that implements that in a very area cost and compute, uh, efficient way.
So Will people implement this silicons, kind of like a co-processor for security, or does it become the main processor of the platform that just happens to be more secure? You know, it really depends on what class of chip you're talking about and whether you are primarily concerned about sort of static at boot time integrity, or you also want to leverage a, um, sort of leverage a secure co-processor as like a secure element or a secure enclave style processing device during runtime. So it really, uh, it really depends, and that's why a lot of the IP is designed to be in a very like, flexible modular fashion.
'cause some people, some people don't even need a processor, right? They just care about identity, which is really important, still relevant for us because we build the identity database, we build the identity, identity harvesting sort of equipment, um, but they don't need all the bells and whistles of having like a full 32 bit or 64 bit core in there to run applications. So it, it's a, and it's a little bit of a wishy-washy answer, but the, the real answer is it really depends on what your specific, uh, security secure identity needs are.
So what's the plan for the 10 million? What needs to be done next? Uh, well, we, uh, have, have been hiring fairly aggressively, uh, in the engineering space.
We are, uh, bringing in additional commercial support because, uh, you know, there's a lot more to running a business than just really, really good engineering. Um, and I think what that really does for us is it gets us to the next level in terms of customer acquisition and support. When you think about this, there's been a lot of concerns over the years about how companies make money in the open source era.
So how do we kind of make a project maintainable and still create an ecosystem where there's people who are like yourself, who are building companies and making money on this in a way that's sustainable? Well, I think, uh, red Hat really showed the way for that, where you, you decide on an open source core, which you support and maintain, and then you add a lot of support and services around that. So there's the support and services associated with the silicon ip, which there's plenty of room to run there.
But then for us, there's also the manufacturing time and the runtime, uh, sort of cloud-based identity as a service model where, uh, we just feel like there's a very, uh, uh, very rich environment. There's a lot of lot that can be offered that leverages some of the secure silicon that we can basically give away, uh, to support it all. What do people who want to build something on this need to be aware of or to think about?
I mean, a lot of folks would be hearing about this for the first time. So how do they get started here? I mean, you can get started with the, the upstream documentation, uh, and, and try and run with it.
Uh, that's often fairly challenging. Uh, you can always reach out. We have plenty of points of contact, uh, ways of contact us through our website.
Um, I would say the best way to get started is just to download it and start, um, it's all there. It's all, it's all freely available. And if you, and if you have a question, please don't hesitate to ask because it can be quite challenging to navigate on your own.
Are you at all worried that the Intel's name Ds of the world, we'll just, you know, basically see what you've done and follow suit? I think that that kind of adoption just sort of shows that, uh, this is, uh, valid and commercially relevant. I don't see any cause for concern there.
I would hope that they would want to adopt this because this level of transparency and high quality development is quite good. And I know that Intel and, uh, a MD in particular, they have a long, long history in doing open source, uh, being supportive of open source firmware and various other, uh, uh, open source software projects. I don't know why this would be any different, especially Intel who has a very large fab that they would like to fill.
So, So speaking of that, are there foundries that are prepared to go build chips on this? Uh, well, we happen to know that there are some foundries who are already building, uh, chips, leveraging this technology, but I think for now, the foundries are really deferring that to their customers. The SOC uh, vendors, the people who are designing the FLIs, the fli, uh, semis who are designing the devices As you kind of put all this together, um, is the nature of the workloads that we're running, particularly in security changing, because I feel like, well, there's just more data to be processed and analyzed, and we're grabbing more telemetry data than ever.
And so are the characteristics of the workloads and security changing to the point where I do need some different approach to the silicon? So I think, yes, there needs to be a different approach to the silicon. I don't think the changing nature of the compute is driving that so much as the growing awareness that security is not a feature to be stapled on.
It is a holistic sort of design enterprise. Uh, and so people are becoming more and more aware, this is especially true with the Cybersecurity Resiliency Act in Europe, that you do have to take some responsibility for the lifetime integrity of, of what is in your silicon, what is running on your silicon, where your silicon is coming from. And I think that is really driving some of the, the change, right?
Um, I don't think that today's workloads are necessarily, um, require a different approach. I just think that there's now more of a realization that there needs to be a holistic sort of security architecture in every chip. So how did you get involved with this?
Not everybody wakes up one morning and says, I know I'm gonna go build an open source silicon project. So what's the backstory here? Well, when I was a, an undergrad 20, 20, 25 years ago, I worked for a fellow named Andrew Bunny Wine, who really impressed upon me that, uh, visibility matters, especially in security.
You need to be able to trust the things that are running your code. And owning a device means being able to control the code that runs on it. So, you know, fast forward 10 years, I, I first started pitching this, it was originally called Honest Machines, took me about another three, four years to land it inside of Google.
Um, and now we're off to the races. Right now we've got commercial chips coming out, being released by New Baton that are based on the design. We've got people like Voss adopting it for their, uh, internal, uh, their chip root of trust.
So it's been a bit of a journey. Um, and I think this is really, this is just a, uh, for me, there's kind of two things motivating it. One, I find it bizarre that my, my iPhone has better security than the, the industrial controllers that run our critical infrastructure.
And two, it just kind of seems an obvious thing, right? If we're gonna run, if most cryptography libraries are gonna be open source because they're inspectable, well then the thing that verifies what's running on the chip should also be open source because it's even lower down the stack, if that makes sense. Sure.
So ultimately, you know, as you look in the year ahead, what's gonna be next for the project? What are you guys working on? Oh, I think for, for the project, it just continues to move forward.
Like I said before, there's been a lot of interesting work recently, uh, around the, uh, integrated, uh, secure element space, the sort of, uh, uh, what they call the Darjeeling design that, that Voss and Robert have been driving. Uh, that's something that we're particularly interested in. I think there's likely to be some additional work on the cryptography, sort of moving it towards a production ready basis.
And those are, I think, the really, really key, uh, important aspects are, uh, for the future. Right? So it's an, it's an interesting thing because we've sort of, we've proven that the IP is good.
We've gotten it over that first hump, and so now it's ready to use in a way, right? So it's, it's the, the work required going forward is gonna be significantly less than the work that was required to get here. Good folks.
Well, you heard it here. We've had open source infrastructure for a while, and now it's all the way down to the silicon level, and it's gonna be optimized for specific use cases like security. So it's a brave new world.
Stay tuned. Hey, Dom, thanks for being on the show. Absolutely.
Really appreciate your time. All right. And back to you guys in the studio.