- Introduction
- What is a Root of Trust?
- Why open silicon: OpenTitan and Pavona
- Threats and trust boundaries
- The simulated chip
- 1. Booting a chip on your laptop
- 1.1. Development environment
- 1.2. Building Egret in Verilator
- 1.3. Hello, World!
- 1.4. Reading the memory map
- Secure boot
- 2. How a chip trusts its own code
- 2.1. The chain of trust
- 2.2. Signing and verifying an image
- 2.3. Building and running a signed chain
- 2.4. ePMP memory protection
- 2.5. Reading the boot log
- Secure storage and lifecycle
- 3. Keeping secrets and managing state
- 3.1. OTP and flash scrambling
- 3.2. Lifecycle states
- 3.3. The lifecycle gate
- Identity and keys (DICE)
- 4. Where a chip's identity comes from
- 4.1. The OTP root secret
- 4.2. Key manager derivation and DICE
- 4.3. Software binding and key versioning
- Attestation
- 5. Proving who you are
- 5.1. Creator and Owner Identity Certificates
- 5.2. The certificate chain
- 5.3. Verifying a chain off-device
- Post-quantum crypto
- 6. Cryptography that survives quantum computers
- 6.1. The acc coprocessor
- 6.2. ML-KEM, ML-DSA, and SPHINCS+
- 6.3. NIST known-answer tests
- 6.4. PQC-enabled secure boot
- Provisioning and ownership
- 7. Birth and handover of a device
- 7.1. Personalization
- 7.2. ECIES-wrapped secret injection
- 7.3. Ownership transfer
- Egret as a secure co-processor
- 8. Driving the root of trust from a host
- 8.1. The command channel
- 8.2. One command, end to end
- 8.3. Building a real host
- 8.4. Breaking the link
- 9. References