Defcon's new badge is a security key you can see inside

Defcon’s new badge is a security key you can see inside

Defcon 的新胸牌:一款你可以“透视”内部的硬件安全密钥

It’s been a longtime feature of the annual Defcon hacker conference that attendees come away not only with knowledge of new software vulnerabilities and hacking techniques but also an elaborately designed conference badge—often electronic masterpieces embedded with intricate puzzles, complex crypto challenges, hidden Easter eggs, and even the mechanical gear trains of a watch. 每年一度的 Defcon 黑客大会都有一个长期传统:参会者不仅能带走关于新软件漏洞和黑客技术的知识,还能获得设计精美的会议胸牌。这些胸牌往往是电子杰作,嵌入了复杂的谜题、高难度的加密挑战、隐藏的彩蛋,甚至还有机械手表的齿轮组。

Each year’s badge creator endeavors to top previous designs and blow the minds of hard-to-impress hackers. But this year’s badges take a different tack. Instead of the badge designs being the star, it’s what is inside the hardware that will really stand out. 每年的胸牌设计者都力求超越前作,让见多识广的黑客们大开眼界。但今年的胸牌采取了不同的策略:主角不再是胸牌的外观设计,而是其硬件内部的玄机。

This year, Defcon asked legendary hardware hacker Andrew “bunnie” Huang to create the badges—revealed here for the first time—and they include an innovative open source chip that Huang designed and that aims to do no less than advance the state of security, transparency, and trustworthiness in computing. 今年,Defcon 邀请了传奇硬件黑客 Andrew “bunnie” Huang 来设计胸牌(在此首次披露)。这些胸牌包含了一款由 Huang 设计的创新开源芯片,其目标旨在推动计算领域在安全性、透明度和可信度方面的进步。

But the chip isn’t just part of the badge. Its core module can be removed and used after the conference as a hardware security token, giving the badge a second life beyond Defcon. 但这枚芯片不仅仅是胸牌的一部分。其核心模块可以在会议结束后拆卸下来,作为硬件安全令牌使用,从而让胸牌在 Defcon 之外获得“第二次生命”。

The chip—called the Baochip-1x—is a “mostly” open source microcontroller that has been three years in the making and fulfills Huang’s years-long dream of making a chip whose security is verifiable. 这款名为 Baochip-1x 的芯片是一款“基本”开源的微控制器,历经三年研发,实现了 Huang 多年来制造一款安全性可验证芯片的梦想。

Huang has published the source code for the Baochip’s operating system, firmware, processor core, cryptographic engines, and input-output system, on GitHub, making these components available for inspection and use. Huang 已将 Baochip 的操作系统、固件、处理器核心、加密引擎和输入输出系统的源代码发布在 GitHub 上,供人们检查和使用。

The chip is also packaged so that researchers can peer inside to check the silicon itself and compare what they see against the published design, rather than having to trust that the manufactured chip is what the designers intended. 该芯片的封装方式也经过特殊处理,研究人员可以窥视其内部,检查硅片本身,并将所见内容与已发布的文档进行比对,而不必盲目相信制造出来的芯片就是设计者预期的样子。

Computer chips are traditionally black-box components with an opaque casing that obscures their circuitry. Even previous open source chips that made their specs and code available for users to examine were encased in impermeable plastic, creating a supply-chain problem. 计算机芯片传统上是“黑盒”组件,不透明的外壳遮蔽了内部电路。即使是以前那些公开了规格和代码供用户检查的开源芯片,也通常被封装在不透光的塑料中,这造成了供应链安全问题。

Users had to trust that nothing changed during the manufacturing stage of the chip, such as a backdoor component being added to it. Unlike conventional chips encased in opaque plastic, the Baochip is packaged so that infrared light can be shone through the back of the silicon, allowing the chip’s internal structures to be visually inspected. 用户必须信任芯片在制造过程中没有被动过手脚,例如被植入后门组件。与封装在不透明塑料中的传统芯片不同,Baochip 的封装方式允许红外光穿透硅片背面,从而实现对芯片内部结构的视觉检查。

Huang plans to demonstrate the technique at the conference, allowing attendees to inspect the chip under an infrared light. “I’ve been doing a bunch of stuff along the lines of trust and silicon and verification transparency” for years, Huang tells WIRED. “It’s all … this kind of story arc I’ve been on … to try and get a chip that we can trust down to the very core, down to the transistor … You can actually … see the RAM arrays … on the chip.” Huang 计划在大会上演示这一技术,让参会者在红外光下检查芯片。“多年来,我一直在做关于信任、硅片和验证透明度方面的工作,”Huang 告诉《连线》杂志,“这都是我一直在追求的故事线……试图制造出一款我们可以从核心、从晶体管层面去信任的芯片……你甚至可以亲眼看到芯片上的 RAM 阵列。”

Build-a-chip

芯片制造

Building a new chip is an expensive project that can cost millions of dollars for fabrication. But Huang got a big break three years ago when a company called Crossbar reached out to him. The company wanted to create a new open source and secure chip but didn’t know how to go about it. 制造新芯片是一个昂贵的项目,制造成本可能高达数百万美元。但三年前,一家名为 Crossbar 的公司联系了 Huang,这让他获得了重大突破。该公司想制造一款新的开源安全芯片,但不知道如何着手。

Huang agreed to assist on one condition: that they let him piggyback on their manufacturing run by placing his CPU on their chip wafer, allowing both designs to share the same manufacturing run rather than requiring Huang to fund a separate run. Huang 同意提供协助,但有一个条件:允许他“搭便车”,将他的 CPU 放在他们的晶圆上进行制造。这样两个设计可以共享同一批次生产,而无需 Huang 额外出资进行单独生产。

“They look at it as, if they put me on the chip, they get two products for the price of one,” Huang says. This kind of piggybacking is not unusual, he adds, though it’s not something the industry likes to discuss publicly. “他们认为,如果把我放进芯片里,他们就能以一份价格获得两款产品,”Huang 说。他补充道,这种“搭便车”的做法并不罕见,尽管业界并不喜欢公开讨论它。

The result is a Crossbar chip that includes both Crossbar’s microprocessor and Huang’s. The Baochip is essentially the same chip but with the Crossbar microprocessor disabled, since Huang doesn’t have the rights to distribute it. 最终产出的 Crossbar 芯片同时包含了 Crossbar 的微处理器和 Huang 的微处理器。Baochip 本质上是同一款芯片,只是禁用了 Crossbar 的微处理器,因为 Huang 没有分发后者的权利。

The Crossbar version of the chip uses a proprietary ARM core, whereas Huang’s version uses a RISC-V core whose implementation is open source. The RISC-V instruction set is also open and publicly documented. The two versions can use the same underlying infrastructure and peripherals while activating different CPU cores. Crossbar 版本的芯片使用专有的 ARM 核心,而 Huang 的版本使用实现开源的 RISC-V 核心。RISC-V 指令集也是开放且有公开文档的。这两个版本可以使用相同的底层基础设施和外设,同时激活不同的 CPU 核心。

There are some closed-source elements on Huang’s chip. Some low-level physical-design and manufacturing elements, including those associated with TSMC’s 22-nanometer fabrication process, are proprietary. “But … if you look on the spectrum of how open you can get things, this is … very, very far beyond any [other] security-oriented chip,” Huang says. Huang 的芯片上仍有一些闭源元素。一些底层的物理设计和制造要素,包括与台积电 22 纳米制造工艺相关的部分,仍是专有的。“但是……如果你从开放程度的维度来看,这已经远远、远远超过了任何其他以安全为导向的芯片,”Huang 说。

Badge beginnings

胸牌的起源

Past Defcon badges have used commercial off-the-shelf chips rather than custom-designed open source silicon. The idea for using the Baochip was sparked by a meeting late last year when Huang spoke with Defcon founder Jeff Moss about his progress in developing his open source chip. 过去的 Defcon 胸牌使用的是现成的商用芯片,而不是定制设计的开源硅片。使用 Baochip 的想法源于去年年底的一次会议,当时 Huang 与 Defcon 创始人 Jeff Moss 谈到了他在开发开源芯片方面的进展。

He told Moss that he planned to release it this summer through his company, Baochip. Moss realized the concept behind it matched perfectly with the conference theme this year—agency—which Defcon defines as the technologies we use and the choices we make that increase self-determination. And he and Huang realized it would be a great opportunity to help bootstrap the chip’s adoption. 他告诉 Moss,他计划今年夏天通过他的公司 Baochip 发布这款芯片。Moss 意识到其背后的理念与今年大会的主题“代理权”(Agency)完美契合——Defcon 将其定义为我们所使用的技术以及我们所做的增加自主权的选择。他和 Huang 都意识到,这将是帮助推动该芯片普及的绝佳机会。

Until now, the Baochip has been distributed only in a small development release; the 27,000 Defcon badges represent its first major distribution. Moss had one requirement for the badges. He wanted them to have a life beyond the conference and not be something that people would just throw in a drawer or a landfill after the event. He’s long been frustrated with the design and limitations of hardware security tokens and crypto wallets that, at the hardware level, can be cracked, so he… 到目前为止,Baochip 仅在小规模开发版本中发布过;而 27,000 个 Defcon 胸牌代表了它的首次大规模分发。Moss 对胸牌有一个要求:他希望它们在会议结束后还能有用途,而不是被人们扔进抽屉或垃圾填埋场。他长期以来一直对硬件安全令牌和加密钱包的设计及其局限性感到沮丧,因为它们在硬件层面是可以被破解的,所以他……