Skip to content

Questions of DICE Cert/Key generation model #1642

Answered by jhand2
yh36 asked this question in Q&A
Discussion options

You must be logged in to vote
  1. Here are a couple relevant sections from the layering spec:
    • [6.2.1] "At layers above the DICE HRoT layer, the CDI value received from the previous TCB component supplies a statistically unique value to the current TCB component."
    • [6.2.1] "The TCI value for any TCB component that includes firmware or software MUST include measurement of said firmware or software"

However, Caliptra DICE is rooted in ROM, which is considered the "Hardware" layer from this spec. These sections make explicit exceptions for Hardware.

The examples you cited in section 9 are examples of rooting DICE in Layer 0. But they are just examples (see figure 11 which is explicitly marked as an example). It is valid t…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by yh36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants