Baochip

@baochip.com

Baochip makes open-source hardware.

Here's a nicely written article that discusses some of the new opportunities unlocked in security by open source hardware: cambridgeanalytica.org/digital-curi... We're looking forward to learning what flaws the DEFCON community discovers, and working with them to improve the state of the art!

The hardware hacker who built a chip you can literally see through—and Defcon just handed 27,000 to hackers

Andrew Bunnie Huang created a see-through security chip for Defcon 34 badges. 27,000 hackers now have one designed to be deliberately broken open.

cambridgeanalytica.org

Baochip is proud to be an inaugural member of the Pavona consortium. It's a strong step towards making secure, open source silicon broadly available. We look forward to vigorously advocating for the interests of small, independent contributors like ourselves. Source code at github.com/pavona/pavona

GitHub - pavona/pavona: A library of modular, tapeout-proven, and secure-by-default open silicon blocks

A library of modular, tapeout-proven, and secure-by-default open silicon blocks - pavona/pavona

github.com

Production tester for the dabao is ready! 100% of boards run through a test where every I/O is toggled, both buttons are pressed, serial ports tickled, and an initial OS image is loaded. Voltages and currents are also checked. The test checks for errors in soldering, and/or faulty components.

Here's what a socket looks like for chip scale packages. Each one is custom made for a given chip package. A couple samples of the 0.4mm pitch Baochip CSP devices are laid out on the lower rim of the socket for size reference.

Bild

Behold the graveyard of Baochips! Security testing is hard, after the chips are locked the only recourse is to desolder and replace them when a test goes wrong or an attack sensor is tripped. On the upside, I'm getting really good at reworking CSPs.

Bild

Woo hoo! just in time: tape & reel packaged Dabao for #39c3. They will be at the #fail0verflow assembly with @bunnie.org . Also come see our talk on Day 2 23:00 in Room 1: "Xous: A Pure-Rust Rethink of the Embedded Operating System", where bunnie & xobs will co-present on Xous running on Baochip!

Bild

It's nice to be able to simulate your constant-time code and prove to yourself that you got it right. Pictured is a simulation of AES chaffing, where fake and real data are computed in a random order. The timing of fake->real and real->fake has to be identical in order to mask power side channels.

Bild

Backside IR image of the chip! The Baochip-1x is packaged specifically to enable you to verify that you've got the correct chip, and not a fake or a substitute part (see bunnie.org/iris for how). The final chip will have part numbering that overlaps the memory array on the lower third of the chip.

Bild

CHIIIIIIPS!!! 12" wafer of CSP bumped chips, hot off the line (solder balls are face-up in this photo, with a couple die already removed for testing).

Bild