资源与支持

SiFive 博客

来自 RISC-V 专家的最新洞察与深度技术解析

September 03, 2020

Randomness is Secure with SiFive Shield HCA

Building a secure foundation using the concept of randomness seems, on the surface, counter-intuitive.

As an aspect of entropy, randomness enables the generation of cryptographic methods to protect data, chips, and systems. By harnessing the nature of randomness as the basis of a secure system, it is possible to enhance the security of computer systems and protect vital information.

In July, SiFive introduced the SiFive Shield hardware cryptographic accelerator (HCA), as part of the improvements contained in the SiFive 20G1 release. The SiFive Shield HCA block consists of the necessary elements to accelerate cryptography to securely boot an SoC, protect communications, and restrict access to the debug interface.

I’m pleased to share with you that the SiFive HCA IP block includes a 100% digital true random number generator (TRNG) that has successfully passed a conformance evaluation against the stringent NIST SP-800-90B recommendation for entropy sources used for random bit generation.

The SiFive HCA TRNG is a fully-digital IP block that offers customization options for the entropy source, including customization of the entropy rate. SiFive’s selected independent partner, Penumbra Security, Inc. (Penumbra) is a NVLAP-accredited Cryptographic and Security Testing laboratory under the Cryptographic Module Validation Program (CMVP) at National Institute of Standards and Technology (NIST).

Happily, Penumbra asserts that SiFive’s method of customizing the entropy rate is effective, and demonstrated targeted entropy rates between 64.9% entropy and 92.4% entropy with the predicted entropy rates aligning with the actual entropy rates. Once integrated, the TRNG can be evaluated and certified against NIST SP-800-90C standard since through an additional SP-800-90A conditioning step enabled via SiFive software library that leverages the SiFive HCA hardware SHA/AES.

The SiFive HCA block can be added into SiFive RISC-V processor cores, alongside other SiFive Shield components such as SiFive WorldGuard. SiFive WorldGuard enables true multi-domain security with multiple hardware enforced domains available for securely processing data across the whole SoC, even in multi-core designs with many primary bus controllers. SiFive Shield is portable and scalable with broad process technology support to ensure consistency over time.

The SiFive 20G1 release with SiFive HCA block is available now. You can read more about the SiFive 20G1 release in our blog, here.

James Prior
James Prior
Senior Director of Product Marketing Communications

Read more Insights from the RISC-V Experts

P570 Gen 3:系统视角
最新文章
P570 Gen 3:系统视角
然而,CPU 的需求横跨性能、功耗和成本等多个维度。在某些细分市场中,需要在不同的功耗与成本约束下实现性能提升。基于这类 CPU 的系统需要可信赖的产品路线图,才能切实交付新的系统能力。尽管部分供应商已退出“低端市场”,SiFive 仍坚持在整条性能曲线上持续创新。本次发布的 P570 Gen 3 Performance IP,旨在为中低端、具备 Linux 能力的系统提供显著的性价比与能效比提升。
SiFive Performance™ P570 Gen 3 深度解析:面向下一代消费级与商用应用的高性能能效设计
最新文章
SiFive Performance™ P570 Gen 3 深度解析:面向下一代消费级与商用应用的高性能能效设计
SiFive 的核心是 RISC-V,这是 SiFive 创始人在公司成立 5 年前发明的指令集架构 (ISA)。SiFive 正持续演进基于 RISC-V 的 IP 基础模块,重新定义并推动各类计算平台的普及化发展。在技术领域,演进并非一串随机变化的时间线,而是一系列精心规划、环环相扣的里程碑。每一步演进都会创造一系列新的环境条件,从而推动下一次更复杂的跨越成为必然。要赢得这场竞赛,关键在于具备适应变化的灵活性与持续创新能力,而这两点正是 SiFive 与 RISC-V 的核心价值观所在。
全力投入:开启增长新篇章
最新文章
全力投入:开启增长新篇章
我们自信地宣布公司发展历程中最重要的里程碑之一:完成 4 亿美元 的融资。本轮融资由 Atreides Management 领投,其他顶级投资机构\*包括 Apollo Global Management、NVIDIA(英伟达)、Point72 Turion 和 T. Rowe Price Investment Management, Inc.,以及现有投资者 Prosperity7 Ventures 和 Sutter Hill Ventures 参投。此次融资使公司估值达到 36.5 亿美元,并将加速 SiFive 的 RISC-V CPU 及 AI IP 解决方案推向数据中心和 AI 基础设施市场的核心地带。