AI & TechBigTech CompaniesCybersecurityNewswireTechnology

Defcon Badges Hide an Open-Source Security Key Chip

▼ Summary

– Defcon 2024 badges, created by hardware hacker Andrew “bunnie” Huang, feature an open source chip called the Baochip-1x, designed to advance security and transparency in computing.
– The chip’s core module is removable and can be repurposed as a hardware security token after the conference.
– Huang published the Baochip’s source code, including its operating system, firmware, processor core, and cryptographic engines, on GitHub for public inspection.
– Unlike conventional opaque chips, the Baochip is packaged to allow infrared light through the silicon, enabling visual inspection of its internal structures.
– Huang piggybacked his CPU design on a manufacturing run by the company Crossbar, sharing costs and allowing both designs to be produced together.

For years, attendees of the annual Defcon hacker conference have come home with more than just fresh intel on software flaws and exploitation techniques. They also carry away an elaborately engineered conference badge, often a miniature electronic marvel stuffed with cryptographic riddles, hidden surprises, and even the delicate inner workings of a mechanical watch.

Traditionally, each year’s badge designer aims to outdo every previous version, dazzling a crowd that is notoriously tough to impress. This year, however, the spotlight shifts away from the badge’s outward design. The real headline is the hardware tucked inside.

For this year’s event, Defcon enlisted legendary hardware hacker Andrew “bunnie” Huang to craft the badges, which are being unveiled here for the first time. His creation includes an innovative open source chip, designed by Huang himself, with ambitions that go far beyond the conference floor. The goal is to push forward the state of security, transparency, and trustworthiness in modern computing.

The chip is not merely a badge component. Its core module detaches and can live on after the conference as a standalone hardware security token, giving the badge a meaningful second life.

Named the Baochip-1x, this “mostly” open source microcontroller took three years to develop and represents Huang’s long-held ambition to build a chip whose security can be genuinely verified. The source code for the operating system, firmware, processor core, cryptographic engines, and input-output system has been published on GitHub, making every layer open for public inspection and reuse.

What truly sets the Baochip apart is its packaging. It is designed so researchers can peer into the silicon itself and cross-check the physical hardware against the published design. This removes the need to blindly trust that the manufactured chip matches the designers’ intentions.

Traditional computer chips are black boxes, sealed in opaque casings that hide their circuitry. Even earlier open source chips, which made their specifications and code available, were still encased in impenetrable plastic. That created a supply-chain dilemma: users had to take it on faith that nothing was altered during manufacturing, such as a backdoor being surreptitiously added.

The Baochip breaks from this convention. Its packaging allows infrared light to pass through the back of the silicon, enabling a direct visual inspection of the chip’s internal architecture. Huang plans to demonstrate this at the conference, letting attendees view the chip firsthand under infrared illumination.

“I’ve been doing a bunch of stuff along the lines of trust and silicon and verification transparency” for years, Huang told WIRED. “It’s all … this kind of story arc I’ve been on … to try and get a chip that we can trust down to the very core, down to the transistor … You can actually … see the RAM arrays … on the chip.”

A Unique Manufacturing Opportunity

Building a new chip from scratch is a costly endeavor, often running into the millions for fabrication alone. Huang’s breakthrough came three years ago when a company called Crossbar approached him. They wanted to develop a new secure, open source chip but lacked the know-how. Huang agreed to help, on one condition: he would piggyback his CPU onto their manufacturing wafer. This arrangement allowed both designs to share a single production run, sparing Huang the enormous expense of funding his own.

“They look at it as, if they put me on the chip, they get two products for the price of one,” Huang says. While this kind of piggybacking is not uncommon, he notes that it is not something the industry tends to discuss openly.

(Source: Wired)

Topics

open source hardware 95% chip security 93% supply chain trust 90% silicon verification 89% defcon conference 88% conference badges 86% hardware hacking 84% microcontroller design 82% transparency in computing 81% infrared inspection 80%
Show More