Open JohnTraverAmd opened 4 months ago
We trust SOC RT FW because SOC ROM is loading the SOC RT FW and is creating a chain of trust and thats the whole argument with Caliptra 1.0; I believe we have assumed/required to assume SOC RT FW is trusted.
Since its "secured", we should have it better available to meet CSP RAS requirements.
Caliptra Error Documentation Requires SOC to have reset ability of Caliptra. This ability must be limited in availability to SOC ROT since SOC ROT FW is not trusted to reset Caliptra independently.
Once we have exited trusted SOC immutable code, ability of SOC ROT to independently reset Caliptra at will, would enable an attack on the secrets of Caliptra by later SOC ROT FW.
Caliptra reset could be allowed by: