301 - Has anybody seen my keys?: A key-hierarchy strategy for rack-level security | RFD | Oxide
- Background and PurposeThere are many different types of secrets inside an oxide rack.
- At the base of the system we have the DeviceId and Alias keys stored on the RoT and used for platform identity and measurement signing for attestation respectively [RFD 36].
- These keys along with a 3rd RoT hosted keypair used for authenticating ephemeral Diffie-Hellman agreement provide the ability for sleds to form secure sprockets sessions for application layer messages [RFD 238].
Unverified
- Background and PurposeThere are many different types of secrets inside an oxide rack.
- At the base of the system we have the DeviceId and Alias keys stored on the RoT and used for platform identity and measurement signing for attestation respectively [RFD 36].
- These keys along with a 3rd RoT hosted keypair used for authenticating ephemeral Diffie-Hellman agreement provide the ability for sleds to form secure sprockets sessions for application layer messages [RFD 238].
Sources: Oxide