TCG DICE specs versus Open Dice Profile

121 views
Skip to first unread message

Sanjeev Verma

unread,
Sep 1, 2022, 1:41:00 PM9/1/22
to open-profi...@googlegroups.com
Dear All,

I see that there is a TCG DICE profile that allows for flexible proprietary implementations. The open Dice profile has a very clear definition of DICE flow and implementation steps. I am just trying to understand the current status. -- Is there any understanding in the Industry regarding going with the Open Dice profile implementation instead of going forward with flexible TCG DICE implementation? 

Thanks,

best regards,

Sanjeev

Darren Krahn

unread,
Sep 1, 2022, 2:57:40 PM9/1/22
to Sanjeev Verma, open-profi...@googlegroups.com
Hi Sanjeev,

You're absolutely right that the TCG DICE specs offer a lot of flexibility, and that the Open Profile narrows this significantly (by design). The challenge with the flexibility is that it's difficult for implementers to know exactly what to build and in practice they need to make a lot of important design decisions. This profile is intended to offer one way of doing DICE where many of these decisions have been thought through and many of the subtle details have been ironed out, e.g. certificate consistency. It's not, however, intended to be an industry standard. Implementers should build what works best for their use case and we hope this profile is helpful, even if only as a point of reference. :)

Cheers,
Darren

--
You received this message because you are subscribed to the Google Groups "Open Profile for DICE" group.
To unsubscribe from this group and stop receiving emails from it, send an email to open-profile-for...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/open-profile-for-dice/CAAO7ukS6G-Fz%3DnxBXFyrzaQvunCtYsf3wgQqNrRF-xzv%3DPmBQg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Sanjeev Verma

unread,
Sep 1, 2022, 4:02:37 PM9/1/22
to Darren Krahn, open-profi...@googlegroups.com
Hello Darren,

Thank you for the clarification. I agree with you. I was trying to see if this is a de facto standard in the industry. I see that Open Titan profile is also now aligned with the Open Dice profile.
Sometimes major players in the industry agree on a certain way of doing things without going through the formal standardization process.

I agree that there ha to be some agreement on certificate in order for compatibility--means that BMC can attest any Silicon RoT without modifying its code irrespective of Silicon RoT vendor.
What is market acceptance of this approach?

best regards,

Sanjeev

Darren Krahn

unread,
Sep 2, 2022, 3:46:27 PM9/2/22
to Sanjeev Verma, open-profi...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages