Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Galdralag-firmware — A cryptographic framework for Baochip-1x . | Kitploit
أدوات/GitHubGitHub/supermagnum/galdralag-firmware
Embedded Systems SecurityEncryption/Decryption ToolsCryptographyHardware SecurityIdentity & Access Management (IAM)AuthenticationFirmware Analysis
GitHubsupermagnum/galdralag-firmware

Galdralag-firmware

A cryptographic framework for Baochip-1x .

عرض المستودع
314منذ 8 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Galdr — Galdralag Firmware

Open Invention Network

Open Invention Network member

This project is registered with the Open Invention Network (OIN). OIN is a defensive patent pool: members cross-license Linux-related patents so participants can ship and use open-source software with reduced patent exposure.

Status: Waiting for: https://github.com/betrusted-io/xous-core/pull/937


Table of contents

  • Open Invention Network
  • Security notice: Shamir host split
  • What this is
    • Galdra contact metadata
    • What this firmware is (and is not)
    • Signed firmware (Ed25519, boot0)
  • Is this AI slop?
  • Test results
  • Why Rust?
    • Memory Safety
    • System-level robustness (with limits)
    • Key material protection (project patterns)
    • Auditable by design
    • What Rust does not prevent
    • Setting up a virtual machine for evaluation
    • Risk assessment and deployment
  • Galdralag for dummies
    • What is GnuPG?
  • GnuPG / OpenPGP keys and Galdra keys
    • Metadata comparison (GnuPG vs Galdra)
  • Skipped and ignored tests
  • About the name
  • Documentation
  • Code map (function and module index)
  • Crate dependencies (upstream vs project)
  • Debugging instructions
  • docs/AUDIT_LOG.md
  • docs/BIOMETRIC_API.md
  • docs/HARDWARE_BRINGUP_TEST_PLAN.md
  • docs/KEY_LIFECYCLE.md
  • docs/RRAM_LAYOUT.md
  • docs/THREE_FACTOR_AUTH.md
  • docs/THREAT_MODEL.md
  • Glossary (plain language)
  • OpenPGP and GnuPG compatibility
  • Token session and key export
  • Web of Trust and Key Signing Parties
    • Obtaining your Galdralag fingerprint
    • What is the web of trust?
    • How it works
    • Key signing parties
    • Typical workflow at a key signing party
    • Fingerprints instead of full keys at the event
    • Keyservers
    • Using keyservers
    • Common keyservers
    • Best practices and caveats
    • Fulla (WoT registry server)
  • Standards vs. firmware-specific features
  • Shamir secret sharing and drive encryption
  • German eID and Governikus as a trust anchor for public keys
  • Standards process: Shamir and ephemeral key exchange
    • CESS (related open standard)
  • Sequoia PGP (if this repository is unresponsive)
  • Platform support (Linux only)
  • Build, install, and uninstall
    • Compile firmware
    • Flashing
    • Compile and install host tools (galdra, galdrad, galdra-gtk)
    • Run galdrad and the desktop GUI (galdra-gtk)
    • Uninstall host tools
  • Key capabilities
    • What makes this token unusual
    • Dual-hardware-key quorum (integrator pattern)
    • Cryptographic capabilities
      • Asymmetric / key agreement
      • Symmetric / AEAD
      • Key derivation / MAC / digest
      • Key management
    • Security properties
    • PIN policy
  • Post-quantum status
    • Implemented — unaudited crate (feature-gated)
    • Pending independent audit — not yet implemented
    • Will not be implemented
  • Zeroisation — hardware caveat
  • Workspace layout
  • Cryptographic dependency policy
  • Quick start
  • Known limitations / open work
    • CCID initial PIN: Dabao CCID vs legacy CDC
  • License

What this is

Firmware for Baochip-1x (Dabao evaluation board) devices running the Xous microkernel, built for riscv32imac-unknown-none-elf.

It's located here: https://www.baochip.com/

The device is a hardware security token in the same category as Nitrokey-class devices, with OpenPGP smartcard-class behaviour and an encrypted vault. The full hardware stack — RTL, schematics, bootloader, OS — is open source and auditable.

Hardware specification, boot model, requirement tables, and ComboHash/PKE usage are documented in Supermagnum/Baochip-1x-firmware. The Dabao evaluation board (KiCad, schematics, switches, pinout) is baochip/dabao. To enter bootloader mode for flashing, press SW2 to toggle it (see that repo's schematic). Architecture notes for this repository: docs/ARCHITECTURE.md.

Galdra contact metadata

تنزيل الأداة