Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Galdralag-firmware — A cryptographic framework for Baochip-1x . | Kitploit
Herramientas/GitHubGitHub/supermagnum/galdralag-firmware
Embedded Systems SecurityEncryption/Decryption ToolsCryptographyHardware SecurityIdentity & Access Management (IAM)AuthenticationFirmware Analysis
GitHubsupermagnum/galdralag-firmware

Galdralag-firmware

A cryptographic framework for Baochip-1x .

Ver Repositorio
314hace 8 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Galdr — Galdralag Firmware

Open Invention Network

Open Invention Network member

This project is registered with the Open Invention Network (OIN). OIN is a defensive patent pool: members cross-license Linux-related patents so participants can ship and use open-source software with reduced patent exposure.

Status: Waiting for: https://github.com/betrusted-io/xous-core/pull/937


Table of contents

  • Open Invention Network
  • Security notice: Shamir host split
  • What this is
    • Galdra contact metadata
    • What this firmware is (and is not)
    • Signed firmware (Ed25519, boot0)
  • Is this AI slop?
  • Test results
  • Why Rust?
    • Memory Safety
    • System-level robustness (with limits)
    • Key material protection (project patterns)
    • Auditable by design
    • What Rust does not prevent
    • Setting up a virtual machine for evaluation
    • Risk assessment and deployment
  • Galdralag for dummies
    • What is GnuPG?
  • GnuPG / OpenPGP keys and Galdra keys
    • Metadata comparison (GnuPG vs Galdra)
  • Skipped and ignored tests
  • About the name
  • Documentation
  • Code map (function and module index)
  • Crate dependencies (upstream vs project)
  • Debugging instructions
  • docs/AUDIT_LOG.md
  • docs/BIOMETRIC_API.md
  • docs/HARDWARE_BRINGUP_TEST_PLAN.md
  • docs/KEY_LIFECYCLE.md
  • docs/RRAM_LAYOUT.md
  • docs/THREE_FACTOR_AUTH.md
  • docs/THREAT_MODEL.md
  • Glossary (plain language)
  • OpenPGP and GnuPG compatibility
  • Token session and key export
  • Web of Trust and Key Signing Parties
    • Obtaining your Galdralag fingerprint
    • What is the web of trust?
    • How it works
    • Key signing parties
    • Typical workflow at a key signing party
    • Fingerprints instead of full keys at the event
    • Keyservers
    • Using keyservers
    • Common keyservers
    • Best practices and caveats
    • Fulla (WoT registry server)
  • Standards vs. firmware-specific features
  • Shamir secret sharing and drive encryption
  • German eID and Governikus as a trust anchor for public keys
  • Standards process: Shamir and ephemeral key exchange
    • CESS (related open standard)
  • Sequoia PGP (if this repository is unresponsive)
  • Platform support (Linux only)
  • Build, install, and uninstall
    • Compile firmware
    • Flashing
    • Compile and install host tools (galdra, galdrad, galdra-gtk)
    • Run galdrad and the desktop GUI (galdra-gtk)
    • Uninstall host tools
  • Key capabilities
    • What makes this token unusual
    • Dual-hardware-key quorum (integrator pattern)
    • Cryptographic capabilities
      • Asymmetric / key agreement
      • Symmetric / AEAD
      • Key derivation / MAC / digest
      • Key management
    • Security properties
    • PIN policy
  • Post-quantum status
    • Implemented — unaudited crate (feature-gated)
    • Pending independent audit — not yet implemented
    • Will not be implemented
  • Zeroisation — hardware caveat
  • Workspace layout
  • Cryptographic dependency policy
  • Quick start
  • Known limitations / open work
    • CCID initial PIN: Dabao CCID vs legacy CDC
  • License

What this is

Firmware for Baochip-1x (Dabao evaluation board) devices running the Xous microkernel, built for riscv32imac-unknown-none-elf.

It's located here: https://www.baochip.com/

The device is a hardware security token in the same category as Nitrokey-class devices, with OpenPGP smartcard-class behaviour and an encrypted vault. The full hardware stack — RTL, schematics, bootloader, OS — is open source and auditable.

Hardware specification, boot model, requirement tables, and ComboHash/PKE usage are documented in Supermagnum/Baochip-1x-firmware. The Dabao evaluation board (KiCad, schematics, switches, pinout) is baochip/dabao. To enter bootloader mode for flashing, press SW2 to toggle it (see that repo's schematic). Architecture notes for this repository: docs/ARCHITECTURE.md.

Galdra contact metadata

Descargar herramienta