Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Galdralag-firmware — A cryptographic framework for Baochip-1x . | Kitploit
उपकरण/GitHubGitHub/supermagnum/galdralag-firmware
Embedded Systems SecurityEncryption/Decryption ToolsCryptographyHardware SecurityIdentity & Access Management (IAM)AuthenticationFirmware Analysis
GitHubsupermagnum/galdralag-firmware

Galdralag-firmware

A cryptographic framework for Baochip-1x .

रिपॉजिटरी देखें
3159 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Galdr — Galdralag Firmware

Open Invention Network

Open Invention Network member

This project is registered with the Open Invention Network (OIN). OIN is a defensive patent pool: members cross-license Linux-related patents so participants can ship and use open-source software with reduced patent exposure.

Status: Waiting for: https://github.com/betrusted-io/xous-core/pull/937


Table of contents

  • Open Invention Network
  • Security notice: Shamir host split
  • What this is
    • Galdra contact metadata
    • What this firmware is (and is not)
    • Signed firmware (Ed25519, boot0)
  • Is this AI slop?
  • Test results
  • Why Rust?
    • Memory Safety
    • System-level robustness (with limits)
    • Key material protection (project patterns)
    • Auditable by design
    • What Rust does not prevent
    • Setting up a virtual machine for evaluation
    • Risk assessment and deployment
  • Galdralag for dummies
    • What is GnuPG?
  • GnuPG / OpenPGP keys and Galdra keys
    • Metadata comparison (GnuPG vs Galdra)
  • Skipped and ignored tests
  • About the name
  • Documentation
  • Code map (function and module index)
  • Crate dependencies (upstream vs project)
  • Debugging instructions
  • docs/AUDIT_LOG.md
  • docs/BIOMETRIC_API.md
  • docs/HARDWARE_BRINGUP_TEST_PLAN.md
  • docs/KEY_LIFECYCLE.md
  • docs/RRAM_LAYOUT.md
  • docs/THREE_FACTOR_AUTH.md
  • docs/THREAT_MODEL.md
  • Glossary (plain language)
  • OpenPGP and GnuPG compatibility
  • Token session and key export
  • Web of Trust and Key Signing Parties
    • Obtaining your Galdralag fingerprint
    • What is the web of trust?
    • How it works
    • Key signing parties
    • Typical workflow at a key signing party
    • Fingerprints instead of full keys at the event
    • Keyservers
    • Using keyservers
    • Common keyservers
    • Best practices and caveats
    • Fulla (WoT registry server)
  • Standards vs. firmware-specific features
  • Shamir secret sharing and drive encryption
  • German eID and Governikus as a trust anchor for public keys
  • Standards process: Shamir and ephemeral key exchange
    • CESS (related open standard)
  • Sequoia PGP (if this repository is unresponsive)
  • Platform support (Linux only)
  • Build, install, and uninstall
    • Compile firmware
    • Flashing
    • Compile and install host tools (galdra, galdrad, galdra-gtk)
    • Run galdrad and the desktop GUI (galdra-gtk)
    • Uninstall host tools
  • Key capabilities
    • What makes this token unusual
    • Dual-hardware-key quorum (integrator pattern)
    • Cryptographic capabilities
      • Asymmetric / key agreement
      • Symmetric / AEAD
      • Key derivation / MAC / digest
      • Key management
    • Security properties
    • PIN policy
  • Post-quantum status
    • Implemented — unaudited crate (feature-gated)
    • Pending independent audit — not yet implemented
    • Will not be implemented
  • Zeroisation — hardware caveat
  • Workspace layout
  • Cryptographic dependency policy
  • Quick start
  • Known limitations / open work
    • CCID initial PIN: Dabao CCID vs legacy CDC
  • License

What this is

Firmware for Baochip-1x (Dabao evaluation board) devices running the Xous microkernel, built for riscv32imac-unknown-none-elf.

It's located here: https://www.baochip.com/

The device is a hardware security token in the same category as Nitrokey-class devices, with OpenPGP smartcard-class behaviour and an encrypted vault. The full hardware stack — RTL, schematics, bootloader, OS — is open source and auditable.

Hardware specification, boot model, requirement tables, and ComboHash/PKE usage are documented in Supermagnum/Baochip-1x-firmware. The Dabao evaluation board (KiCad, schematics, switches, pinout) is baochip/dabao. To enter bootloader mode for flashing, press SW2 to toggle it (see that repo's schematic). Architecture notes for this repository: docs/ARCHITECTURE.md.

Galdra contact metadata

टूल डाउनलोड करें