Second, while it's true that we're (obviously?) not entirely satisfied with the LPC55, we have worked around the vulnerabilities we have found -- and the alternatives that we have found aren't better. In particular: there appears to be no alternative that is at once robust, mature, secure, and entirely open. And even in the RISC-V ecosystem, there is a disconcerting trend towards proprietary boot ROMs (!!). We definitely welcome alternatives though, so please prove us wrong on that front! (That said: any alternative will be too late for our first product; we will have the LPC55 in our system for at least the foreseeable future.)
In terms of the BigCo's having "opened" their solutions, they haven't really (sadly). OpenTitan -- which we were really bullish about! -- only existed as an FPGA during the time we were trying to build on it. We actually wanted to make a go of making a secure FPGA -- but the problem is harder and the ecosystem is more proprietary than with secure microcontrollers. There are (or were) "plans" to make an ASIC, but we were asked to pony up $500K to join the lowRISC Foundation to find out what those plans were. (!!) To be blunt: that's not open -- it's open-washing. (I hope OpenTitan has seen or will see the error of its ways and opened up an ASIC roadmap -- it's an important effort and we would like to see it succeed.)
As for the other BigCo's, of the ones that I know about, they are either not using an RoT (!) or are using one that's strictly proprietary (i.e., no idea) or they are using the (wait for it...) LPC55.
So, yeah. Big sigh. tl;dr: We would welcome something better; we need to live with the LPC55; we would love RISC-V to not repeat a bunch of proprietary mistakes; we would love OpenTitan to be ActuallyOpenTitan.
Kind of unrelated here, but wanted to mention Precursor [1]. They just shipped, it's still an early product but... something works.
In the interest of disclosure, I'm actually in a position to start a secure open-source MCU project/company, but it looks like a terrible dead end.
I don't think we'll ever know. It is kind of amazing how secretive chip makers are despite the absolutely massive moat they enjoy. Not only is there a fabrication barrier to entry approaching the size of a small nation's GDP, but there is a maze of intellectual property laws backed by supranational leg breakers. And still they operate as if none of that existed and only trade secrets provide them any measure of competitive edge. Now imagine how bad it would be if the US military hadn't put multisource requirements in place...
I am very much looking forward to the day that their BS argument for secrecy might actually make some sense, because that'll be around the time that it becomes practical for businesses operating out of home garages to fabricate their own designs and start eating NXP's lunch.
Unlikely that will ever be cleared up since the IP vendors are very precious about their stuff
Here is a great video by Duncan explaining the whole processes in detail: https://youtu.be/HwsTRThChn0
All the components are open source too. You can read more about it here: https://doc.coreboot.org/security/vboot/index.html
As for the security chip, all current Chromebooks ship with a CR50. This is a Google designed chip. The boot rom is closed source unfortunately, but it essentially just verifies and jumps to RW. You can find the RW code here if anyone is curious: https://source.chromium.org/chromiumos/chromiumos/codesearch...
The security chip gives us TPM2 functionality and some ChromeOS specific features like CCD: https://chromium.googlesource.com/chromiumos/platform/ec/+/c...
You should be able to use vboot with a different TPM. Reach out if you want to chat!