DEF CON 33 - How to secure unique ecosystem shipping 1 billion+ cores? - Adam Zabrocki, Marko Mitic

DEF CON 33 - How to secure unique ecosystem shipping 1 billion+ cores? - Adam Zabrocki, Marko Mitic

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 37:03

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Nvidia redesigned their processor security ecosystem using RISC-V to create a flexible, secure architecture that supports their diverse product range, from consumer GPUs to data center AI platforms 0:15.

Key Takeaways:
• Nvidia transitioned from their proprietary Falcon architecture to RISC-V to address scalability and security requirements across their billion-core ecosystem 3:01
• The Paragrine ecosystem implements hardware security features like pointer masking and control flow integrity through RISC-V extensions 14:37
• Nvidia uses formal verification with SPARK language for critical firmware components to ensure absence of runtime errors 25:56
• Their partition architecture creates isolated execution environments for mixed criticality applications on a single RISC-V controller 8:29

Security requires a holistic approach combining hardware and software co-design, with flexibility to adapt to evolving threats 35:17.

Sources:

  • 0:15 Overview of Nvidia's diverse product ecosystem
  • 3:01 Transition from Falcon to RISC-V architecture
  • 14:37 Hardware security extensions for RISC-V
  • 25:56 Formal verification using SPARK language
  • 35:17 Lessons learned and holistic security approach

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. I'm actually surprised there's so many people on Saturday relatively in the morning. So thank you everyone for coming to this talk in the Saturday morning. Um I'm delighted to be four time uh on the DevCon mainstream and have an opportunity to speak about how to secure and how actually Nvidia secure unique ecosystem shipping more than billion cores. However, are we even the right people to speak about such an important topic? I don't want to spend too much time here but who we are. Currently I'm working in Nvidia as um director of offensive security. My name is Adam Zabroski and I'm leading various offensive security research um efforts across entire company. I'm also involved in the risk 5 international when I'm uh serving as a vice chair of J extension group and I'm autho…