Live data from Hacker News

Securing a SoC is Not Easy

pandoralive.info

21–30 of 71 posts

Re: Securing a SoC is Not Easy

#21

High end SoC vendors generally don't care about you until you're buying millions of devices. If you can't find it on Digikey/Mouser/etc you're probably not going to get your hands on these parts without an in with one of the big name suppliers or the SoC vendor itself. However, in the case where you are shopping for millions of devices - say you're looking for the centerpiece of a new smartphone, its not unusual for…

That's not always the case. It depends how hungry they are. I was involved in a project that was clearly not going to require millions of devices. We were a small startup (though with some big partners). Texas Instruments really wanted to get their SoC into this segment though and we got a lot of their attention + pre-production samples + technical support. If this is an SoC looking for customers (like this was) and you can get the ear of the marketing team and/or have the right partners things will work out.

There are a lot of other electronic parts that are like that. If you get to talk and have a relationship with the right people you can get samples and support. Otherwise it can be virtually un-obtainium if it's not in Digikey's inventory. It's always been like that...

Re: Securing a SoC is Not Easy

#22
post #20
post #19

Earlier quoted context omitted.

Yes, would be happy to talk with your colleague and point him to the right contacts. I am at the San Diego headquarters.

If you don't mind, contact me through the form on Pandoralive ( http://pandoralive.info/?page_id=2 ) and I'll get in touch with you personally. Not sure if it's not too late for this particular device, but it's for sure not the last project of that kind so it wouldn't hurt to start establishing a relationship. :)

Done.

Re: Securing a SoC is Not Easy

#23

The situation for hobbyists getting SoCs is terrible - I've got a MiiPC at home that won't be getting much use because Marvell won't release any documentation on it without an NDA

NDAs are firmly integrated in the embedded industry. If you could get your hands on any other SoC, you would need to sign an NDA as well. For example Tegra documentation needs an NDA too.

Freescale and TI tend to be good about providing heaps of documentation without requiring any NDA.

Unfortunately, they're pretty alone in that regard.

Re: Securing a SoC is Not Easy

#24
This is, I believe, the only thing that has kept Intel in the game. Had someone had some foresight to go "all in" with the open source bit they could retake the old IBM PC spot (I'm talking about the one the PC in 1981 took away from CP/M machines, not the current spot). People who build appliances won't care but people who build computers will.

Re: Securing a SoC is Not Easy

#25
post #21

High end SoC vendors generally don't care about you until you're buying millions of devices. If you can't find it on Digikey/Mouser/etc you're probably not going to get your hands on these parts without an in with one of the big name suppliers or the SoC vendor itself. However, in the case where you are shopping for millions of devices - say you're looking for the centerpiece of a new smartphone, its not unusual for…

That's not always the case. It depends how hungry they are. I was involved in a project that was clearly not going to require millions of devices. We were a small startup (though with some big partners). Texas Instruments really wanted to get their SoC into this segment though and we got a lot of their attention + pre-production samples + technical support. If this is an SoC looking for customers (like this was) and…

Yes, Texas Instruments does that, I had the same experience (were we involved in the same project?). They do it if they are strategically interested in a certain market segment. Your project might look like a demo to them — worth investing some time and effort into.

Unfortunately, I'd say they are the exception. Good luck even getting someone at Broadcom or Qualcomm to speak to you. If your projected volumes are not (convincingly) into at least hundreds of thousands, you will get a simple "no", if you even manage to get an answer at all.

Re: Securing a SoC is Not Easy

#26
post #10
post #8

Earlier quoted context omitted.

So what is the recommended approach ? (sorry if the link you shared answers the question, i have not checked it yet)

The link, and indeed the whole blog, is worth reading. However, it doesn't directly answer the question. Bunnie suggests dealing with Chinese brokers who can source availability of 'cut tape', remnants from large production runs of the chip. It doesn't address consistency and reliable supply issues over a longer period of time but does allow for procurement of relatively small quantities of parts. Bunnie also suggest…

A major risk in dealing with unofficial brokers instead of going through distributors is a good chance of getting devices that were scrapped in production test due to malfunction or failing on performance parameters.

We have had several customers with issues sourcing this way and not realizing their devices are malfunctioning.

Re: Securing a SoC is Not Easy

#27
Could anyone familiar with the project reveal what kind of volumes are we talking about? E.g. nvidia's web page says that the minimum is 100,000 units.

It kinda makes sense not to sell these in small quantities because the SoC manufacturer would either end up getting lots of support requests or they would get a bad reputation for ignoring support. The reason is that unlike in the x86 world where there's some kind of a "standard" (derived from the IBM PC), ARM SoCs don't have any kind of consistent ecosystem where the motherboard components, firmware, etc would be specified. Every ARM SoC boots in a different manner, they might have separate bootloaders and there's a whole lot of SoC specific code in the Linux kernel.

Of course, the SoC manufacturer might be able to release documentation about the chip, but that kind of documentation might not exist (in a neat package that can actually be released and not e.g. an intranet wiki), it might contain sensitive IP (lawyers would have to get involved) or it might be written in a foreign language (and translating technical documentation from Chinese or Korean is not cheap either).

For the industry to mature and move forward, a common standard for SoCs would be a very welcome development.

Disclosure: I work as a SW engineer in a SoC company but I have no connection to the sales department and don't really know how this works in practice.

Re: Securing a SoC is Not Easy

#28
All sorts of parts can be surprisingly hard to find. I've been working on a radio product where the 16-way channel selector switch had to be specially ordered from China, while everything else came from Digikey.

Re: Securing a SoC is Not Easy

#29
post #27

Could anyone familiar with the project reveal what kind of volumes are we talking about? E.g. nvidia's web page says that the minimum is 100,000 units. It kinda makes sense not to sell these in small quantities because the SoC manufacturer would either end up getting lots of support requests or they would get a bad reputation for ignoring support. The reason is that unlike in the x86 world where there's some kind of…

This is a small project, and the first production runs would probably only be in the thousands of units.

Re: Securing a SoC is Not Easy

#30
post #27

Could anyone familiar with the project reveal what kind of volumes are we talking about? E.g. nvidia's web page says that the minimum is 100,000 units. It kinda makes sense not to sell these in small quantities because the SoC manufacturer would either end up getting lots of support requests or they would get a bad reputation for ignoring support. The reason is that unlike in the x86 world where there's some kind of…

I've been a backer/supporter/follower of the Pandora project since the very early days. What I have to say is not official - but to answer your question the impression that I have is that the volume is literally in the 10k - 20k. The reason is of course economy - this is a hardware startup, and the funding is not nearly at the levels to support 100k quantities.

This is a real shame in the SoC market right now - so many great products could be being made if only the chip mfr's were paying attention to the little guys. Its why companies like ACME Systems (http://www.acmesystems.it/) are working hard on providing SoC's and SoM's to the little guys - for a fair price - but its also why they have a fixed-price policy (no matter what quantity: the same price.) This has the advantage (for the hardware developers) of having access to the chips in small quantities, but it eats the margins when the quantities get larger (>10k), because the price will be the same.

This is an area where a new startup could really come along and eat everyones' lunch. Ignoring the little guys is going to hurt the Samsung and Nvidia's of this market, but I suppose they know that already and its why they price/set policy that will exclude newcomers to the scene ..

Post reply on HN