DICE
Full Title
Device Identifier Composition Engine
Context
DICE is designed to the absolute minimum root of trust for programmable devices. Although it can do some TPM-stuff, it's mostly the root-of-trust on which to build things like TPMs (which are themselves pretty complicated.)
Many/most CPUs now have DICE support, although for more powerful CPUs it tends to be hidden away
{https://trustedcomputinggroup.org/work-groups/dice-architectures/ DICE | Trusted Computing Group] - Modern cyber-attacks are often sophisticated and relentless in their continual efforts to seek out vulnerabilities in modern technology-based solutions. At the same time, new market segments like the Internet of Things (IoT), are driving innovative architectures and creating solutions with challenging power, security, resource, and other constraints.
- DICE: Device Identifier Composition Engine - Microsoft Research aka RIoT (Robust | Resilient | Recoverable – IoT)
- There's a new sort of DICE called a DICE Protection Environment that's being driven by Google that's closer to a mini-TPM. This will also be a TCG standard in a few weeks.