[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-devel] Virtualization videos from Platform Security Summit 2019



Xen, OpenXT, QubesOS and embedded developers may be interested in these 
videos.  

The first (IBM ppc Ultravisor with extended Q&A) is related to past discussions 
of minimal L0 Xen in firmware, similar to HP/Bromium nesting-optimized 
hypervisor.  The second is related to kexec and TrenchBoot, which (video TBD) 
was demoed booting Xen with AMD SKINIT DRTM on PC Engines $150 APU2 with TPM 
2.0.  The third describes a custom AMD Jaguar-derived SoC with a precursor to 
AMD's PSP, running a minimal version of Hyper-V called Nanovisor.  The fourth 
describes changes to Windows and x86 firmware/hardware for virtualization-based 
security.

Rich


Protected Execution Facility: We present the Protected Execution Facility ― an 
architecture modification for IBM Linux and OpenPower Linux servers ― along 
with the associated firmware, the Protected Execution Ultravisor which provides 
additional security to virtual machines ― called secure virtual machines 
(SVMs). The Protected Execution Facility concurrently supports both normal VMs 
and SVMs.
https://www.platformsecuritysummit.com/2019/speaker/hunt/


LinuxBoot progress: boot anything from Linux: LinuxBoot replaces traditionally 
closed source firmware (e.g. UEFI) with an open, auditable, and measurable 
Linux kernel and initramfs. We’ll present an overview of LinuxBoot, its part in 
the boot integrity story, and talk about newly gained abilities to boot VMware, 
Xen, and Windows from Linux, and future plans.
https://www.platformsecuritysummit.com/2019/speaker/koch/


Guarding Against Physical Attacks: The Xbox One Story: ... describe the Xbox 
security design goals and why it needs to guard against hardware attacks, 
followed by descriptions of the hardware and software architecture to keep the 
Xbox secure. This includes details about the custom SoC we built with AMD and 
how we addressed the fact that all data read from flash, the hard drive, and 
even DRAM cannot be trusted. We will also discuss the corresponding software 
changes we made to keep the system and the games secure.
https://www.platformsecuritysummit.com/2019/speaker/chen


Advancing Windows Security: ... the OS security engineering team at Microsoft 
has built a strategy to address new and challenging attacks. This talk will 
walk attendees through Windows current and future security strategy and the 
engineering challenges with scaling across new devices, form factors, and 
threat models ...
https://www.platformsecuritysummit.com/2019/speaker/weston/



_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxx
https://lists.xenproject.org/mailman/listinfo/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.