1 / 15
Securing Secure Boot on Xen
Ross Lagerwall Software Engineer, Citrix Systems
Presentation licensed CC-By-SA-4.0
Securing Secure Boot on Xen Ross Lagerwall Software Engineer, - - PowerPoint PPT Presentation
Securing Secure Boot on Xen Ross Lagerwall Software Engineer, Citrix Systems 1 / 15 Presentation licensed CC-By-SA-4.0 Why Secure Boot? How can we prevent running malware at boot? With Secure Boot! What if the machine is a VM in
1 / 15
Presentation licensed CC-By-SA-4.0
2
3
Operating system Firmware Hardware Extensible Firmware Interface
Images: Tiancocore (https://github.com/tianocore/edk2/blob/master/MdeModulePkg/Logo/Logo.bmp) UEFI (https://en.wikipedia.org/wiki/Unified_Extensible_Firmware_Interface)
4
5
6
7
8
See Securing secure boot with System Management Mode, Paolo Bonzini, KVM Forum 2015 for more details.
9
10
11
12
store
Guest (n) OS OVMF
SetVariable() return Memory
Hypervisor (dom0) varstored (n)
map SetVariable() handler_set_variable() return ioport write(port, pagenr) XenVariable module dispatch
XAPI DB
13
14
15