4 ms·
Ginseng modifies the kernel and protects sensitive parts by using the CPU's trusted execution environment[1] which has a higher privilege level than the kernel
by CodeArtisan 8y ago
Ginseng modifies the kernel and protects sensitive parts by using the CPU's trusted execution environment[1] which has a higher privilege level than the kernel. From the paper
We now describe Ginseng’s runtime protection against such
accesses. The runtime protection heavily relies on GService,
a passive, app-independent piece of software in the Secure
world. GService ensures the code integrity, data confidentiality
and control-flow integrity (CFI). It does so only for sensitive
functions to minimize overhead. It also modifies the kernel
at three points, when booting, when modifying the kernel
page table, and when handling an exception. Since we do
not trust the OS, the kernel may overwrite the modifications.
However, when any of these modifications is disabled, the
kernel will infinitely trigger data aborts trying to modify readonly
memory, thus ensuring sensitive data are always safe.
I would have look at the source code to find more but the github repository has been deleted.
[1]
https://en.wikipedia.org/wiki/Trusted_execution_environment https://en.wikipedia.org/wiki/Trusted_execution_environment
https://en.wikipedia.org/wiki/ARM_architecture#Security_extensions https://en.wikipedia.org/wiki/ARM_architecture#Security_exte...
https://en.wikipedia.org/wiki/Software_Guard_Extensions https://en.wikipedia.org/wiki/Software_Guard_Extensions
- dmitrygr 8y agoNo amount of modifications in the kernel will make this safe. What if I load a module that fixes my IRQ handlers? Or do they forbid modules? What if I find an exploit in the kernel? Or did they somehow make a 100% exploit-free kernel? This sort of thing is exactly why TEE exists. It cannot be done half in userspace half in TEE
- CodeArtisan 8y agoFrom what i have understood, Ginseng sets sensitive memory regions to only be accessed by the TEE then unmap these regions from the kernel memory space. If your kernel module try to read/write/map these regions, a memory violation exception is raised and then handled by the TEE.
- dmitrygr 8y agoThat literally means that every time you take an interrupt, you also take an extra fault into the hypervisor (since your CPU cannot read the vector, because it has been protected). In that case, forget any ideas of speed. The whole point of hardware assisted virtualization was to prevent that situation. These guys suggest going decades back in terms of performance. No thanks.