3 ms·
Agreed. One benefit of the SFI-based approach over typical approaches that leverage hardware like MPUs or this firewall is that we can have arbitrarily many pri
by bkettle 3y ago
Agreed. One benefit of the SFI-based approach over typical approaches that leverage hardware like MPUs or this firewall is that we can have arbitrarily many privilege domains. For the security key we only have three (Trusted, USB, and FIDO2 lib) but there is nothing stopping us from adding more to get finer-grained privilege separation with each module having a smaller set of permissions. It’s possible to build multiple domains on top of these hardware mechanisms, but adds reconfiguration complexity at every context switch that we are able to avoid (at the cost of general runtime overhead). It would definitely be interesting to compare the two approaches.
Another approach adds hardware specifically for this kind of sandboxing: a paper from earlier this year [1] implements an extension to x86 that adds hardware support for Wasm-style SFI. It could be interesting to see how this can apply to the embedded context where resources are more limited.
One nice thing about embedded stuff like this, though, is that we are dealing with human time scales and fairly simple operations—-there was a lot of room for slowdown without becoming unreasonable.
1: https://dl.acm.org/doi/pdf/10.1145/3582016.3582023 https://dl.acm.org/doi/pdf/10.1145/3582016.3582023