4 ms·
At PrivateCore, we keep key material (and the entire Linux stack) pinned in the CPU cache, then encrypt main memory. This would thwart physical memory extractio
by sweis 13y ago
At PrivateCore, we keep key material (and the entire Linux stack) pinned in the CPU cache, then encrypt main memory. This would thwart physical memory extraction attacks, like cold booting, Fireware, Thunderbolt, NV-DIMMs, bus analyzers, malicious RAM, etc.
Note, that doesn't help if someone compromises the software stack and extracts memory contents logically. A compromised kernel running in cache can just decrypt memory contents.
- dobbsbob 13y agoPrivExec does something similar with ephemeral keys http://www.onarlioglu.com/privexec/ http://www.onarlioglu.com/privexec/
- codys 13y agoI was not aware pinning memory in the CPU cache was even possible. Is this done via some Linux interface? Or directly by using some hardware feature of the CPU? In any case, it sounds like a very interesting way of maintaining greater protection for secrets.