5-Intel TDX技术解析-杜凡.pdf

编号:624524 PDF 11页 820.64KB 下载积分:VIP专享
下载报告请您先登录!

5-Intel TDX技术解析-杜凡.pdf

1、机密计算之Intel TDX 技术解析IntelFan DuCloud Software ArchitectIntel Confidential2MKTME Multi Key TMEiMC.MKTME(AES-XTS)DRAMCPUCacheCipher TextPlain TextSoftwareKey IndexKey MaterialEncrypt Mode0TME1EncryptN-1No encryptPage TableVAPAKey idx Repurpose MSB physical address as key id Assign key with VA/PA mappin

2、g in page table Introduce new ISA PCONFIG to configure key ICX 64 keys,SPR 128 keysKey idxPFNProtPTE EntryInitialized by OS page fault handlerInitialized by PCONFIGIntel Confidential3Preparation Virtualization BasicsVMX Non-Root ModeVCPU0VCPU1VCPU NVMX Root ModeHost state AreaGuest state AreaVM Exec

3、ution CtrlCPU0CPU1CPU MVMCSExtended Page Table(EPT)Ring0:Guest KernelRing3:Guest OSGuest Physical AddressRing0:Host KVM ModuleRing3:QemuHost Physical MemoryIntel Confidential4Design goal of TDXTrust Domain Extensions(TDX)extends Virtual Machines Extensions(VMX)and Multi-Key Total Memory Encryption(M

4、KTME)to build kind of virtual machine called Trusted Domain(TD).The TD CPU state and memory are protected against from BIOS,host OS,device and any other firmware unless explicitly shared by TD.Intel Confidential5TDX Trust Domain eXtensionKey IndexKey MaterialEncrypt Mode0TME1EncryptN-1No encryptPart

5、ition MKTME key into shared key and private key.Introduce SEAM mode(SEcure Arbitration Mode)Limit private key usage Setup VM private mapping in secure EPT Intercept ISAs caused VM_EXIT to VMM Protect VM CPU stateShared KeysPrivate KeysIntel Confidential6TDX Modes TransitionsVMXONVMXOFFDefaultHost VM

6、MLegacy VMTD VMTDX ModuleVM EntryVM ExitVM EntryVM ExitOut of VMXVMX RootVMX Non-RootSEAM ModeNon-SEAM ModeMKTME Private KeyMKTME Shared KeyMKTME Shared KeySEAMCALLSEAMRETIntel Confidential7TDX Migration ArchitectureIntel Confidential8TDX C

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(5-Intel TDX技术解析-杜凡.pdf)为本站 (Flechazo) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠