Главная
Study mode:
on
1
Intro
2
Intel Trusted Execution Technology (TXT)
3
Open Cloud Integrity Technology (CIT) Intel's remote attestation solution
4
UEFI secure boot UEFI BIOS's Verified boot component
5
Threats!
6
Goals! To maintain integrity properly
7
Trusted Platform Module (TPM)
8
Shim and Grub Shim
9
Assumptions
10
TUX Architecture
11
Integrity Manager
12
Kernel update using TUX
13
Remote attestation with TUX
14
Trusted Secure boot (TS-Boot) Combination of UEFI secure boot, Shim, and Cores Grub
15
PCR-Verification
16
TPM measurements
17
Experiment
18
Demo
19
Discussion
20
Conclusion Integrity changes when update is conducted and thus it should be property managed along with updates
Description:
Explore a conference talk on TUX (Trust Update for Linux Kernel), a proposed solution to maintain up-to-date integrity of the pre-boot environment in Linux systems. Learn about the challenges posed by frequent security updates and how TUX addresses them by consolidating kernel repositories with Intel's Open CIT. Discover how TUX deploys kernels with updated integrity values as signatures and implements a secure bootloader for integrity verification during boot. Gain insights into the architecture of TUX, including its Integrity Manager, kernel update process, and remote attestation capabilities. Understand the concept of Trusted Secure boot (TS-Boot) and its integration with UEFI secure boot, Shim, and Cores Grub. Examine the use of TPM measurements and PCR-Verification in maintaining system trust. Watch a demo of TUX in action and engage in a discussion on the importance of managing integrity changes alongside system updates.

Updating Linux with TUX: Trust Update for Linux Kernel

Linux Foundation
Add to list
0:00 / 0:00