Главная
Study mode:
on
1
Introduction
2
Outline
3
Open Source
4
New Stuff
5
Protected Execution Facility
6
In transit
7
SVM
8
Base Principles
9
Overview
10
Linux KVM
11
Normal and Secure VM
12
Limitations
13
Layout
14
CSM blob
15
Boot changes
16
Ultravisor
17
Kernel Changes
18
Hardware Changes
19
Summary
20
IBM Secure Hardware
21
Questions
Description:
Explore the Protected Execution Facility, an architectural modification for IBM Linux and OpenPower Linux servers, in this 42-minute conference talk by Guerney D. H. Hunt from IBM Research. Delve into the challenges of keeping applications and containers secure against attacks and compromised components in both traditional and cloud computing environments. Learn about the associated firmware, the Protected Execution Ultravisor, which enhances security for virtual machines, creating secure virtual machines (SVMs). Discover how this facility supports both normal VMs and SVMs concurrently, and understand the protections and restrictions applied to SVMs. Compare and contrast vendor approaches to providing security in potentially compromised hypervisor or OS scenarios. Gain insights into topics such as Open Source, Linux KVM, boot changes, kernel modifications, and hardware alterations necessary for implementing this security technology.

Protected Execution Facility for Secure Virtual Machines

Linux Foundation
Add to list