Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Grab it
Explore a cutting-edge approach to securing TPM2 NVRAM data using Intel's TXT and tboot extensions for kernel signature verification in this 33-minute conference talk. Delve into the design and progress of a solution that aims to restrict access to TPM2-stored data exclusively to kernels signed by authorized entities while maintaining robustness during kernel upgrades and downgrades. Compare this innovative approach with existing solutions utilizing traditional TXT and UEFI Secure Boot, understanding their limitations in terms of protection and usability. Gain insights into the proposed solution, open issues, current status, and participate in a Q&A session covering topics such as kernel rollback and authorities.
Securing TPM Secrets with TXT and Kernel Signatures