|
|
|
|
|
by e12e
4698 days ago
|
|
> our approach does give you assurance that someone with physical access can't easily snapshot your VM memory. But how do you know the VM (or rather the hypervisor for the vm) is running on physical hardware, and not in a hypervisor? I can't think of a way you could be certain of this remotely? Perhaps you could be on-site for the boot-up, and then rely on the fact that snapshotting is very hard -- but it sounds rather fragile... Still very interesting project! I've been thinking a bit on "running inside the L/1/2/3 chache"-lately - but I hadn't thought about the particular idea that you could treat RAM as "external" -- assuming you could guarantee that you're always in cache. |
|
Today, that attestation process relies on a TPM and a signed certificate chain baked in by the TPM manufacturer. This is standard stuff out of the Trusted Computing Group.
One more thing to add, this isn't just a personal side project. We're a company and have a beta product deployed to early adopters.