verified_boot: Add presentation

Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Żygowski <michal.zygowski@3mdeb.com>
This commit is contained in:
Michał Kopeć
2024-06-13 12:09:27 +02:00
committed by Michał Żygowski
parent f9a1600c1a
commit 4087ca5743
4 changed files with 329 additions and 0 deletions
Binary file not shown.

After

Width:  |  Height:  |  Size: 136 KiB

+37
View File
@@ -0,0 +1,37 @@
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!-- Created with Inkscape (http://www.inkscape.org/) -->
<svg width="67.775795mm" height="14.390643mm" viewBox="0 0 67.775795 14.390643" version="1.1" id="svg1" xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" xmlns="http://www.w3.org/2000/svg" xmlns:svg="http://www.w3.org/2000/svg">
<sodipodi:namedview id="namedview1" pagecolor="#ffffff" bordercolor="#000000" borderopacity="0.25" inkscape:showpageshadow="2" inkscape:pageopacity="0.0" inkscape:pagecheckerboard="0" inkscape:deskcolor="#d1d1d1" inkscape:document-units="mm"/>
<defs id="defs1">
<linearGradient id="a" x1="3.2172999" y1="15" x2="44.7812" y2="15" gradientUnits="userSpaceOnUse">
<stop offset="0" stop-color="#d93025" id="stop1"/>
<stop offset="1" stop-color="#ea4335" id="stop2"/>
</linearGradient>
<linearGradient id="b" x1="20.721901" y1="47.6791" x2="41.503899" y2="11.6837" gradientUnits="userSpaceOnUse">
<stop offset="0" stop-color="#fcc934" id="stop3"/>
<stop offset="1" stop-color="#fbbc04" id="stop4"/>
</linearGradient>
<linearGradient id="c" x1="26.598101" y1="46.501499" x2="5.8161001" y2="10.506" gradientUnits="userSpaceOnUse">
<stop offset="0" stop-color="#1e8e3e" id="stop5"/>
<stop offset="1" stop-color="#34a853" id="stop6"/>
</linearGradient>
</defs>
<g inkscape:label="Livello 1" inkscape:groupmode="layer" id="layer1" transform="translate(-127.52917,-127.79374)">
<path fill="#5f6368" d="m 189.71962,134.80547 a 4.0613541,4.0613541 0 0 1 -4.06136,4.06135 4.0613541,4.0613541 0 0 1 -4.06135,-4.06135 4.0613541,4.0613541 0 0 1 4.06135,-4.06136 4.0613541,4.0613541 0 0 1 4.06136,4.06136 z m -4.03408,3.12459 a 3.127375,3.0241875 89.5 0 0 2.99681,-3.15362 3.127375,3.0241875 89.5 0 0 -3.05136,-3.10086 3.127375,3.0241875 89.5 0 0 -2.99681,3.15362 3.127375,3.0241875 89.5 0 0 3.05136,3.10086 z" id="path9" inkscape:export-filename="path9.svg" inkscape:export-xdpi="96" inkscape:export-ydpi="96" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 195.30497,136.34005 v 0.61648 q -0.82814,2.46062 -3.50573,1.76212 -1.30439,-0.34131 -1.86531,-1.88648 a 0.07408333,0.07408333 0 0 1 0.0423,-0.0952 l 0.7673,-0.30427 q 0.0714,-0.0291 0.10054,0.0423 0.66939,1.64041 2.22514,1.39964 c 0.85196,-0.12964 1.44727,-0.92339 1.07421,-1.75948 -0.39423,-0.88635 -1.93939,-1.12448 -2.74637,-1.52664 -1.77007,-0.88636 -1.4949,-3.11944 0.28046,-3.67771 q 2.16429,-0.67998 3.34168,1.29117 a 0.08995833,0.09260417 62.5 0 1 -0.0423,0.12964 l -0.73819,0.33073 a 0.08202083,0.08466667 63.5 0 1 -0.10848,-0.0344 q -0.72231,-1.24618 -2.05581,-0.84402 c -0.75671,0.23019 -1.20121,1.1483 -0.50535,1.72244 0.62177,0.51329 1.49489,0.64029 2.29129,1.00013 q 1.2065,0.54768 1.44462,1.83356 z" id="path10" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 152.04031,133.97732 q 1.1721,-1.21708 2.61408,-0.53975 0.98425,0.45773 1.016,1.7489 0.037,1.53458 0.008,3.43958 -0.003,0.0741 -0.0741,0.0741 l -0.83079,-0.003 q -0.0661,0 -0.0688,-0.0661 -0.045,-1.39965 0.005,-2.68287 c 0.0423,-1.06098 -0.2831,-2.032 -1.59014,-1.80975 -0.80434,0.13493 -1.16946,0.94456 -1.16417,1.70127 q 0.005,1.41287 0.005,2.74637 0,0.10848 -0.11112,0.11113 l -0.7329,0.005 q -0.14023,0 -0.14023,-0.14023 v -7.52475 q 0,-0.13229 0.12965,-0.12965 l 0.75671,0.0185 q 0.11112,0.003 0.11112,0.11377 l -0.0476,2.8919 q -0.003,0.16404 0.11377,0.045 z" id="path11" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 147.54768,137.94342 q 1.06627,0.0503 1.56898,-0.84931 0.0741,-0.13229 0.21167,-0.0714 l 0.60854,0.26723 q 0.14023,0.0609 0.0661,0.19315 -0.85989,1.55839 -2.7305,1.34144 c -1.90764,-0.21961 -2.82575,-2.28071 -2.12725,-3.9423 0.87313,-2.07697 3.73063,-2.31775 4.84188,-0.27516 q 0.0608,0.11112 -0.0556,0.15875 l -0.67204,0.29104 a 0.15875,0.15875 0 0 1 -0.20373,-0.0741 q -0.4154,-0.8308 -1.31763,-0.87313 c -2.29394,-0.11112 -2.43946,3.72533 -0.1905,3.83381 z" id="path15" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 162.97363,138.88254 a 2.8495625,2.7807708 89.4 0 1 -2.81046,-2.82028 2.8495625,2.7807708 89.4 0 1 2.75077,-2.87853 2.8495625,2.7807708 89.4 0 1 2.81046,2.82027 2.8495625,2.7807708 89.4 0 1 -2.75077,2.87854 z m -0.0238,-0.9206 a 1.9314583,1.7727083 89.9 0 0 1.76935,-1.93455 1.9314583,1.7727083 89.9 0 0 -1.77607,-1.92836 1.9314583,1.7727083 89.9 0 0 -1.76935,1.93455 1.9314583,1.7727083 89.9 0 0 1.77607,1.92836 z" id="path16" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 167.68512,133.97997 c 0.33867,-0.28575 0.64558,-0.57415 1.09008,-0.68792 q 1.17211,-0.29633 1.92881,0.48419 a 0.69585416,0.68262499 13.8 0 1 0.15875,0.25664 q 0.0159,0.0503 0.0609,0.0847 0.10054,0.0767 0.17198,-0.0265 0.57944,-0.82021 1.54252,-0.87048 1.93939,-0.0952 2.12989,1.87061 0.082,0.83608 0.0238,3.4925 -0.003,0.11641 -0.12171,0.11641 h -0.80433 q -0.11907,0 -0.11642,-0.11906 0.0106,-1.50813 -0.005,-3.19352 c -0.0159,-1.99496 -2.45004,-1.47902 -2.49238,0.12171 q -0.0503,1.87854 -0.0238,3.05329 0.003,0.13758 -0.13494,0.13758 l -0.78316,-0.003 q -0.1323,0 -0.12965,-0.1323 0.0265,-1.4896 -0.005,-3.15647 c -0.0397,-2.02142 -2.42623,-1.49755 -2.48709,0.0661 q -0.0688,1.67746 -0.0265,3.09298 0.003,0.13494 -0.12965,0.13229 h -0.80169 a 0.1031875,0.10054167 0 0 1 -0.10318,-0.10054 l -0.003,-5.06942 q 0,-0.17991 0.17992,-0.17991 l 0.64293,0.003 q 0.17198,0.003 0.15346,0.17463 l -0.037,0.38629 q -0.0212,0.18521 0.12171,0.0662 z" id="path17" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 176.65714,136.39297 q 0.16669,0.96572 0.84931,1.31762 1.40494,0.72231 2.35744,-0.59531 0.0397,-0.0529 0.0979,-0.0291 l 0.70643,0.30427 q 0.0662,0.0291 0.0344,0.0952 c -0.49742,1.00013 -1.47638,1.4605 -2.59027,1.35203 -2.70669,-0.26194 -3.39196,-4.0349 -1.05304,-5.32871 0.98689,-0.54504 2.44475,-0.35984 3.19352,0.54239 q 0.71437,0.86254 0.63235,2.02142 -0.0106,0.16933 -0.18256,0.16933 l -3.91319,-0.008 q -0.15875,0 -0.13229,0.15875 z m 0.16404,-0.99748 2.96863,-0.0106 a 0.03439583,0.03439583 0 0 0 0.0344,-0.0344 v -0.0238 a 1.2012083,1.4896041 89.8 0 0 -1.49489,-1.19591 h -0.0582 a 1.2012083,1.4896041 89.8 0 0 -1.48431,1.2065 v 0.0238 a 0.03439583,0.03439583 0 0 0 0.0344,0.0344 z" id="path18" style="stroke-width:0.264583"/>
<path fill="#5f6368" d="m 158.0146,134.08051 q 0.66146,-1.06892 2.10344,-0.73554 a 0.079375,0.079375 0 0 1 0.0556,0.10847 l -0.29634,0.74348 a 0.1349375,0.1349375 0 0 1 -0.15345,0.082 c -1.15888,-0.254 -1.85473,0.57415 -1.81769,1.68805 q 0.0476,1.44462 0.003,2.63525 -0.005,0.10054 -0.10583,0.10054 l -0.79639,-0.005 a 0.1349375,0.13229166 0 0 1 -0.13494,-0.1323 v -5.08793 q 0,-0.127 0.12964,-0.127 l 0.73555,0.003 a 0.14022916,0.13758333 4.3 0 1 0.13758,0.15611 q -0.037,0.2831 0.0106,0.54768 0.0344,0.17728 0.12965,0.0238 z" id="path19" style="stroke-width:0.264583"/>
<g id="g19" transform="matrix(0.30224767,0,0,0.29980472,127.52917,127.79376)" style="display:inline">
<circle cx="24" cy="23.994699" r="12" style="fill:#ffffff" id="circle6"/>
<path d="M 3.2154,36 A 24,24 0 1 0 12,3.2154 24,24 0 0 0 3.2154,36 Z M 34.3923,18 A 12,12 0 1 1 18,13.6077 12,12 0 0 1 34.3923,18 Z" style="fill:none" id="path6-1"/>
<path d="M 24,12 H 44.7812 A 23.9939,23.9939 0 0 0 3.2173,12.0029 L 13.6079,30 13.6172,29.9976 A 11.9852,11.9852 0 0 1 24,12 Z" style="fill:url(#a)" id="path7-2"/>
<circle cx="24" cy="24" r="9.5" style="fill:#1a73e8" id="circle7"/>
<path d="M 34.3913,30.0029 24.0007,48 A 23.994,23.994 0 0 0 44.78,12.0031 H 23.9989 l -0.0025,0.0093 a 11.985,11.985 0 0 1 10.3949,17.9905 z" style="fill:url(#b)" id="path8-0"/>
<path d="M 13.6086,30.0031 3.218,12.006 A 23.994,23.994 0 0 0 24.0025,48 L 34.3931,30.0029 34.3864,29.9961 a 11.9852,11.9852 0 0 1 -20.7778,0.007 z" style="fill:url(#c)" id="path9-4"/>
</g>
</g>
</svg>

After

Width:  |  Height:  |  Size: 7.7 KiB

+50
View File
@@ -0,0 +1,50 @@
<!--
SPDX-FileCopyrightText: 2024 3mdeb <contact@3mdeb.com>
SPDX-License-Identifier: Apache-2.0
-->
<!doctype html>
<html>
<head>
<title>Dasharo Verified Boot</title>
<meta charset="utf-8" />
<script>
classTitle = "Dasharo Verified Boot";
courseAuthor = "Michał Kopeć";
</script>
<link
rel="stylesheet"
type="text/css"
href="/remark-templates/dasharo-presentation-template/css/slides.css"
/>
<style></style>
</head>
<body>
<script src="/remark-templates/dasharo-presentation-template/js/remark.js"></script>
<script src="/remark-templates/dasharo-presentation-template/js/jquery.js"></script>
<script>
var slideshow = remark.create({
sourceUrl: "vpub_0xb_verified_boot.md",
countIncrementalSlides: false,
});
slideshow.on("afterShowSlide", function (slide) {
if ($(".bottomBar")[0]) {
$(".bottomBar").remove();
} else {
// Do something if class does not exist
}
$(".remark-slide-content").append(
"<div class='bottomBar'>" +
classTitle +
" <br> CC-SA-4.0 | " +
courseAuthor +
"</div>",
);
});
</script>
</body>
</html>
+242
View File
@@ -0,0 +1,242 @@
class: center, middle, intro
# Verified Boot and firmware updates
## How to do them securely and openly
.center[<img src="/remark-templates/dasharo-presentation-template/images/dasharo-sygnet-white.svg" width="150px" style="margin-left:-20px">]
???
<!--
SPDX-FileCopyrightText: 2024 3mdeb <contact@3mdeb.com>
SPDX-License-Identifier: CC-BY-SA-4.0
-->
---
# whoami
- Michał Kopeć
- Firmware Engineer at 3mdeb since 2021
- Develops Dasharo for laptops, network appliances and other platforms
- Uses Arch btw
---
# Agenda
- Verified Boot
- in Chrome
- in Dasharo
- Problem statement
- Boot Guard
- CBFS verification
- Secure firmware updates
---
# Verified boot
- Verified Boot: Cryptographic verification of the boot process to ensure only
code from a trusted source (e.g. device vendor) can run
- coreboot supports Vboot, Google's version of verified boot scheme
- Vboot has:
- A root of trust
- Verification of subsequent firmware stages
- Signatures and public tools for self-signing
- A special A/B update mechanism
- Support for re-ownership
- Dasharo uses Vboot
???
- Google created Vboot for chrome devices
- In Chrome, vboot is also used for OS and EC secure boot
- We use some subset of Vboot's capabilities
---
# Verified Boot in Chrome devices
.center.image-55[![](/img/vboot/cros.svg)]
- Write protection: WP# pin on the BIOS chip
- WP# pin is controlled by Cr50 security chip (newer devices) or physical
screw (older devices)
- Updates: An OS service handles the A/B update scheme
- One slot is updated, and when confirmed bootable, the other slot is updated
too
- Write protected portion of the flash is **not** updated, and serves as
recovery
- WP region contains the initial bootblock and verifies the A/B slots
- When both slots fail or recovery is manually requested (e.g. by keyboard
key), the firmware boots from the recovery partition
???
- Cr50 is a Google's TPM-like device, also known as Titan C
---
# Verified Boot in Dasharo
.center.image-20[![](/remark-templates/dasharo-presentation-template/images/dasharo-sygnet.svg)]
- Write protection is provided by chipset (typically, can be also SPI WP#)
- Optional feature, but enabled by default for most platforms
- Protects against software attacks
- Updates are handled by Dasharo Tools Suite
- Capsule Update and fwupd support is WIP
- Most updates also need to update the bootblock, so they require protection
to be disabled for updates - obviously suboptimal
- OS secure boot is handled by UEFI SB
???
- Firmware programs protected range registers in chipset, which ensures software
cannot write to flash
- Firmware is not physically write protected
- We find we need to update the recovery region because of:
- Firmware layout changes
- New features added to booblock
- Breaking Kconfig changes
- coreboot rebases
- Google is not affected by this because they:
- Generally do not add new features to firmware
- Use a fixed coreboot rev for each mainboard
---
# Problem
- How do we improve Dasharo verified boot while staying secure and without
taking control away from users?
- Security: A guarantee that only firmware from a trusted vendor is run
- Control: Ability to self-sign, to inspect and replace firmware components
- There are other verified boot schemes
---
# Intel Boot Guard
- The most widely known option
- Verifies and measures the initial bootblock
- Ensures FW authenticity using keys fused to the chipset
- Supports firmware verification and measurement
- Different profiles with different features enabled
- Verified, Measured and Enforced knobs
- Verified boot is always enabled in all profiles
- Ties a platform to a specific firmware vendor, forever
???
- Intel specific, AMD has a different but comparable secure boot scheme
Verifies the initial bootblock, rest is up to BIOS (Vboot)
- fused: programmed into one-time programmable e-fuses inside the chipset
- Measurements are made in locality 3, so they can't be faked by malicious BIOS
- Profile 3: Verified and Measured with infinite time for remediation
- Profile 3 acts as root of trust for measurement, but not for verification
- On verification failure, the PCR0 measurements are always the same. This was
determined experimetally.
- so users can choose to use Dasharo firmware and get measured IBB, or flash
their own and lose measured IBB.
- might make sense for some small percentage for users
- does not help us a lot
---
# Boot Guard cons
- Requires more blobs in firmware
- Boot Guard ACM
- Fusing removes some owner control
- Profile 3 does not ensure initial boot block authenticity
- Only helps us establish a root of trust for measurement
- Other profiles take away owner control completely
???
- ACM - Authenticated Code Module. Hyper-privileged, Intel signed blob that
performs the actual BIOS verification and measurement, then hands off to the
BIOS reset vector.
---
# CBFS Verification
- A relatively new coreboot feature
- Cryptographically verifies components of the coreboot image
- According to documentation:
> This only makes sense if you use some
> out-of-band mechanism to guarantee the integrity of the bootblock
> itself, such as Intel Boot Guard or flash write-protection.
- Same applies to vboot's recovery region, which is ultimately trusted
- Depends on some other mechanism for signing (e.g. Boot Guard)
- Can effectively replace the portions of Vboot that Dasharo uses
???
- CBFS - coreboot's internal file system
---
# Firmware updates
- Chrome Vboot: A+B+RO
- A and B slots for updates, RO slot contains IBB and verification code
- Anti-rollback using TPM
- Vboot aware OS service manages slot updates
- Dasharo:
- Initial idea was to leave RO untouched and only update A/B slots
- In practice, most updates introduce breaking changes that require updating
the bootblock
- Dasharo Tools Suite handles updates, does the entire update in one operation
- So we don't use the A/B feature
- Capsule Updates may help here
---
# Other firmware update mechanisms
- Flashrom plugin in fwupd
- Updates the BIOS region only
- Is not Vboot aware
- UEFI Capsule Update
- Most widely used in proprietary UEFIs
- Can be made aware of which regions to update and which to preserve, verify
signatures, handle disabling flash protections
- WIP for Dasharo
???
- Capsule Updates are a requirement for Windows sticker certification
- Supported by Windows Update and fwupd
# Other firmware update mechanisms
- Intel BIOS Guard
- Hooks into the SMM flash update handler to call an ACM, which authorizes
flash writes
- Can bypass chipset flash protections and Top Swap (configurable with
MFIT/FIT/FITC in flash descriptor straps)
- Can also handle EC updates
- Proprietary feature with proprietary tooling
- Top Swap
- Redundant bootblock feature
- Configurable from 64KB up to 4M/8MB (maximum depending on CPU/SoC/chipset
family) in flash descriptor straps (MFIT/FITC/FIT)
- Potential integration with vboot?
???
- Top swap size is (barely?) enough to fit an entire Vboot RO partition
- e.g. have immutable, write-protected recovery that verifies the top swap block
and sets the top swap bit accordingly?
---
class: center, middle, intro
# Q&A