mirror of
https://github.com/Dasharo/presentations.git
synced 2026-06-13 19:16:14 -07:00
verified_boot: Add presentation
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com> Signed-off-by: Michał Żygowski <michal.zygowski@3mdeb.com>
This commit is contained in:
Binary file not shown.
|
After Width: | Height: | Size: 136 KiB |
@@ -0,0 +1,37 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
<svg width="67.775795mm" height="14.390643mm" viewBox="0 0 67.775795 14.390643" version="1.1" id="svg1" xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" xmlns="http://www.w3.org/2000/svg" xmlns:svg="http://www.w3.org/2000/svg">
|
||||
<sodipodi:namedview id="namedview1" pagecolor="#ffffff" bordercolor="#000000" borderopacity="0.25" inkscape:showpageshadow="2" inkscape:pageopacity="0.0" inkscape:pagecheckerboard="0" inkscape:deskcolor="#d1d1d1" inkscape:document-units="mm"/>
|
||||
<defs id="defs1">
|
||||
<linearGradient id="a" x1="3.2172999" y1="15" x2="44.7812" y2="15" gradientUnits="userSpaceOnUse">
|
||||
<stop offset="0" stop-color="#d93025" id="stop1"/>
|
||||
<stop offset="1" stop-color="#ea4335" id="stop2"/>
|
||||
</linearGradient>
|
||||
<linearGradient id="b" x1="20.721901" y1="47.6791" x2="41.503899" y2="11.6837" gradientUnits="userSpaceOnUse">
|
||||
<stop offset="0" stop-color="#fcc934" id="stop3"/>
|
||||
<stop offset="1" stop-color="#fbbc04" id="stop4"/>
|
||||
</linearGradient>
|
||||
<linearGradient id="c" x1="26.598101" y1="46.501499" x2="5.8161001" y2="10.506" gradientUnits="userSpaceOnUse">
|
||||
<stop offset="0" stop-color="#1e8e3e" id="stop5"/>
|
||||
<stop offset="1" stop-color="#34a853" id="stop6"/>
|
||||
</linearGradient>
|
||||
</defs>
|
||||
<g inkscape:label="Livello 1" inkscape:groupmode="layer" id="layer1" transform="translate(-127.52917,-127.79374)">
|
||||
<path fill="#5f6368" d="m 189.71962,134.80547 a 4.0613541,4.0613541 0 0 1 -4.06136,4.06135 4.0613541,4.0613541 0 0 1 -4.06135,-4.06135 4.0613541,4.0613541 0 0 1 4.06135,-4.06136 4.0613541,4.0613541 0 0 1 4.06136,4.06136 z m -4.03408,3.12459 a 3.127375,3.0241875 89.5 0 0 2.99681,-3.15362 3.127375,3.0241875 89.5 0 0 -3.05136,-3.10086 3.127375,3.0241875 89.5 0 0 -2.99681,3.15362 3.127375,3.0241875 89.5 0 0 3.05136,3.10086 z" id="path9" inkscape:export-filename="path9.svg" inkscape:export-xdpi="96" inkscape:export-ydpi="96" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 195.30497,136.34005 v 0.61648 q -0.82814,2.46062 -3.50573,1.76212 -1.30439,-0.34131 -1.86531,-1.88648 a 0.07408333,0.07408333 0 0 1 0.0423,-0.0952 l 0.7673,-0.30427 q 0.0714,-0.0291 0.10054,0.0423 0.66939,1.64041 2.22514,1.39964 c 0.85196,-0.12964 1.44727,-0.92339 1.07421,-1.75948 -0.39423,-0.88635 -1.93939,-1.12448 -2.74637,-1.52664 -1.77007,-0.88636 -1.4949,-3.11944 0.28046,-3.67771 q 2.16429,-0.67998 3.34168,1.29117 a 0.08995833,0.09260417 62.5 0 1 -0.0423,0.12964 l -0.73819,0.33073 a 0.08202083,0.08466667 63.5 0 1 -0.10848,-0.0344 q -0.72231,-1.24618 -2.05581,-0.84402 c -0.75671,0.23019 -1.20121,1.1483 -0.50535,1.72244 0.62177,0.51329 1.49489,0.64029 2.29129,1.00013 q 1.2065,0.54768 1.44462,1.83356 z" id="path10" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 152.04031,133.97732 q 1.1721,-1.21708 2.61408,-0.53975 0.98425,0.45773 1.016,1.7489 0.037,1.53458 0.008,3.43958 -0.003,0.0741 -0.0741,0.0741 l -0.83079,-0.003 q -0.0661,0 -0.0688,-0.0661 -0.045,-1.39965 0.005,-2.68287 c 0.0423,-1.06098 -0.2831,-2.032 -1.59014,-1.80975 -0.80434,0.13493 -1.16946,0.94456 -1.16417,1.70127 q 0.005,1.41287 0.005,2.74637 0,0.10848 -0.11112,0.11113 l -0.7329,0.005 q -0.14023,0 -0.14023,-0.14023 v -7.52475 q 0,-0.13229 0.12965,-0.12965 l 0.75671,0.0185 q 0.11112,0.003 0.11112,0.11377 l -0.0476,2.8919 q -0.003,0.16404 0.11377,0.045 z" id="path11" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 147.54768,137.94342 q 1.06627,0.0503 1.56898,-0.84931 0.0741,-0.13229 0.21167,-0.0714 l 0.60854,0.26723 q 0.14023,0.0609 0.0661,0.19315 -0.85989,1.55839 -2.7305,1.34144 c -1.90764,-0.21961 -2.82575,-2.28071 -2.12725,-3.9423 0.87313,-2.07697 3.73063,-2.31775 4.84188,-0.27516 q 0.0608,0.11112 -0.0556,0.15875 l -0.67204,0.29104 a 0.15875,0.15875 0 0 1 -0.20373,-0.0741 q -0.4154,-0.8308 -1.31763,-0.87313 c -2.29394,-0.11112 -2.43946,3.72533 -0.1905,3.83381 z" id="path15" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 162.97363,138.88254 a 2.8495625,2.7807708 89.4 0 1 -2.81046,-2.82028 2.8495625,2.7807708 89.4 0 1 2.75077,-2.87853 2.8495625,2.7807708 89.4 0 1 2.81046,2.82027 2.8495625,2.7807708 89.4 0 1 -2.75077,2.87854 z m -0.0238,-0.9206 a 1.9314583,1.7727083 89.9 0 0 1.76935,-1.93455 1.9314583,1.7727083 89.9 0 0 -1.77607,-1.92836 1.9314583,1.7727083 89.9 0 0 -1.76935,1.93455 1.9314583,1.7727083 89.9 0 0 1.77607,1.92836 z" id="path16" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 167.68512,133.97997 c 0.33867,-0.28575 0.64558,-0.57415 1.09008,-0.68792 q 1.17211,-0.29633 1.92881,0.48419 a 0.69585416,0.68262499 13.8 0 1 0.15875,0.25664 q 0.0159,0.0503 0.0609,0.0847 0.10054,0.0767 0.17198,-0.0265 0.57944,-0.82021 1.54252,-0.87048 1.93939,-0.0952 2.12989,1.87061 0.082,0.83608 0.0238,3.4925 -0.003,0.11641 -0.12171,0.11641 h -0.80433 q -0.11907,0 -0.11642,-0.11906 0.0106,-1.50813 -0.005,-3.19352 c -0.0159,-1.99496 -2.45004,-1.47902 -2.49238,0.12171 q -0.0503,1.87854 -0.0238,3.05329 0.003,0.13758 -0.13494,0.13758 l -0.78316,-0.003 q -0.1323,0 -0.12965,-0.1323 0.0265,-1.4896 -0.005,-3.15647 c -0.0397,-2.02142 -2.42623,-1.49755 -2.48709,0.0661 q -0.0688,1.67746 -0.0265,3.09298 0.003,0.13494 -0.12965,0.13229 h -0.80169 a 0.1031875,0.10054167 0 0 1 -0.10318,-0.10054 l -0.003,-5.06942 q 0,-0.17991 0.17992,-0.17991 l 0.64293,0.003 q 0.17198,0.003 0.15346,0.17463 l -0.037,0.38629 q -0.0212,0.18521 0.12171,0.0662 z" id="path17" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 176.65714,136.39297 q 0.16669,0.96572 0.84931,1.31762 1.40494,0.72231 2.35744,-0.59531 0.0397,-0.0529 0.0979,-0.0291 l 0.70643,0.30427 q 0.0662,0.0291 0.0344,0.0952 c -0.49742,1.00013 -1.47638,1.4605 -2.59027,1.35203 -2.70669,-0.26194 -3.39196,-4.0349 -1.05304,-5.32871 0.98689,-0.54504 2.44475,-0.35984 3.19352,0.54239 q 0.71437,0.86254 0.63235,2.02142 -0.0106,0.16933 -0.18256,0.16933 l -3.91319,-0.008 q -0.15875,0 -0.13229,0.15875 z m 0.16404,-0.99748 2.96863,-0.0106 a 0.03439583,0.03439583 0 0 0 0.0344,-0.0344 v -0.0238 a 1.2012083,1.4896041 89.8 0 0 -1.49489,-1.19591 h -0.0582 a 1.2012083,1.4896041 89.8 0 0 -1.48431,1.2065 v 0.0238 a 0.03439583,0.03439583 0 0 0 0.0344,0.0344 z" id="path18" style="stroke-width:0.264583"/>
|
||||
<path fill="#5f6368" d="m 158.0146,134.08051 q 0.66146,-1.06892 2.10344,-0.73554 a 0.079375,0.079375 0 0 1 0.0556,0.10847 l -0.29634,0.74348 a 0.1349375,0.1349375 0 0 1 -0.15345,0.082 c -1.15888,-0.254 -1.85473,0.57415 -1.81769,1.68805 q 0.0476,1.44462 0.003,2.63525 -0.005,0.10054 -0.10583,0.10054 l -0.79639,-0.005 a 0.1349375,0.13229166 0 0 1 -0.13494,-0.1323 v -5.08793 q 0,-0.127 0.12964,-0.127 l 0.73555,0.003 a 0.14022916,0.13758333 4.3 0 1 0.13758,0.15611 q -0.037,0.2831 0.0106,0.54768 0.0344,0.17728 0.12965,0.0238 z" id="path19" style="stroke-width:0.264583"/>
|
||||
<g id="g19" transform="matrix(0.30224767,0,0,0.29980472,127.52917,127.79376)" style="display:inline">
|
||||
<circle cx="24" cy="23.994699" r="12" style="fill:#ffffff" id="circle6"/>
|
||||
<path d="M 3.2154,36 A 24,24 0 1 0 12,3.2154 24,24 0 0 0 3.2154,36 Z M 34.3923,18 A 12,12 0 1 1 18,13.6077 12,12 0 0 1 34.3923,18 Z" style="fill:none" id="path6-1"/>
|
||||
<path d="M 24,12 H 44.7812 A 23.9939,23.9939 0 0 0 3.2173,12.0029 L 13.6079,30 13.6172,29.9976 A 11.9852,11.9852 0 0 1 24,12 Z" style="fill:url(#a)" id="path7-2"/>
|
||||
<circle cx="24" cy="24" r="9.5" style="fill:#1a73e8" id="circle7"/>
|
||||
<path d="M 34.3913,30.0029 24.0007,48 A 23.994,23.994 0 0 0 44.78,12.0031 H 23.9989 l -0.0025,0.0093 a 11.985,11.985 0 0 1 10.3949,17.9905 z" style="fill:url(#b)" id="path8-0"/>
|
||||
<path d="M 13.6086,30.0031 3.218,12.006 A 23.994,23.994 0 0 0 24.0025,48 L 34.3931,30.0029 34.3864,29.9961 a 11.9852,11.9852 0 0 1 -20.7778,0.007 z" style="fill:url(#c)" id="path9-4"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 7.7 KiB |
@@ -0,0 +1,50 @@
|
||||
<!--
|
||||
SPDX-FileCopyrightText: 2024 3mdeb <contact@3mdeb.com>
|
||||
|
||||
SPDX-License-Identifier: Apache-2.0
|
||||
-->
|
||||
|
||||
<!doctype html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Dasharo Verified Boot</title>
|
||||
<meta charset="utf-8" />
|
||||
<script>
|
||||
classTitle = "Dasharo Verified Boot";
|
||||
courseAuthor = "Michał Kopeć";
|
||||
</script>
|
||||
<link
|
||||
rel="stylesheet"
|
||||
type="text/css"
|
||||
href="/remark-templates/dasharo-presentation-template/css/slides.css"
|
||||
/>
|
||||
|
||||
<style></style>
|
||||
</head>
|
||||
<body>
|
||||
<script src="/remark-templates/dasharo-presentation-template/js/remark.js"></script>
|
||||
<script src="/remark-templates/dasharo-presentation-template/js/jquery.js"></script>
|
||||
<script>
|
||||
var slideshow = remark.create({
|
||||
sourceUrl: "vpub_0xb_verified_boot.md",
|
||||
countIncrementalSlides: false,
|
||||
});
|
||||
|
||||
slideshow.on("afterShowSlide", function (slide) {
|
||||
if ($(".bottomBar")[0]) {
|
||||
$(".bottomBar").remove();
|
||||
} else {
|
||||
// Do something if class does not exist
|
||||
}
|
||||
|
||||
$(".remark-slide-content").append(
|
||||
"<div class='bottomBar'>" +
|
||||
classTitle +
|
||||
" <br> CC-SA-4.0 | " +
|
||||
courseAuthor +
|
||||
"</div>",
|
||||
);
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,242 @@
|
||||
class: center, middle, intro
|
||||
|
||||
# Verified Boot and firmware updates
|
||||
|
||||
## How to do them securely and openly
|
||||
|
||||
.center[<img src="/remark-templates/dasharo-presentation-template/images/dasharo-sygnet-white.svg" width="150px" style="margin-left:-20px">]
|
||||
|
||||
???
|
||||
|
||||
<!--
|
||||
SPDX-FileCopyrightText: 2024 3mdeb <contact@3mdeb.com>
|
||||
|
||||
SPDX-License-Identifier: CC-BY-SA-4.0
|
||||
-->
|
||||
|
||||
---
|
||||
|
||||
# whoami
|
||||
|
||||
- Michał Kopeć
|
||||
- Firmware Engineer at 3mdeb since 2021
|
||||
- Develops Dasharo for laptops, network appliances and other platforms
|
||||
- Uses Arch btw
|
||||
|
||||
---
|
||||
|
||||
# Agenda
|
||||
|
||||
- Verified Boot
|
||||
- in Chrome
|
||||
- in Dasharo
|
||||
- Problem statement
|
||||
- Boot Guard
|
||||
- CBFS verification
|
||||
- Secure firmware updates
|
||||
|
||||
---
|
||||
|
||||
# Verified boot
|
||||
|
||||
- Verified Boot: Cryptographic verification of the boot process to ensure only
|
||||
code from a trusted source (e.g. device vendor) can run
|
||||
- coreboot supports Vboot, Google's version of verified boot scheme
|
||||
- Vboot has:
|
||||
- A root of trust
|
||||
- Verification of subsequent firmware stages
|
||||
- Signatures and public tools for self-signing
|
||||
- A special A/B update mechanism
|
||||
- Support for re-ownership
|
||||
- Dasharo uses Vboot
|
||||
|
||||
???
|
||||
|
||||
- Google created Vboot for chrome devices
|
||||
- In Chrome, vboot is also used for OS and EC secure boot
|
||||
- We use some subset of Vboot's capabilities
|
||||
|
||||
---
|
||||
|
||||
# Verified Boot in Chrome devices
|
||||
|
||||
.center.image-55[]
|
||||
|
||||
- Write protection: WP# pin on the BIOS chip
|
||||
- WP# pin is controlled by Cr50 security chip (newer devices) or physical
|
||||
screw (older devices)
|
||||
- Updates: An OS service handles the A/B update scheme
|
||||
- One slot is updated, and when confirmed bootable, the other slot is updated
|
||||
too
|
||||
- Write protected portion of the flash is **not** updated, and serves as
|
||||
recovery
|
||||
- WP region contains the initial bootblock and verifies the A/B slots
|
||||
- When both slots fail or recovery is manually requested (e.g. by keyboard
|
||||
key), the firmware boots from the recovery partition
|
||||
|
||||
???
|
||||
|
||||
- Cr50 is a Google's TPM-like device, also known as Titan C
|
||||
|
||||
---
|
||||
|
||||
# Verified Boot in Dasharo
|
||||
|
||||
.center.image-20[]
|
||||
|
||||
- Write protection is provided by chipset (typically, can be also SPI WP#)
|
||||
- Optional feature, but enabled by default for most platforms
|
||||
- Protects against software attacks
|
||||
- Updates are handled by Dasharo Tools Suite
|
||||
- Capsule Update and fwupd support is WIP
|
||||
- Most updates also need to update the bootblock, so they require protection
|
||||
to be disabled for updates - obviously suboptimal
|
||||
- OS secure boot is handled by UEFI SB
|
||||
|
||||
???
|
||||
|
||||
- Firmware programs protected range registers in chipset, which ensures software
|
||||
cannot write to flash
|
||||
- Firmware is not physically write protected
|
||||
- We find we need to update the recovery region because of:
|
||||
- Firmware layout changes
|
||||
- New features added to booblock
|
||||
- Breaking Kconfig changes
|
||||
- coreboot rebases
|
||||
- Google is not affected by this because they:
|
||||
- Generally do not add new features to firmware
|
||||
- Use a fixed coreboot rev for each mainboard
|
||||
|
||||
---
|
||||
|
||||
# Problem
|
||||
|
||||
- How do we improve Dasharo verified boot while staying secure and without
|
||||
taking control away from users?
|
||||
- Security: A guarantee that only firmware from a trusted vendor is run
|
||||
- Control: Ability to self-sign, to inspect and replace firmware components
|
||||
- There are other verified boot schemes
|
||||
|
||||
---
|
||||
|
||||
# Intel Boot Guard
|
||||
|
||||
- The most widely known option
|
||||
- Verifies and measures the initial bootblock
|
||||
- Ensures FW authenticity using keys fused to the chipset
|
||||
- Supports firmware verification and measurement
|
||||
- Different profiles with different features enabled
|
||||
- Verified, Measured and Enforced knobs
|
||||
- Verified boot is always enabled in all profiles
|
||||
- Ties a platform to a specific firmware vendor, forever
|
||||
|
||||
???
|
||||
|
||||
- Intel specific, AMD has a different but comparable secure boot scheme
|
||||
Verifies the initial bootblock, rest is up to BIOS (Vboot)
|
||||
- fused: programmed into one-time programmable e-fuses inside the chipset
|
||||
- Measurements are made in locality 3, so they can't be faked by malicious BIOS
|
||||
- Profile 3: Verified and Measured with infinite time for remediation
|
||||
- Profile 3 acts as root of trust for measurement, but not for verification
|
||||
- On verification failure, the PCR0 measurements are always the same. This was
|
||||
determined experimetally.
|
||||
- so users can choose to use Dasharo firmware and get measured IBB, or flash
|
||||
their own and lose measured IBB.
|
||||
- might make sense for some small percentage for users
|
||||
- does not help us a lot
|
||||
|
||||
---
|
||||
|
||||
# Boot Guard cons
|
||||
|
||||
- Requires more blobs in firmware
|
||||
- Boot Guard ACM
|
||||
- Fusing removes some owner control
|
||||
- Profile 3 does not ensure initial boot block authenticity
|
||||
- Only helps us establish a root of trust for measurement
|
||||
- Other profiles take away owner control completely
|
||||
|
||||
???
|
||||
|
||||
- ACM - Authenticated Code Module. Hyper-privileged, Intel signed blob that
|
||||
performs the actual BIOS verification and measurement, then hands off to the
|
||||
BIOS reset vector.
|
||||
|
||||
---
|
||||
|
||||
# CBFS Verification
|
||||
|
||||
- A relatively new coreboot feature
|
||||
- Cryptographically verifies components of the coreboot image
|
||||
- According to documentation:
|
||||
> This only makes sense if you use some
|
||||
> out-of-band mechanism to guarantee the integrity of the bootblock
|
||||
> itself, such as Intel Boot Guard or flash write-protection.
|
||||
- Same applies to vboot's recovery region, which is ultimately trusted
|
||||
- Depends on some other mechanism for signing (e.g. Boot Guard)
|
||||
- Can effectively replace the portions of Vboot that Dasharo uses
|
||||
|
||||
???
|
||||
|
||||
- CBFS - coreboot's internal file system
|
||||
|
||||
---
|
||||
|
||||
# Firmware updates
|
||||
|
||||
- Chrome Vboot: A+B+RO
|
||||
- A and B slots for updates, RO slot contains IBB and verification code
|
||||
- Anti-rollback using TPM
|
||||
- Vboot aware OS service manages slot updates
|
||||
- Dasharo:
|
||||
- Initial idea was to leave RO untouched and only update A/B slots
|
||||
- In practice, most updates introduce breaking changes that require updating
|
||||
the bootblock
|
||||
- Dasharo Tools Suite handles updates, does the entire update in one operation
|
||||
- So we don't use the A/B feature
|
||||
- Capsule Updates may help here
|
||||
|
||||
---
|
||||
|
||||
# Other firmware update mechanisms
|
||||
|
||||
- Flashrom plugin in fwupd
|
||||
- Updates the BIOS region only
|
||||
- Is not Vboot aware
|
||||
- UEFI Capsule Update
|
||||
- Most widely used in proprietary UEFIs
|
||||
- Can be made aware of which regions to update and which to preserve, verify
|
||||
signatures, handle disabling flash protections
|
||||
- WIP for Dasharo
|
||||
|
||||
???
|
||||
|
||||
- Capsule Updates are a requirement for Windows sticker certification
|
||||
- Supported by Windows Update and fwupd
|
||||
|
||||
# Other firmware update mechanisms
|
||||
|
||||
- Intel BIOS Guard
|
||||
- Hooks into the SMM flash update handler to call an ACM, which authorizes
|
||||
flash writes
|
||||
- Can bypass chipset flash protections and Top Swap (configurable with
|
||||
MFIT/FIT/FITC in flash descriptor straps)
|
||||
- Can also handle EC updates
|
||||
- Proprietary feature with proprietary tooling
|
||||
- Top Swap
|
||||
- Redundant bootblock feature
|
||||
- Configurable from 64KB up to 4M/8MB (maximum depending on CPU/SoC/chipset
|
||||
family) in flash descriptor straps (MFIT/FITC/FIT)
|
||||
- Potential integration with vboot?
|
||||
|
||||
???
|
||||
|
||||
- Top swap size is (barely?) enough to fit an entire Vboot RO partition
|
||||
- e.g. have immutable, write-protected recovery that verifies the top swap block
|
||||
and sets the top swap bit accordingly?
|
||||
|
||||
---
|
||||
|
||||
class: center, middle, intro
|
||||
|
||||
# Q&A
|
||||
Reference in New Issue
Block a user