Intel Trusted Execution Technology for Server Platforms: A Guide to More Secure Datacenters

William Futral, James Sonnett Greene · OAPEN (The OAPEN Foundation) · 2013

Additional MeasurementsHow does Intel TXT provide attestation, and what makes it so powerful?• How does the system administrator enable it?• How does the datacenter take advantage of it?• How does system software use it?• How do others make use of it?• Then we will take a closer look at attestation and how it is currently used.To get a glimpse of the future, we will also discuss concepts that are being evaluated and prototyped. What Intel TXT Does Not DoIntel TXT does not measure trust, nor does it define levels of trust.These are subjective terms whose definitions will change over time.Rather, Intel TXT allows the datacenter/cloud service provider, cloud service client, OS, and other entities to make their own trust decisions with a new set of robust credentials.These trust decisions can be, but do not have to be, based solely on Intel TXT.In fact, since defense in depth refers to using multiple methods to protect your assets, Intel TXT assumes that other security mechanisms exist, new technologies will emerge, and together they will provide greater coverage.Intel TXT is flexible enough that it can be used to help verify proper utilization of other methods and their policies.Intel TXT does not monitor runtime configuration.It only performs measurements at specific events, such as Power On, and upon request by the host OS to do a secure launch.Therefore, it does not degrade performance since it does not steal cycles from the operating system or applications running on the platform, nor does it consume memory bandwidth and other operational resources after the secure launch.Currently, Intel TXT only measures the host OS or VMM and does not provide for secure measurements of a guest OS or its applications.This is a topic of discussion and interest throughout the industry, and it would be very surprising if this capability is not added in the future. Enhancements for ServersAs mentioned at the beginning, Intel TXT was first developed for client platforms (desktop and mobile).So is it the same technology?There are some differences, primarily because servers are more complex than client machines.One of the most prominent differences is the set of server features known as Reliability, Availability, and Serviceability (RAS).The complexity of server RAS features such as memory mirroring, memory sparing, and error handling require capabilities that are very platform-specific, and thus must be performed by platform-specific code.This code must be trusted; in particular, the BIOS code that executes after a platform reset (to mitigate the reset attack) and the System Management Module (SMM) code, which may need to change memory configuration and/or platform configuration while the system is in operation.This changes what the TCG refers to as the TCB (Trusted Computing Base), which, by definition, is the minimum amount of code that needs to be trusted for a platform.For server platforms, the TCB includes the processor microcode and the ACM, whose signature and integrity are checked before the ACM is allowed to execute.It must also include the BIOS (or at least a portion of the BIOS). Including BIOS in the TCBFor client platforms, the BIOS does not need to be trusted to clear memory in defense of a reset attack, because memory cleaning is performed by the ACM before allowing the BIOS to access the memory.This is not possible for servers given the complexity of server memory configurations and RAS features.Thus in response to (or to detect) a reset attack, BIOS code integrity must be verified before the BIOS can be trusted to clean secrets from memory.Typically, this is transparent to the OS and end user, but it does have implications on how BIOS upgrades occur.For instance, upgrading BIOS causes its measurement to change, and if there is a reset attack after a BIOS update, the BIOS would not be trusted.To overcome this problem, Intel TXT allows for a signed BIOS policy that allows the ACM to validate that the BIOS is still trusted using signature verification.

Read the paper · More papers on PaperTik