Building Execution Environments from the Trusted Platform Module
摘要
In this chapter, we describe attempts at unifying the worlds of hardware and software in which the behaviour of software is controlled by security hardware. We look at technologies born out of the trusted computing movement, describing one of the key technology enablers: the Trusted Platform Module (TPM) specifications from the Trusted Computing Group. We review several widely deployed commercial technologies that use TPMs to build environments in which applications can be executed on an initially untrusted system. Among these technologies, we look at Intel Trusted Execution Technology (Intel TXT) and AMD’s Secure Virtual Machine (AMD SVM) and Secure Encrypted Virtualisation (AMD SEV). Lastly, we discuss several academic and industry projects that, while not commercially deployed, were still influential in the development of modern trusted execution environments.