intel / intel/confidential-computing.tdx.tdx-module

How to prevent untrusted BIOS from loading compromised P-SEAM loader?

Open
#4 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
113
Forks
24
PR merge metrics
No merged PRs in 30d

Description

Hi, I am studying the loading procedure of TDX module,

Based on the SDMs, I found that ensuring the initial integrity of P-SEAM loader (which is loaded into the SEAM Range) is the key to protect following modules (e.g., TDX module, TDVMs).

Also, I read that NP-SEAM loader (authenticated by Intel) is responsible to load the P-SEAM loader.

However, aren't there any possibility that untrusted BIOS loads its own compromised P-SEAM loader and finalizes SEAM Range by configuring `SEAMRR` MSRs?

Is there any hardware mechanism that prevents untrusted BIOS from writing `SEAMRR` MSRs?

I could not find any information from the SDMs.

Contributor guide

Open the contributing guide

Research direction

The issue names no repository files, tests, or entry points. Start with the Intel SDMs and the TDX loading procedure described in the message; done means documenting whether hardware prevents an untrusted BIOS from writing SEAMRR MSRs and explaining the relevant protection mechanism.

Written by the indexing model from the issue text.

Assessment

Domain
operating-systems, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.