intel / intel/confidential-computing.tdx.tdx-module
How to prevent untrusted BIOS from loading compromised P-SEAM loader?
- Dominant language
- No language data
- Stars
- 113
- Forks
- 24
- PR merge metrics
- No merged PRs in 30d
Description
Hi, I am studying the loading procedure of TDX module,
Based on the SDMs, I found that ensuring the initial integrity of P-SEAM loader (which is loaded into the SEAM Range) is the key to protect following modules (e.g., TDX module, TDVMs).
Also, I read that NP-SEAM loader (authenticated by Intel) is responsible to load the P-SEAM loader.
However, aren't there any possibility that untrusted BIOS loads its own compromised P-SEAM loader and finalizes SEAM Range by configuring `SEAMRR` MSRs?
Is there any hardware mechanism that prevents untrusted BIOS from writing `SEAMRR` MSRs?
I could not find any information from the SDMs.
Contributor guide
Research direction
The issue names no repository files, tests, or entry points. Start with the Intel SDMs and the TDX loading procedure described in the message; done means documenting whether hardware prevents an untrusted BIOS from writing SEAMRR MSRs and explaining the relevant protection mechanism.
Written by the indexing model from the issue text.
Assessment
- Domain
- operating-systems, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100