Explore the challenges and implications of the ARM Confidential Computing Architecture (CCA) in this 25-minute KVM Forum talk. Delve into the composition of CCA, including the Realm Management Extension (RME), firmware (Monitor), and Real Management Monitor (RMM). Examine how the RMM, despite being part of the hypervisor stack, is provided by the platform itself rather than deployed by the normal world hypervisor. Analyze the consequences of this split ownership for KVM and discuss potential improvements to the current situation. Gain insights into the complexities of implementing confidential computing in ARM-based systems and the impact on hypervisor development and deployment.
Overview
Syllabus
KVM/arm64: Episode V - The Blob Strikes Back
Taught by
KVM Forum