Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Splitting pKVM Into Discrete, Mutually Exclusive Address Spaces for Enhanced Security

Linux Foundation via YouTube

Overview

Explore the advanced security features of pKVM, a confidential computing extension for KVM/arm64, in this 28-minute Linux Foundation talk. Dive into the proposed enhancements that create separate, independently tagged address spaces for improved isolation between host and guests. Learn how these changes mitigate potential vulnerabilities, reduce the impact of bugs, and minimize trust requirements for drivers. Examine the hypervisor's isolation mechanisms and common constructs used to prevent accidental data leakages. Gain insights into VCPU isolation, mobile isolation, exception levels, and strategies for dealing with buggy software in the context of confidential computing.

Syllabus

Introduction
Buggy Software
Exception Levels
Extras
VCPU Isolation
Mobile Isolation

Taught by

Linux Foundation

Reviews

Start your review of Splitting pKVM Into Discrete, Mutually Exclusive Address Spaces for Enhanced Security

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.