Xen Project Developer Summit has ended
Friday, October 25 • 2:00pm - 2:30pm
In-Guest Mechanism to Strengthen Guest Separation, Philip Tricca, Citrix

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Terms related to security like 'disaggregation' and 'stubdom' have found their way into the standard Xen vernacular. Implementations of these architectures still require heavy lifting but examples have made their way into both the open source and commercial products. In this talk Philip presents a lesser known but complimentary method to confine QEMU processes using SELinux type enforcement. This architecture alone is interesting but Philip believes its utility extends beyond QEMU and SELinux. Future problems like inter-VM communication mechanisms hold unique challenges with regard to access control and policy semantics. Philip will argue that an approach influenced by sVirt and user-space object managers will be useful here. As always, attendees should expect tangents into abstract topics like the nature of trust and the utopic world that strong security mechanisms will bring about.


Philip Tricca

Platform Architect, Intel
Philip is a platform architect in Intel's platform security division working to enable use of the Trusted Platform Module (TPM) and SGX in open source. Recently Phil has taken over maintainership of Intel's implementation of the TPM2 software stack and has been obsessing over system... Read More →

Friday October 25, 2013 2:00pm - 2:30pm BST
Moorfoot Hall Edinburgh International Conference Centre

Attendees (0)