요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.
1. 요약·해설
원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.
Read와 unlink zeroization
securityfs-secrets-coco:20-47Read는 secret content를 반환하고 unlink는 data를 zero로 덮은 뒤 filesystem entry를 제거합니다. Unlink 뒤에는 다시 읽을 수 없습니다.
EFI secret-area binary format
securityfs-secrets-coco:48-51Guest Owner가 주입하는 secrets table의 binary format은 drivers/virt/coco/efi_secret/efi_secret.c의 Structure of the EFI secret area에 설명되어 있습니다.
2. 영어 원문 전체
번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.
원문 전체 펼치기
What: security/secrets/coco
Date: February 2022
Contact: Dov Murik <[email protected]>
Description:
Exposes confidential computing (coco) EFI secrets to
userspace via securityfs.
EFI can declare memory area used by confidential computing
platforms (such as AMD SEV and SEV-ES) for secret injection by
the Guest Owner during VM's launch. The secrets are encrypted
by the Guest Owner and decrypted inside the trusted enclave,
and therefore are not readable by the untrusted host.
The efi_secret module exposes the secrets to userspace. Each
secret appears as a file under <securityfs>/secrets/coco,
where the filename is the GUID of the entry in the secrets
table. This module is loaded automatically by the EFI driver
if the EFI secret area is populated.
Two operations are supported for the files: read and unlink.
Reading the file returns the content of secret entry.
Unlinking the file overwrites the secret data with zeroes and
removes the entry from the filesystem. A secret cannot be read
after it has been unlinked.
For example, listing the available secrets::
# modprobe efi_secret
# ls -l /sys/kernel/security/secrets/coco
-r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
-r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
-r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
-r--r----- 1 root root 0 Jun 28 11:54 e6f5a162-d67f-4750-a67c-5d065f2a9910
Reading the secret data by reading a file::
# cat /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
the-content-of-the-secret-data
Wiping a secret by unlinking a file::
# rm /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
# ls -l /sys/kernel/security/secrets/coco
-r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
-r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
-r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
Note: The binary format of the secrets table injected by the
Guest Owner is described in
drivers/virt/coco/efi_secret/efi_secret.c under "Structure of
the EFI secret area".
3. 한국어 전문 번역
영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.
Confidential-computing EFI secret injection
1-18| 항목 | 내용 |
|---|---|
| What | security/secrets/coco |
| Date | 2022년 2월 |
| Contact | Dov Murik <[email protected]> |
| Description | Confidential computing(coco) EFI secret을 securityfs를 통해 userspace에 노출합니다. |
EFI는 AMD SEV·SEV-ES 같은 confidential-computing platform이 VM launch 중 Guest Owner의 secret injection에 사용할 memory area를 선언할 수 있습니다. Secret은 Guest Owner가 암호화하고 trusted enclave 안에서 복호화하므로 untrusted host는 읽을 수 없습니다.
efi_secret module은 secret을 userspace에 노출합니다. 각 secret은 <securityfs>/secrets/coco 아래 file 하나로 나타나며 filename은 secrets table entry의 GUID입니다. EFI secret area가 채워져 있으면 EFI driver가 이 module을 자동으로 load합니다.
GUID secret file read와 wipe
20-47File은 read와 unlink 두 operation을 지원합니다. File을 읽으면 secret entry content를 반환합니다. File을 unlink하면 secret data를 zero로 덮어쓰고 filesystem에서 entry를 제거합니다. Unlink된 secret은 읽을 수 없습니다.
사용 가능한 secret을 나열하는 예:
# modprobe efi_secret
# ls -l /sys/kernel/security/secrets/coco
-r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
-r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
-r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
-r--r----- 1 root root 0 Jun 28 11:54 e6f5a162-d67f-4750-a67c-5d065f2a9910
File을 읽어 secret data를 읽는 예:
# cat /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
the-content-of-the-secret-data
File을 unlink해 secret을 wipe하는 예:
# rm /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
# ls -l /sys/kernel/security/secrets/coco
-r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
-r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
-r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
EFI secret table binary structure
48-51Guest Owner가 주입하는 secrets table의 binary format은 drivers/virt/coco/efi_secret/efi_secret.c에서 "Structure of the EFI secret area" 아래에 설명되어 있습니다.
Guest Owner의 encrypted secret은 trusted guest 안에서만 복호화되고 GUID file을 unlink하면 data zeroization과 namespace 제거가 함께 일어난다.
Guest Owner secret injection과 exposure
securityfs-secrets-coco:1-18Guest Owner가 secret을 암호화해 EFI-declared memory area에 주입하면 trusted enclave 안에서 복호화되어 untrusted host는 읽을 수 없습니다. efi_secret module은 populated area의 table entries를 GUID filename으로 노출합니다.