← Documents Documentation/ABI/testing/securityfs-secrets-coco GitHub 원문 ↗

Linux 6.18.37 · ABI / testing

Confidential-computing EFI secrets securityfs ABI

AMD SEV·SEV-ES 같은 confidential-computing VM launch에서 Guest Owner가 주입한 EFI secrets를 GUID files로 읽고 unlink로 zeroize·제거하는 securityfs ABI를 설명합니다.

Source pathDocumentation/ABI/testing/securityfs-secrets-coco
Source versionLinux v6.18.37
TranslationDUJINLABS 전문 번역 + 해설

요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.

1. 요약·해설

원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.

Guest Owner secret injection과 exposure

securityfs-secrets-coco:1-18

Guest Owner가 secret을 암호화해 EFI-declared memory area에 주입하면 trusted enclave 안에서 복호화되어 untrusted host는 읽을 수 없습니다. efi_secret module은 populated area의 table entries를 GUID filename으로 노출합니다.

EFI secret-area binary format

securityfs-secrets-coco:48-51

Guest Owner가 주입하는 secrets table의 binary format은 drivers/virt/coco/efi_secret/efi_secret.c의 Structure of the EFI secret area에 설명되어 있습니다.

2. 영어 원문 전체

번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.

원문 전체 펼치기
1 What: security/secrets/coco
2 Date: February 2022
3 Contact: Dov Murik <[email protected]>
4 Description:
5 Exposes confidential computing (coco) EFI secrets to
6 userspace via securityfs.
7
8 EFI can declare memory area used by confidential computing
9 platforms (such as AMD SEV and SEV-ES) for secret injection by
10 the Guest Owner during VM's launch. The secrets are encrypted
11 by the Guest Owner and decrypted inside the trusted enclave,
12 and therefore are not readable by the untrusted host.
13
14 The efi_secret module exposes the secrets to userspace. Each
15 secret appears as a file under <securityfs>/secrets/coco,
16 where the filename is the GUID of the entry in the secrets
17 table. This module is loaded automatically by the EFI driver
18 if the EFI secret area is populated.
19
20 Two operations are supported for the files: read and unlink.
21 Reading the file returns the content of secret entry.
22 Unlinking the file overwrites the secret data with zeroes and
23 removes the entry from the filesystem. A secret cannot be read
24 after it has been unlinked.
25
26 For example, listing the available secrets::
27
28 # modprobe efi_secret
29 # ls -l /sys/kernel/security/secrets/coco
30 -r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
31 -r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
32 -r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
33 -r--r----- 1 root root 0 Jun 28 11:54 e6f5a162-d67f-4750-a67c-5d065f2a9910
34
35 Reading the secret data by reading a file::
36
37 # cat /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
38 the-content-of-the-secret-data
39
40 Wiping a secret by unlinking a file::
41
42 # rm /sys/kernel/security/secrets/coco/e6f5a162-d67f-4750-a67c-5d065f2a9910
43 # ls -l /sys/kernel/security/secrets/coco
44 -r--r----- 1 root root 0 Jun 28 11:54 736870e5-84f0-4973-92ec-06879ce3da0b
45 -r--r----- 1 root root 0 Jun 28 11:54 83c83f7f-1356-4975-8b7e-d3a0b54312c6
46 -r--r----- 1 root root 0 Jun 28 11:54 9553f55d-3da2-43ee-ab5d-ff17f78864d2
47
48 Note: The binary format of the secrets table injected by the
49 Guest Owner is described in
50 drivers/virt/coco/efi_secret/efi_secret.c under "Structure of
51 the EFI secret area".
52

3. 한국어 전문 번역

영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.

Confidential-computing EFI secret injection

1-18
항목내용
Whatsecurity/secrets/coco
Date2022년 2월
ContactDov Murik <[email protected]>
DescriptionConfidential computing(coco) EFI secret을 securityfs를 통해 userspace에 노출합니다.

EFI는 AMD SEV·SEV-ES 같은 confidential-computing platform이 VM launch 중 Guest Owner의 secret injection에 사용할 memory area를 선언할 수 있습니다. Secret은 Guest Owner가 암호화하고 trusted enclave 안에서 복호화하므로 untrusted host는 읽을 수 없습니다.

efi_secret module은 secret을 userspace에 노출합니다. 각 secret은 <securityfs>/secrets/coco 아래 file 하나로 나타나며 filename은 secrets table entry의 GUID입니다. EFI secret area가 채워져 있으면 EFI driver가 이 module을 자동으로 load합니다.

EFI secret table binary structure

48-51

Guest Owner가 주입하는 secrets table의 binary format은 drivers/virt/coco/efi_secret/efi_secret.c에서 "Structure of the EFI secret area" 아래에 설명되어 있습니다.

Coco EFI secret lifecycle
Guest Owner encrypts secretInject into EFI secret area during VM launchTrusted enclave decryptsUntrusted host cannot read
Populated EFI secret areaEFI driver auto-loads efi_secretGUID-named securityfs fileUserspace read returns secret content
Unlink GUID fileOverwrite secret data with zeroesRemove filesystem entrySecret cannot be read again

Guest Owner의 encrypted secret은 trusted guest 안에서만 복호화되고 GUID file을 unlink하면 data zeroization과 namespace 제거가 함께 일어난다.