Learning outcomes
- Derive and reduce the trusted computing base for one deployed security property.
- Choose process, container, virtual-machine, kernel, and hardware boundaries from a stated adversary and consequence.
- Connect secure boot and measured boot to fresh platform attestation without overstating the result.
- Analyze side channels, covert channels, tamper faults, mandatory labels, and controlled data release.
Scenario
A platform team runs an identity-aware gateway, a policy service, and high-value workloads on shared cloud infrastructure. It must prevent a compromised workload from taking gateway authority, verify approved node state before credential issuance, reduce cross-tenant leakage, harden recovery, and prove which lower layers remain trusted.
Ordered learning units
Trusted Computing Base
Identify every component whose correct behavior is necessary for a stated security property, then reduce and verify that trusted set.
Reference Monitor
Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.
Security Kernel
Understand the small privileged mechanism that implements a reference monitor and controls access to system resources.
Minimize a Trusted Computing Base
Derive the real trusted set for one security claim, remove accidental trust, and build evidence for every remaining assumption.
Privilege Separation
Split a service into components with different authority so compromise of one parser or workflow does not grant the complete service privilege.
Execution Isolation and Sandboxing
Bound untrusted code with explicit memory, process, file, network, device, syscall, identity, and resource controls.
Compare process, container, and VM isolation
Compare shared kernel, virtual machine, host, node, runtime, credential, and control-plane trust boundaries.
System Hardening
Reduce a deployed system to required services, identities, interfaces, privileges, configurations, and recovery paths, then keep it there.
Harden a Security-Sensitive Service
Build, deploy, verify, update, and recover a role-specific minimal service without broad host or control-plane authority.
Hardware Root of Trust
Anchor a narrow security function in protected hardware while stating the manufacturing, firmware, key, lifecycle, and physical assumptions that remain.
Secure Boot and Measured Boot
Distinguish code authorization before execution from recorded boot measurements used for later appraisal and recovery.
Platform Attestation
Appraise fresh signed evidence about a platform through explicit attester, verifier, reference-value, policy, and relying-party roles.
Design Secure Boot and Platform Attestation
Connect roots of trust, boot verification, measurements, fresh evidence, appraisal, policy, update, revocation, and recovery.
Side-Channel Attack
Analyze information leaked through time, caches, memory access, power, emissions, sound, faults, resources, and error behavior.
Fault Injection and Tamper Resistance
Model physical and logical faults that skip checks, corrupt state, expose keys, or force unsafe recovery in a security component.
Covert Channel
Find unintended communication paths that let cooperating subjects transfer information through shared storage, timing, load, errors, or resource state.
Analyze Side-Channel and Shared-Resource Risk
Model secret-dependent signals and deliberate covert channels across software, shared hardware, protocols, and physical devices.
Information Flow Control
Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.
Multilevel Security
Enforce mandatory policy when one system processes information and users at different sensitivity and clearance levels.
Design Information Flow Controls
Define labels, allowed flows, trusted transformations, release policy, evidence, and residual channels across an application and its data systems.
Evaluation questions
- Which components, operators, credentials, providers, and recovery paths are trusted for the exact security property?
- Which kernel, host, hardware, device, cache, management, and control-plane mechanisms remain shared across the claimed boundary?
- What does each boot or attestation result prove, omit, and permit the relying party to decide?
- Which direct, derived, timing, covert, tamper, rollback, and declassification paths can still break the property?
Completion conditions
- Produce and reduce a deployed TCB graph for one high-authority service, with evidence for every remaining trust assumption.
- Harden and test one service boundary against prohibited file, process, device, network, credential, resource, and recovery actions.
- Run one fresh platform-attestation flow with replay, stale-version, omitted-component, update, and outage tests.
- Measure one side or covert channel and implement one bounded information-flow release with negative tests.
