Jeudi 5 Novembre 2026
- Imprimer
- Partager
- Partager sur Facebook
- Partager sur LinkedIn
The Design and Verification of a Virtual Firmware Monitor
Abstract:
To accommodate ever-increasing multi-tenancy and security constraints, computer systems have evolved toward greater isolation between software components. Yet, even today, firmware remains all-powerful and completely unchecked. By executing with the highest privilege on the CPU, firmware can bypass hypervisor and confidential computing isolation, breaking any existing security guarantees in case of a compromise.
In this talk, we will explore how to secure the highest privilege level of the CPU, where the firmware runs. We will present the design, implementation, and verification of Miralis, a new kind of system we call a Virtual Firmware Monitor. We will explain how Miralis can safely and efficiently de-privilege unmodified vendor firmware on RISC-V platforms by revisiting classic virtualization ideas. Finally, we will explain how we verified core Miralis subsystems, from virtualization logic to assembly, by leveraging existing exhaustive ISA specifications.
Biography:
Charly is a member of the Systems Research team at Google (SRG). His research focuses on building secure systems foundations, with an emphasis on virtualization, confidential computing, low-level system security, and lightweight formal methods. Before joining Google, Charly obtained his PhD from EPFL and an engineering degree from École Polytechnique.
Date et lieu
Jeudi 5 Novembre à 17:00
Bâtiment IMAG, salle 406
Organisé par
Alain Tchana
Responsable équipe KraKOS
- Imprimer
- Partager
- Partager sur Facebook
- Partager sur LinkedIn