Update hardware-security.md: Replace image with updated architecture diagram

This commit is contained in:
Paolo Matarazzo 2024-04-08 16:47:08 -04:00
parent a75b5a77a4
commit 838feeffc4
3 changed files with 1 additions and 1 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.2 MiB

View File

@ -86,7 +86,7 @@ In Secured-core PCs, System Guard Secure Launch protects bootup with a technolog
System Management Mode (SMM) isolation is an execution mode in x86-based processors that runs at a higher effective privilege than the hypervisor. SMM complements the protections provided by DRTM by helping to reduce the attack surface. Relying on capabilities provided by silicon providers like Intel and AMD, SMM isolation enforces policies System Management Mode (SMM) isolation is an execution mode in x86-based processors that runs at a higher effective privilege than the hypervisor. SMM complements the protections provided by DRTM by helping to reduce the attack surface. Relying on capabilities provided by silicon providers like Intel and AMD, SMM isolation enforces policies
that implement restrictions such as preventing SMM code from accessing OS memory. The SMM isolation policy is included as part of the DRTM measurements that can be sent to a verifier like Microsoft Azure Remote Attestation. that implement restrictions such as preventing SMM code from accessing OS memory. The SMM isolation policy is included as part of the DRTM measurements that can be sent to a verifier like Microsoft Azure Remote Attestation.
:::image type="content" source="image.png" alt-text="aas" lightbox="image.png"::: :::image type="content" source="architecture.png" alt-text="aas" lightbox="architecture.png":::
Learn more: Dynamic Root of Trust measure and SMM isolation Learn more: Dynamic Root of Trust measure and SMM isolation

Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB