towercomputers / toweros

TowerOS: An Operating System for Network-Boundary Converged Multi-Level Secure Computing
https://toweros.org
Apache License 2.0
3 stars 0 forks source link

Establish and Document Security Model #106

Closed adamkrellenstein closed 10 months ago

adamkrellenstein commented 10 months ago

Security Guarantees

Firewall

Hardware

Operating System

Application-Level

Trusted Computing Base

Threat Analysis

Class Attack Mitigated If so, how?
Theft Theft of Device Yes Encrypted root disks
Physical Tampering Evil-Maid Attack Optional Raspberry Pis: https://www.zymbit.com/
Physical Tampering Cold-Boot Attack Optional Raspberry Pis: https://www.zymbit.com/
Microarchitectural RowHammer; RowPress Yes Host-Isolation
Microarchitectural Speculative Execution Yes Host-Isolation
Physical Side-Channel Power Consumption (https://www.hertzbleed.com/) Optional Disable DVFS
Physical Side-Channel Acoustic Emissions No
Physical Side-Channel Electromagnetic Radiation No
ouziel-slama commented 10 months ago

https://towercomputers.github.io/tower-tools/security/