From: Laurent Vivier <Laurent@vivier.eu>
To: "Bud P. Bruegger" <bruegger@ancitel.it>
Cc: qemu-devel@nongnu.org, John Forrester <forrester@ancitel.it>
Subject: Re: [Qemu-devel] QEMU as a "virtual smart card"?
Date: Wed, 02 Sep 2009 00:27:02 +0200 [thread overview]
Message-ID: <1251844022.5774.4.camel@Quad> (raw)
In-Reply-To: <20090831180825.6ed2ea55@bud-laptop>
Le lundi 31 août 2009 à 18:08 +0200, Bud P. Bruegger a écrit :
> Hello everyone,
>
> we are thinking of a possibly "exotic" use of QEMU and would like to
> ask your advice on whether we are going in the right direction.
>
> We are pondering of how to use a virtual machine to have some security
> features normally associated with hard tokens such as smart cards.
>
> In particular, one of the key concepts of smart cards is that they can
> store secret keys that never leave the device but can only be used by a
> trusted and protected internal CPU for encryption/signing.
>
> At least looking naively at QEMU, it seems that its CPU and RAM are
> well protected from the host operating system--in a way to say make it
> practically impossible for some malware to extract the secret key used
> in a virtual machine.
>
> Is this a valid conception of what QEMU does? How good is the
> isolation of a virtual machine from the host operating system.
>
> We are also interested in the isolation of input devices, in
> particularly the keyboard as to prevent PIN sniffing. My "naive"
> impression is that key logging for a PS/2 keyboard is probably more
> difficult than with a USB keyboard. Is there any thruth to my
> misconception?
>
> Finally one last question questions:
>
> * Is there any way of getting exclusive access to an USB pen drive
> from a virtual machine, preventing the host operating system to say take
> an image of the content?
>
> many thanks in advance for any input and illuminations!
In fact, you want to do that: http://www.myglobull.com/ ?
Regards,
Laurent
--
--------------------- laurent@vivier.eu ----------------------
"Tout ce qui est impossible reste à accomplir" Jules Verne
"Things are only impossible until they're not" Jean-Luc Picard
next prev parent reply other threads:[~2009-09-01 22:27 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-31 16:08 [Qemu-devel] QEMU as a "virtual smart card"? Bud P. Bruegger
2009-09-01 22:27 ` Laurent Vivier [this message]
2009-09-01 23:47 ` Jamie Lokier
2009-09-02 14:58 ` Blue Swirl
2009-09-03 15:09 ` Bud P. Bruegger
2009-09-03 18:51 ` Blue Swirl
2009-09-04 12:08 ` Paul Brook
2009-09-04 13:12 ` Lennart Sorensen
2009-09-04 13:40 ` Bud P. Bruegger
2009-09-05 2:21 ` Jamie Lokier
2009-09-02 6:58 ` [Qemu-devel] " Paolo Bonzini
2009-09-02 9:17 ` François Revol
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1251844022.5774.4.camel@Quad \
--to=laurent@vivier.eu \
--cc=bruegger@ancitel.it \
--cc=forrester@ancitel.it \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.