All of lore.kernel.org
 help / color / mirror / Atom feed
From: greg@kroah.com (Greg KH)
To: linux-arm-kernel@lists.infradead.org
Subject: [Ksummit-2013-discuss] [ARM ATTEND] Trustzone-based security solution for ARM Linux
Date: Thu, 15 Aug 2013 11:26:00 -0700	[thread overview]
Message-ID: <20130815182600.GA22567@kroah.com> (raw)
In-Reply-To: <CAKv+Gu8_65EkDkn6-W1NKZSs9P8KOxfFNzFNXq0Eqm5dMYGxwQ@mail.gmail.com>

On Thu, Aug 15, 2013 at 07:41:46PM +0200, Ard Biesheuvel wrote:
> > I'm not pretending they are the same thing, but I am wanting to know how
> > Linux doesn't work for either of those requirements, as I want to see
> > Linux be the solution for this "trusted" kernel as well.
> >
> 
> For the former case, there is the assumption (or misconception) that
> Linux cannot deliver the boot speed or bounded worst case response
> time requirements imposed by things like software defined radio.

So, what can we do to address this?  Technically I think Linux can
handle this just fine, as others have pointed out it is used in these
situations.

> Also, there is the existing codebase of RTOS hosted CAN stacks etc,
> that have been certified by the [automotive] customer and are moved
> from a dedicated MCU into the application CPU as a cost saving
> measure. This means that even if Linux does fit the bill in principle,
> many will still have no choice other than to go with non-Linux.

That's their decision, which is fine.  Getting the Linux CAN stack
"certified" might be a good goal for a manufacturer who wants to ship
Linux for this type of system, although we all know how much those
things really matter when it comes to technical issues :)

> For the latter case, it depends on the compatibility of Linux with the
> restricted secure world environment, most notably the secure memory.
> 256k of on chip SRAM is sufficient to do plenty of interesting things
> in the secure world, but sadly, running Linux is not one of them. (I
> know PoP DDR is considered to be secure memory by some vendors as
> well, but its application is not as widespread in the automotive
> world)

Ah, yeah, 256K of ram might be tough to slim Linux down to, but system
sizes keep increasing, so those limitations might be resolved soon
without us having to do anything...

thanks,

greg k-h

  reply	other threads:[~2013-08-15 18:26 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-08-15  3:44 [ARM ATTEND] Trustzone-based security solution for ARM Linux Barry Song
2013-08-15  4:28 ` [Ksummit-2013-discuss] " Greg KH
2013-08-15  5:14   ` Jassi Brar
2013-08-15  7:45     ` Barry Song
2013-08-15  8:05       ` Greg KH
2013-08-15  8:22         ` Barry Song
2013-08-15 16:01           ` Greg KH
2013-08-16  2:08             ` Barry Song
2013-08-15  8:24         ` Ard Biesheuvel
2013-08-15 15:56           ` Greg KH
2013-08-15 17:41             ` Ard Biesheuvel
2013-08-15 18:26               ` Greg KH [this message]
2013-08-15 18:33                 ` Russell King - ARM Linux
2013-08-15 18:44                   ` Greg KH
2013-08-15  8:17       ` Jassi Brar
2013-08-15  8:36         ` Barry Song
2013-08-15  7:36   ` Barry Song
2013-08-15 16:03     ` Stephen Warren
2013-08-15 17:43       ` Dave Martin
2013-08-16  2:39         ` Barry Song
2013-08-16 11:14           ` Dave Martin
2013-08-16 11:17           ` Jassi Brar
2013-08-19 23:31             ` Barry Song
2013-08-15  9:05   ` Barry Song
2013-08-15  7:57 ` Ben Dooks
2013-08-15  8:06   ` Barry Song
2013-08-15 14:08 ` Dave Martin
2013-08-16  2:49   ` Barry Song
     [not found] <20130816110446.GA2909@localhost.localdomain>
2013-08-19 23:13 ` [Ksummit-2013-discuss] " Barry Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20130815182600.GA22567@kroah.com \
    --to=greg@kroah.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.