ืคื’ื™ืขื•ืช ื‘ืžืขื‘ื“ื™ AMD ื”ืžืืคืฉืจืช ืœืš ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ื”ื’ื ื” ืฉืœ SEV (Secure Encrypted Virtualization)

ื—ื•ืงืจื™ื ื‘ืžืจื›ื– ื”ืœืžื”ื•ืœืฅ ืœืื‘ื˜ื—ืช ืžื™ื“ืข (CISPA) ืคืจืกืžื• ืฉื™ื˜ืช ื”ืชืงืคื” ื—ื“ืฉื” ืฉืœ CacheWarp ื›ื“ื™ ืœืกื›ืŸ ืืช ืžื ื’ื ื•ืŸ ื”ืื‘ื˜ื—ื” AMD SEV (Secure Encrypted Virtualization) ื”ืžืฉืžืฉ ื‘ืžืขืจื›ื•ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืžื”ืคืจืขื•ืช ืฉืœ ื”-Hypervisor ืื• ืžื ื”ืœ ื”ืžืขืจื›ืช ื”ืžืืจื—. ื”ืฉื™ื˜ื” ื”ืžื•ืฆืขืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืขื ื’ื™ืฉื” ืœ-Hypervisor ืœื‘ืฆืข ืงื•ื“ ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื•ืœื”ืกืœื™ื ื”ืจืฉืื•ืช ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ื”ืžื•ื’ื ืช ื‘ืืžืฆืขื•ืช AMD SEV.

ื”ืžืชืงืคื” ืžื‘ื•ืกืกืช ืขืœ ืฉื™ืžื•ืฉ ื‘ืคื’ื™ืขื•ืช (CVE-2023-20592) ื”ื ื’ืจืžืช ื›ืชื•ืฆืื” ืžืคืขื•ืœื” ืœื ื ื›ื•ื ื” ืฉืœ ื”ืžื˜ืžื•ืŸ ื‘ืžื”ืœืš ื‘ื™ืฆื•ืข ื”ื•ืจืืช ื”ืžืขื‘ื“ ืฉืœ INVD, ื‘ืขื–ืจืชื” ื ื™ืชืŸ ืœื”ืฉื™ื’ ืื™ ื”ืชืืžื” ืฉืœ ื ืชื•ื ื™ื ื‘ื–ื™ื›ืจื•ืŸ ื•ื‘ืžื˜ืžื•ืŸ. , ื•ืžืขืงืคื™ื ืžื ื’ื ื•ื ื™ื ืœืฉืžื™ืจื” ืขืœ ืฉืœืžื•ืช ื–ื™ื›ืจื•ืŸ ื”ืžื›ื•ื ื” ื”ื•ื•ื™ืจื˜ื•ืืœื™ืช, ื”ืžื™ื•ืฉืžื™ื ืขืœ ืกืžืš ื”ื”ืจื—ื‘ื•ืช SEV-ES ื•- SEV-SNP. ื”ืคื’ื™ืขื•ืช ืžืฉืคื™ืขื” ืขืœ ืžืขื‘ื“ื™ AMD EPYC ืžื”ื“ื•ืจ ื”ืจืืฉื•ืŸ ื•ืขื“ ื”ืฉืœื™ืฉื™.

ืขื‘ื•ืจ ืžืขื‘ื“ื™ AMD EPYC ืžื”ื“ื•ืจ ื”ืฉืœื™ืฉื™ (Zen 3), ื”ื‘ืขื™ื” ื ืคืชืจื” ื‘ืขื“ื›ื•ืŸ ื”ืžื™ืงืจื•ืงื•ื“ ืฉืœ ื ื•ื‘ืžื‘ืจ ืฉืคื•ืจืกื ืืชืžื•ืœ ืขืœ ื™ื“ื™ AMD (ื”ืชื™ืงื•ืŸ ืื™ื ื• ื’ื•ืจื ืœืคื’ื™ืขื” ื›ืœืฉื”ื™ ื‘ื‘ื™ืฆื•ืขื™ื). ืขื‘ื•ืจ ื”ื“ื•ืจ ื”ืจืืฉื•ืŸ ื•ื”ืฉื ื™ ืฉืœ AMD EPYC (Zen 1 ื•-Zen 2), ืœื ื ื™ืชื ืช ื”ื’ื ื”, ืžื›ื™ื•ื•ืŸ ืฉืžืขื‘ื“ื™ื ืืœื” ืื™ื ื ืชื•ืžื›ื™ื ื‘ืชื•ืกืฃ SEV-SNP, ื”ืžืกืคืง ื‘ืงืจืช ืฉืœืžื•ืช ืขื‘ื•ืจ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช. ื”ื“ื•ืจ ื”ืจื‘ื™ืขื™ ืฉืœ ืžืขื‘ื“ื™ AMD AMD EPYC "Genoa" ื”ืžื‘ื•ืกืกื™ื ืขืœ ืžื™ืงืจื•-ืืจื›ื™ื˜ืงื˜ื•ืจืช "Zen 4" ืื™ื ื• ืคื’ื™ืข.

ื˜ื›ื ื•ืœื•ื’ื™ื™ืช AMD SEV ืžืฉืžืฉืช ืœื‘ื™ื“ื•ื“ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืขืœ ื™ื“ื™ ืกืคืงื™ ืขื ืŸ ื›ื’ื•ืŸ Amazon Web Services (AWS), Google Cloud, Microsoft Azure ื•-Oracle Compute Infrastructure (OCI). ื”ื’ื ืช AMD SEV ืžื™ื•ืฉืžืช ื‘ืืžืฆืขื•ืช ื”ืฆืคื ื” ื‘ืจืžืช ื”ื—ื•ืžืจื” ืฉืœ ื–ื™ื›ืจื•ืŸ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช. ื‘ื ื•ืกืฃ, ื”ื”ืจื—ื‘ื” SEV-ES (ืžืฆื‘ ืžื•ืฆืคืŸ) ืžื’ื™ื ื” ืขืœ ืื•ื’ืจื™ CPU. ืจืง ืœืžืขืจื›ืช ื”ืื•ืจื—ืช ื”ื ื•ื›ื—ื™ืช ื™ืฉ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ื”ืžืคื•ืขื ื—ื™ื, ื•ื›ืืฉืจ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืื—ืจื•ืช ื•ื”-Hypervisor ืžื ืกื™ื ืœื’ืฉืช ืœื–ื™ื›ืจื•ืŸ ื–ื”, ื”ื ืžืงื‘ืœื™ื ืกื˜ ืžื•ืฆืคืŸ ืฉืœ ื ืชื•ื ื™ื.

ื”ื“ื•ืจ ื”ืฉืœื™ืฉื™ ืฉืœ ืžืขื‘ื“ื™ AMD EPYC ื”ืฆื™ื’ ื”ืจื—ื‘ื” ื ื•ืกืคืช, SEV-SNP (Secure Nested Paging), ื”ืžื‘ื˜ื™ื—ื” ืคืขื•ืœื” ื‘ื˜ื•ื—ื” ืฉืœ ื˜ื‘ืœืื•ืช ื“ืคื™ ื–ื™ื›ืจื•ืŸ ืžืงื•ื ื ื•ืช. ื‘ื ื•ืกืฃ ืœื”ืฆืคื ืช ื–ื™ื›ืจื•ืŸ ื›ืœืœื™ืช ื•ื‘ื™ื“ื•ื“ ืจื™ืฉื•ื, SEV-SNP ืžื™ื™ืฉื ืืžืฆืขื™ื ื ื•ืกืคื™ื ืœื”ื’ื ื” ืขืœ ืฉืœืžื•ืช ื”ื–ื™ื›ืจื•ืŸ ืขืœ ื™ื“ื™ ืžื ื™ืขืช ืฉื™ื ื•ื™ื™ื ื‘-VM ืขืœ ื™ื“ื™ ื”-Hypervisor. ืžืคืชื—ื•ืช ื”ื”ืฆืคื ื” ืžื ื•ื”ืœื™ื ื‘ืฆื“ ืฉืœ ืžืขื‘ื“ PSP (Platform Security Processor) ื ืคืจื“ ื”ืžื•ื‘ื ื” ื‘ืฉื‘ื‘, ื”ืžื™ื•ืฉื ืขืœ ื‘ืกื™ืก ืืจื›ื™ื˜ืงื˜ื•ืจืช ARM.

ื”ืžื”ื•ืช ืฉืœ ืฉื™ื˜ืช ื”ื”ืชืงืคื” ื”ืžื•ืฆืขืช ื”ื™ื ืœื”ืฉืชืžืฉ ื‘ื”ื•ืจืื” ืฉืœ INVD ื›ื“ื™ ืœื‘ื˜ืœ ื‘ืœื•ืงื™ื (ืฉื•ืจื•ืช) ื‘ืžื˜ืžื•ืŸ ืฉืœ ื“ืคื™ื ืžืœื•ื›ืœื›ื™ื ืžื‘ืœื™ ืœื–ืจื•ืง ืืช ื”ื ืชื•ื ื™ื ืฉื”ืฆื˜ื‘ืจื• ื‘ืžื˜ืžื•ืŸ ืœื–ื™ื›ืจื•ืŸ (ื›ืชื™ื‘ื” ื—ื–ืจื”). ืœืคื™ื›ืš, ื”ืฉื™ื˜ื” ืžืืคืฉืจืช ืœืš ืœื”ื•ืฆื™ื ื ืชื•ื ื™ื ืฉื”ืฉืชื ื• ืžื”ืžื˜ืžื•ืŸ ืžื‘ืœื™ ืœืฉื ื•ืช ืืช ืžืฆื‘ ื”ื–ื™ื›ืจื•ืŸ. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืžื•ืฆืข ืœื”ืฉืชืžืฉ ื‘ื—ืจื™ื’ื™ ืชื•ื›ื ื” (ื”ื–ืจืงืช ืชืงืœื•ืช) ื›ื“ื™ ืœื”ืคืกื™ืง ืืช ืคืขื•ืœืช ื”ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช ื‘ืฉื ื™ ืžืงื•ืžื•ืช: ืžืœื›ืชื—ื™ืœื”, ื”ืชื•ืงืฃ ืงื•ืจื ืœื”ื•ืจืื” "wbnoinvd" ื›ื“ื™ ืœืืคืก ืืช ื›ืœ ืคืขื•ืœื•ืช ื”ื›ืชื™ื‘ื” ื‘ื–ื™ื›ืจื•ืŸ ืฉื ืฆื‘ืจื• ื‘- ื”ืžื˜ืžื•ืŸ, ื•ื‘ืžืงื•ื ื”ืฉื ื™ ืงื•ืจื ืœื”ื•ืจืื” "invd" ืœื”ื—ื–ืจืช ืคืขื•ืœื•ืช ื›ืชื™ื‘ื” ืฉืœื ืžืฉืชืงืคื•ืช ื‘ื–ื™ื›ืจื•ืŸ ืœืžืฆื‘ ื”ื™ืฉืŸ.

ื›ื“ื™ ืœื‘ื“ื•ืง ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžืขืจื›ื•ืช ืฉืœืš, ืคื•ืจืกื ืื‘ ื˜ื™ืคื•ืก ืฉืœ ื ื™ืฆื•ืœ ื”ืžืืคืฉืจ ืœืš ืœื”ื›ื ื™ืก ื—ืจื™ื’ ืœืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ื”ืžื•ื’ื ืช ื‘ืืžืฆืขื•ืช AMD SEV ื•ืœื”ื—ื–ื™ืจ ืฉื™ื ื•ื™ื™ื ื‘-VM ืฉืœื ืื•ืคืกื• ืœื–ื™ื›ืจื•ืŸ. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื—ื–ืจื” ืœืื—ื•ืจ ืฉืœ ืฉื™ื ื•ื™ ื›ื“ื™ ืœืฉื ื•ืช ืืช ื–ืจื™ืžืช ื”ืชื•ื›ื ื™ืช ืขืœ ื™ื“ื™ ื”ื—ื–ืจืช ื›ืชื•ื‘ืช ื”ื—ื–ืจื” ื™ืฉื ื” ื‘ืขืจื™ืžื”, ืื• ืœื”ืฉืชืžืฉ ื‘ืคืจืžื˜ืจื™ ื”ื›ื ื™ืกื” ืฉืœ ื”ืคืขืœื” ื™ืฉื ื” ืฉืื•ืžืชื” ื‘ืขื‘ืจ ืขืœ ื™ื“ื™ ื”ื—ื–ืจืช ืขืจืš ืชื›ื•ื ืช ืื™ืžื•ืช.

ืœื“ื•ื’ืžื”, ื—ื•ืงืจื™ื ื”ื“ื’ื™ืžื• ืืช ื”ืืคืฉืจื•ืช ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ืช CacheWarp ื›ื“ื™ ืœื‘ืฆืข ืžืชืงืคืช Bellcore ืขืœ ื”ื˜ืžืขืช ืืœื’ื•ืจื™ืชื RSA-CRT ื‘ืกืคืจื™ื™ืช ipp-crypto, ืฉืื™ืคืฉืจื” ืœืฉื—ื–ืจ ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™ ื‘ืืžืฆืขื•ืช ื”ื—ืœืคืช ืฉื’ื™ืื•ืช ื‘ืขืช ื—ื™ืฉื•ื‘ ื“ื™ื’ื™ื˜ืœื™. ื—ึฒืชึดื™ืžึธื”. ื–ื” ื’ื ืžืจืื” ื›ื™ืฆื“ ื ื™ืชืŸ ืœืฉื ื•ืช ืืช ืคืจืžื˜ืจื™ ืื™ืžื•ืช ื”ื”ืคืขืœื” ืœ-OpenSSH ื‘ืขืช ื—ื™ื‘ื•ืจ ืžืจื—ื•ืง ืœืžืขืจื›ืช ืื•ืจื—, ื•ืœืื—ืจ ืžื›ืŸ ืœืฉื ื•ืช ืืช ืžืฆื‘ ื”ืื™ืžื•ืช ื‘ืขืช ื”ืคืขืœืช ืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช sudo ื›ื“ื™ ืœืงื‘ืœ ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืื•ื‘ื•ื ื˜ื• 20.04. ื”ื ื™ืฆื•ืœ ื ื‘ื“ืง ืขืœ ืžืขืจื›ื•ืช ืขื ืžืขื‘ื“ื™ AMD EPYC 7252, 7313P ื•-7443.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”