Rate This Document
Findability
Accuracy
Completeness
Readability

Measurement Startup

The measurement process in Kunpeng BoostKit for Confidential Computing CCA Kit is as follows:

  1. The Kunpeng Hardware Security Module (HSM) is used as the root of trust (RoT). The CCA-related firmware is measured during Kunpeng device startup, and the measurement results are stored as a platform measurement report into the SRAM of the HSM.
  2. The kernel and startup parameters during VM startup are measured to generate a VM measurement report.
  3. The reports are packaged into a complete measurement token, which provides the remote attestation capability.

Advantages and Benefits

  1. The CCA-related firmware can be measured to enhance dependency firmware security for secure startup. cVM startup can be measured to safeguard cVMs.
  2. A built-in hardware RoT is employed, supporting anti-probing, anti-tampering, and side-channel protection to ensure secure and trustworthy measurement results.
Figure 1 Measurement process
Figure 2 Measurement report format