#eurobsdcon
51 posts · Last used 5d
https://www.youtube.com/live/AcOPLWc-_UE?si=02njYCVqRZpj9SEN
In the second video from #EuroBSDCon, the presentation focused on Confidential Computing and bringing #AMD #SEV (Secure Encrypted Virtualization) support to FreeBSD’s native hypervisor, bhyve. The talk broke down how hardware-enforced memory encryption isolates guest virtual machines from untrusted cloud providers and malicious host hypervisors.
The speaker walked through the zero-trust threat model, where an AES encryption engine built directly into the CPU's memory controller encrypts every byte of guest RAM on the fly.
By leveraging an isolated ARM-based co-processor the AMD Secure Processor encryption keys reside strictly within the hardware silicon throughout the VM's entire lifecycle. The host hypervisor acts as nothing more than an untrusted message router, meaning even a fully compromised host with root access sees only encrypted ciphertext when trying to dump guest memory.
To guarantee that the VM is running on genuine AMD hardware and untampered firmware, the implementation incorporates a robust remote attestation pipeline. Using the sevctl utility over a dedicated Unix domain socket exposed by bhyve, guest owners establish a secure Diffie-Hellman channel directly with the AMD Secure Processor.
They verify AMD's official certificate chain, validate a cryptographic measurement hash of the UEFI boot firmware (OVMF), and inject runtime secrets such as disk decryption keys—directly into encrypted guest RAM before the VM finishes booting.
A major technical highlight was overcoming multi-core (SMP) stability issues. In AMD SEV, a VM's encryption key is bound to a hardware Address Space Identifier (ASID). Standard hypervisors assign a fresh ASID when migrating a virtual CPU to a new physical core, which automatically clears out old Translation Lookaside Buffer (TLB) entries.
Because SEV keeps the exact same ASID across core hops, virtual CPUs were hitting stale memory mappings on old physical cores, causing frequent kernel crashes. The solution was implementing a targeted TLB flush for that specific ASID every time a virtual CPU migrates to a new core. +++
EuroBSDCon 2026 Brussels Day 2 room D007
EuroBSDCon 2026 Brussels room D007
The last day of talks at the European *BSD event of the year has come to an end! 😈⛳🐡
A colossal shout-out to everyone who made this event awesome! Bedankt!!
A big up to OC for taking care of us these days. 🫶🏻
- Kristof Provost
- Cristina Boca
- Aymeric Wibo
- Philipp Buehler
And let's not forget the fantastic talks and tutorials by:
- Alexander Bluhm
- Alice Sowerby
- Allan Jude
- Andreas Kirchner
- Anne Currie
- Balaje Sankar
- Baptiste Daroussin
- Benedict Reuschling
- Beni Keller
- Bojan Novković
- Brooks Davis
- Charalampos Mainas
- Charlie Li
- Dave Cottlehuber
- George Neville-Neil
- Harold Gutch
- Henning Brauer
- Hiroki Sato
- Johannes Thyssen Tishman
- Kent Inge Fagerland Simonsen
- Kirk McKusick
- Kristaps Dzonsons
- Lukas Engelhardt
- Maciej Jan Broniarz
- Marc Espie
- Martin Vahlensieck
- Mateusz Piotrowski
- Matthieu Herrb
- Michael Dexter
- Moin Rahman
- Olivier Certner
- Organizers
- Ori Bernstein
- Patrick M. Hausen
- Peter N. M. Hansteen
- Pierre Emeriaud
- Pierre Pronchery
- Stefan Sperling
- Stefano Marinelli
- Stephen Borrill
- Taylor R Campbell
- Thomas Pasqualini
- Varinka Ohanyan
- Vinícius Z.
- Walter Belgers
- Yu-Chiang (Date) Huang
- Zhen-Rong Wu
🤘 You all rocked the stage! 🤘
#EuroBSDCon #EuroBSDCon2026 #EuroBSDCon2027 #BSD #RUNBSD #FreeBSD #NetBSD #OpenBSD