I wonder if a 2nd physical CPU which can monitor the 'main' cpu might be a MUCH better solution. Kinda like and 'executive' CPU that notices strange things about the main CPU. Parts when scanned have been modified. CPU usage has gotten bigger.
In many smaller systems I put and executive module in to monitor the 'state' of the various system modules. When a module is in a funny state, or in a transient state for too long, the 'executive' kills it.
Given a 2nd and 3rd CPU there might even be chance to have some real encryption done by the assembled system?
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
another integrity solution
Date: 2020-04-22 12:51 pm (UTC)I wonder if a 2nd physical CPU which can monitor the 'main' cpu might be a MUCH better solution. Kinda like and 'executive' CPU that notices strange things about the main CPU. Parts when scanned have been modified. CPU usage has gotten bigger.
In many smaller systems I put and executive module in to monitor the 'state' of the various system modules. When a module is in a funny state, or in a transient state for too long, the 'executive' kills it.
Given a 2nd and 3rd CPU there might even be chance to have some real encryption done by the assembled system?
Lots of fun.