OpenXT Target Features List
Measurement & attestation
Must provide trusted evidence about the state of the software running on the platform at boot and during run-time
Solution must be extensible to allow for application to various use-cases and types of evidence measurements agents (i.e. must be able to create rules and metrics to measure
vTPM and supporting infrastructure
Virtual trusted platform module that can be used to reflect changes within the software controlling the machine. Supporting infrastructure are services needed for the hardware to be properly used by the vTPM, which is already included in Xen
Introspection of running VMs using an integrity measurement agent
Detect changes in what’s expected in the VM; integrity violations in the Linux kernel (i.e. using LKIM
Newer Kernels
Need to base Xen on a longterm kernel
Upgrade Xen for security
UEFI support on host
64bit support on host and guest
A more controlled USB policy for increased security (patches have already been submitted)
Service VM build target (i.e. v4v, perhaps revive the NILFVM target)
Fix or replace NetworkManager
Complete the networks objects (VPN, wireless, wired) concept
Consider ConnMann as an alternative
Create the concept of user access and admin acces
Provide better support for vif hotplugging (can be provided with an upgrade of Xen)
System flexibility after build
Support changes to system configuration, updates to Xen, etc
Decomposition of Dom0
Graphics domain to improve the UI VM interface
Control domain to streamline/parallelize the chained VM boot/startup process
Enhanced full disk encryption
Multiple monitor support
Minimize dependency on CPU architecture