2026-09-24 –, GPN-T Main Room
This session presents a technical deep dive into integrating TrenchBoot on an Alder Lake-N platform using an open firmware stack.
We will examine the complete measured launch chain across coreboot, EDK II, the bootloader, Linux, and the TPM, with particular attention to the boundary between open-source components and silicon-vendor binary blobs. The talk will cover the platform-specific work required to enable DRTM, the measurements produced during launch, and the security guarantees that can realistically be achieved on modern x86 hardware.
A live demonstration will show a successful measured launch and remote attestation flow. We will then simulate an unauthorized change in the boot path and show how the resulting measurements expose the altered platform state.
The session is a practical implementation success story, showing that TrenchBoot can operate in a modern open source firmware stack while also highlighting the remaining dependencies on proprietary platform initialization.
Firmware Engineer @ 3mdeb; ~3 years in open source firmware, working mostly with coreboot and EDK2, LinuxBoot/Heads. Interested in Linux kernel development and audio processing.