EDK II Security White Papers - lersek/edk2 GitHub Wiki

A list of White Papers and information for EDK II Security from multiple sources

General:

EDK II Code:

Memory Protection:

SMM Protection:

SecureBoot/AuthVariable:

TrustedBoot/TPM2:

DMA: A Tour Beyond BIOS - Using IOMMU for DMA Protection in UEFI firmware (Oct 2017)

Capsule/Recovery: A Tour Beyond BIOS - Capsule Update and Recovery in EDK II (Dec 2016)

S3: A Tour Beyond BIOS - Implementing S3 Resume with EDK II (Oct 2015)

Profile: A Tour Beyond BIOS - Implementing Profiling in EDK_II (July 2016)

STM/VMM:

StandaloneMM: A Tour Beyond BIOS - Launching Standalone SMM Drivers in the PEI Phase using EDK II (May 2015)