Documentary historical research2026 · Research in progress

A history of security enforced by hardware

From supervisor modes and protected memory to attestation, trusted execution, and the microarchitectural states that now carry authority and evidence.

01

Argument

Distributed enforcement fabric

Modern platform security does not reside in a single privileged block. It emerges from components that must coordinate names, authority, evidence, derived state, and revocation.
Author’s interpretation

Distributed enforcement fabric is an analytical synthesis, not a historical term used by the sources. It describes the topology of dependencies that collectively enforces a guarantee.

02

Genealogy

The boundary did not advance in a straight line

Each period made a different actor or state explicit. The sequence is comparative—not a claim of linear progress.

011960s

Privilege & memory

Atlas · System/360 · Burroughs · Multics

Made visible

CPU authority and protected address spaces

Left outside

Devices and derived translation state

[10]–[16]
021980s

Compatibility under control

Intel 80286 · 80386

Made visible

Legacy execution as a managed domain

Left outside

Platform-wide device mediation

[17], [18]
032000s

The boundary reaches devices

Xen · Linux · Intel VT-d

Made visible

DMA initiators as architectural principals

Left outside

Coherent revocation across cached state

[19], [20]
042000s

Boot produces evidence

TCG · TPM · Linux IMA

Made visible

Platform history as evidence for another actor

Left outside

The verifier’s policy and interpretation

[21], [22]
052010s

Privilege moves outside

Intel SGX · TEEs

Made visible

Protected execution despite a privileged OS

Left outside

I/O, availability, and microarchitecture

[23], [24]
062018→

Internal history becomes observable

Spectre · Meltdown

Made visible

Caches and predictors as carriers of secrets

Left outside

Transient effects beyond architectural rollback

[28]–[32]

Process-traced episodes

Three mechanisms of historical change

ACompatibility

x86 protected mode

Protection coexisted with real mode, making transitions and legacy execution part of the boundary.

BCoordination

IOMMU integration

Isolation crossed CPU, chipset, firmware, hypervisor, kernel, interrupts, and cached translations.

CEvidence

TCG to Linux IMA

Standards, registers, kernel measurement, and remote interpretation turned history into assessable evidence.

03

Framework

Distributed enforcement fabric

A guarantee emerges across components when observation is divided, authority must be translated, and state coordinated over time.

Figure 01

Conceptual model. Nodes show dependencies across enforcement and interpretation.

01

Name

What can receive authority?

ring · page · device · enclave
02

Mediate

Which path must an operation cross?

instruction · translation · interconnect
03

Measure

What evidence is produced?

digest · counter · challenge
04

Remember

What history sustains the guarantee?

TLB · IOTLB · cache · PCR
05

Erase

How does authority end?

invalidation · revocation · zeroization

Limits

What the framework does not claim

  • It is not a universal ontology of security.
  • It does not reduce hardware security to cryptography.
  • It does not treat technical change as linear progress.
  • It does not claim that hardware alone creates trust.
04

Sources

Begin with the documents

A selected path through the primary corpus. The complete manuscript uses 35 references and a structured claim-to-source register.

Method & traceability

Documentary evidence, explicit inference

The study compares manuals, original papers, standards, operating-system documentation, and historical analyses. It reports no practical experiments.

35
manuscript references
28
audited claims
8
mechanism families
05

About

Federico Pacheco