论文标题

Synergia:使用机密和值得信赖的计算来硬化高保险安全系统

Synergia: Hardening High-Assurance Security Systems with Confidential and Trusted Computing

论文作者

Ozga, Wojciech, Faqeh, Rasha, Quoc, Do Le, Gregor, Franz, Dragone, Silvio, Fetzer, Christof

论文摘要

高保险安全系统需要与不受信任的世界有很大的隔离,以保护对安全敏感或对隐私敏感的数据的处理。现有法规强加了此类系统必须在值得信赖的操作系统(OS)中执行,以确保它们不会与可能对其可用性或安全性产生负面影响的不信任软件相处。但是,由于杜鹃攻击,现有的技术证明OS完整性的技术缺乏。在本文中,我们首先展示了针对杜鹃袭击的新型防御机制,我们正式证明了这一点。然后,我们将其作为完整性监视和执行框架的一部分实现,该框架证明了OS的可信度比现有完整性监视系统快3.7倍至8.5倍。我们通过保护执行现实世界中的eHealth应用程序,执行微基准和宏观基准并评估安全风险来证明其实用性。

High-assurance security systems require strong isolation from the untrusted world to protect the security-sensitive or privacy-sensitive data they process. Existing regulations impose that such systems must execute in a trustworthy operating system (OS) to ensure they are not collocated with untrusted software that might negatively impact their availability or security. However, the existing techniques to attest to the OS integrity fall short due to the cuckoo attack. In this paper, we first show a novel defense mechanism against the cuckoo attack, and we formally prove it. Then, we implement it as part of an integrity monitoring and enforcement framework that attests to the trustworthiness of the OS from 3.7x to 8.5x faster than the existing integrity monitoring systems. We demonstrate its practicality by protecting the execution of a real-world eHealth application, performing micro and macro-benchmarks, and assessing the security risk.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源