【24h】

Authentication Control Point and Its Implications For Secure Processor Design

机译:身份验证控制点及其对安全处理器设计的启示

获取原文

摘要

Secure processor architecture enables tamper-proof protec- tion on software that addresses many dificult security prob- lems such as reverse-engineering prevention, trusted com- puting, secure mobile agents by providing a secure comput- ing environment that is resistant to both physical tamper- ing and software exploits. Two essential features offered by a secure processor are software encryption for protect- ing software privacy and integrity verification for prevent- ing tampering of the protected software. Despite a number of secure processor designs have been proposed, the delicate relationship between privacy and integrity protection in the context of modern out-of-order processor design is not well understood. This paper aims to remedy this research deficiency by evaluatingdifferent designs that integrate soft- ware decryption and integrity verification into an out-of- order pipeline. Our paper provides an in-depth analysis of the security and performance trade-offs, implications of sev- eral designs in the context of memory fetch side-channel ex- ploits. Among the evaluated spectrum of design alternatives are (1) authentication-then-issue, (2) authentication-then- commit, (3) authentication-then-write, (4) authentication- then-fetch, and (5) authentication-then-commit + address obfuscation. Performance of various designs was evaluated using a cycle based processor model and SPEC 2000 bench- mark suite.
机译:安全的处理器体系结构可通过提供可抵御两种物理篡改的安全计算环境,对解决许多困难的安全问题的软件提供防篡改保护,这些问题包括逆向工程预防,可信赖的计算,安全的移动代理。 -软件开发。安全处理器提供的两个基本功能是用于保护软件隐私的软件加密和用于防止篡改受保护软件的完整性验证。尽管已经提出了许多安全的处理器设计,但是在现代无序处理器设计的背景下,隐私和完整性保护之间的微妙关系还没有得到很好的理解。本文旨在通过评估将软件解密和完整性验证集成到无序流水线中的不同设计来弥补这一研究不足。我们的论文对安全性和性能之间的折衷进行了深入分析,这是在存储器获取侧通道证书的情况下几种设计的含义。设计备选方案的评估范围包括(1)身份验证然后发出,(2)身份验证然后提交,(3)身份验证然后写入,(4)身份验证然后提取以及(5)身份验证然后提交+地址混淆。使用基于周期的处理器模型和SPEC 2000基准套件评估了各种设计的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号