首页> 外文会议>International conference on trust and trustworthy computing >Lockdown: Towards a Safe and Practical Architecture for Security Applications on Commodity Platforms
【24h】

Lockdown: Towards a Safe and Practical Architecture for Security Applications on Commodity Platforms

机译:锁定:为商品平台上的安全应用程序开发一种安全实用的体系结构

获取原文

摘要

We investigate a new point in the design space of red/green systems [19,30], which provide the user with a highly-protected, yet also highly-constrained trusted ("green") environment for performing security-sensitive transactions, as well as a high-performance, general-purpose environment for all other (non-security-sensitive or "red") applications. Through the design and implementation of the Lockdown architecture, we evaluate whether partitioning, rather than virtualizing, resources and devices can lead to better security or performance for red/green systems. We also design a simple external interface to allow the user to securely learn which environment is active and easily switch between them. We find that partitioning offers a new tradeoff between security, performance, and usability. On the one hand, partitioning can improve the security of the "green" environment and the performance of the "red" environment (as compared with a virtualized solution). On the other hand, with current systems, partitioning makes switching between environments quite slow (13-31 seconds), which may prove intolerable to users.
机译:我们研究了红色/绿色系统[19,30]的设计空间中的一个新点,该系统为用户提供了一个高度受保护的,同时也是高度受限的受信任(“绿色”)环境,用于执行对安全敏感的事务,例如以及适用于所有其他(非安全敏感或“红色”)应用程序的高性能通用环境。通过Lockdown体系结构的设计和实现,我们评估对资源和设备进行分区(而不是虚拟化)是否可以为红/绿系统带来更好的安全性或性能。我们还设计了一个简单的外部接口,使用户可以安全地了解哪个环境处于活动状态,并可以在它们之间轻松切换。我们发现分区在安全性,性能和可用性之间提供了新的权衡。一方面,与虚拟化解决方案相比,分区可以提高“绿色”环境的安全性和“红色”环境的性能。另一方面,在当前系统中,分区使环境之间的切换非常慢(13-31秒),这可能对用户来说是无法忍受的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号