首页> 外文会议>IEEE International Symposium on Network Computing and Applications >Leveraging Intel SGX Technology to Protect Security-Sensitive Applications
【24h】

Leveraging Intel SGX Technology to Protect Security-Sensitive Applications

机译:利用英特尔SGX技术来保护安全敏感应用

获取原文

摘要

This paper explains the process by which Intel Software Guard Extensions (SGX) can be leveraged into an existing codebase to protect a security-sensitive application. Intel SGX provides user-level applications with hardware-enforced confidentiality and integrity protections and incurs manageable impact on performance. These protections apply to all three phases of the operational data lifecycle: at rest, in use, and in transit. SGX shrinks the trusted computing base (and therefore the attack surface) of the application to only the hardware on the CPU chip and the portion of the application's software that is executed within the protected enclave. The SDK enables SGX integration into existing C/C++ codebases while still ensuring program support for legacy and non-Intel platforms. This paper is the first published work to walk through the step-by-step process of Intel SGX integration with examples and performance results from an actual cryptographic application produced in a standard Linux development environment.
机译:本文介绍了英特尔软件保护扩展扩展(SGX)的过程可以将其利用到现有的代码库中以保护安全敏感应用程序。 Intel SGX提供具有硬件强制机密性和完整性保护的用户级应用程序,并招收可管理的对性能的影响。这些保护适用于运营数据生命周期的所有三个阶段:在休息,在使用中和运输中。 SGX将应用程序的可信计算库(以及因此攻击面)缩小到仅在CPU芯片上的硬件以及应用程序的软件的部分在受保护的外壳中执行的。 SDK使SGX集成到现有的C / C ++ CodeBases中,同时仍然确保对遗留和非英特尔平台的程序支持。本文是第一次通过Intel SGX集成的逐步处理与标准Linux开发环境中产生的实际加密应用程序的实际加密应用程序进行的发布工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号