首页> 外文会议>IEEE International Systems Conference >Using a Shared SGX Enclave in the UNIX PAM Authentication Service
【24h】

Using a Shared SGX Enclave in the UNIX PAM Authentication Service

机译:在UNIX PAM身份验证服务中使用共享SGX Chandave

获取原文

摘要

Confidentiality in the storage and handling of sensitive data is a central concern in computing security; one of the most sensitive data in computer systems is users’ credentials. To ensure the confidentiality and integrity of sensitive data, developers can use a Trusted Execution Environment (TEE). One of such TEE is Intel Software Guard Extensions (SGX), which reduces the trusted computing base to a hardware/software concept called enclave. However, using SGX enclaves usually incurs in a performance impact in the application execution. In this paper we propose an enclave sharing approach to reduce the performance overhead in scenarios where multiple enclaves handle the same data. To evaluate this approach, we implemented a SGX-secured OS authentication service. Three prototypes were built, considering distinct concerns about security and performance. Results show that this approach can be used in high demand environments, presenting a small overhead.
机译:在敏感数据存储和处理中的保密性是计算安全性的核心问题;计算机系统中最敏感的数据之一是用户的凭据。为确保敏感数据的机密性和完整性,开发人员可以使用可信任的执行环境(TEE)。此类T恤之一是英特尔软件保护扩展(SGX),其将可信计算库减少到名为Chancave的硬件/软件概念。但是,使用SGX CORMAVES通常会在应用程序执行中的性能影响中发生。在本文中,我们提出了一个环绕声共享方法,以减少在多个环绕声处理相同数据的情况下的性能开销。为了评估这种方法,我们实现了一个SGX安全操作系统认证服务。建立了三种原型,考虑到对安全性和性能不同的担忧。结果表明,这种方法可用于高需求环境,呈现小开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号