首页> 外文会议>International Conference on Formal Engineering Methods >Formal Foundations for Intel SGX Data Center Attestation Primitives
【24h】

Formal Foundations for Intel SGX Data Center Attestation Primitives

机译:英特尔SGX数据中心证明原语的正式基础

获取原文

摘要

Intel has recently offered third-party attestation services, called Data Center Attestation Primitives (DCAP), for a data center to create its own attestation infrastructure. These services address the availability concerns and improve the performance as compared to the remote attestation based on Enhanced Privacy ID (EPID). Practical developments, such as Hyperledger Avalon, have already planned to support DCAP in their roadmap. However, the lack of formal proof for DCAP leads to security concerns. To fill this gap, we propose an automated, rigorous, and sound formal approach to specify and verify the remote attestation based on Intel SGX DCAP under the assumption that there are no side-channel attacks and no vulnerabilities inside the enclave. In the proposed approach, the data center configuration and operational policies are specified to generate the symbolic model, and security goals are specified as security properties to produce verification results. The evaluation of non-Quoting Verification Enclave-based DCAP indicates that the confidentiality of secrets and integrity of data is preserved against a Dolev-Yao adversary in this technology. We also present a few of the many inconsistencies found in the existing literature on Intel SGX DCAP during formal specification.
机译:英特尔最近提供了第三方认证服务,称为数据中心证明原语(DCAP),用于数据中心,以创建其自己的证明基础架构。与基于增强的隐私ID(EPID)相比,这些服务解决了可用性问题并提高了性能。已经计划在他们的路线图中支持DCAP的实际发展。但是,缺乏正式证明DCAP会导致安全问题。为了填补这一差距,我们提出了一种自动化,严谨和声音的正式方法来指定和验证基于Intel SGX DCAP的远程证明,假设没有侧通道攻击,并且在飞程内没有漏洞。在所提出的方法中,指定数据中心配置和操作策略以生成符号模型,并且将安全性目标指定为生成验证结果的安全性。基于非引用验证的DCAP的评估表明,在这项技术中的Dolev-Yao对手中保留了秘密和数据的完整性的机密性。在正式规范期间,我们还提出了在英特尔SGX DCAP上现有文献中的许多不一致。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号