首页> 外文会议>ACM SIGSAC Conference on Computer and Communications Security >Trusted Display on Untrusted Commodity Platforms
【24h】

Trusted Display on Untrusted Commodity Platforms

机译:不受信任的商品平台上的可信显示

获取原文

摘要

A trusted display service assures the confidentiality and authenticity of content output by a security-sensitive application and thus prevents a compromised commodity operating system or application from surreptitiously reading or modifying the displayed output. Past approaches have failed to provide trusted display on commodity platforms that use modern graphics processing units (GPUs). For example, full GPU virtualization encourages the sharing of GPU address space with multiple virtual machines without providing adequate hardware protection mechanisms; e.g., address-space separation and instruction execution control. This paper proposes a new trusted display service that has a minimal trusted code base and maintains full compatibility with commodity computing platforms. The service relies on a GPU separation kernel that (1) defines different types of GPU objects, (2) mediates access to security-sensitive objects, and (3) emulates object whenever required by commodity-platform compatibility. The separation kernel employs a new address-space separation mechanism that avoids the challenging problem of GPU instruction verification without adequate hardware support. The implementation of the trusted-display service has a code base that is two orders of magnitude smaller than other similar services, such as those based on full GPU virtualization. Performance measurements show that the trusted-display overhead added over and above that of the underlying trusted system is fairly modest.
机译:可信显示服务通过安全敏感应用程序确保内容输出的机密性和真实性,从而防止受损商品操作系统或应用程序免受偷偷摸摸地读取或修改所显示的输出。过去的方法未能在使用现代图形处理单元(GPU)的商品平台上提供可信赖的显示。例如,完整的GPU虚拟化鼓励使用多个虚拟机共享GPU地址空间,而无需提供足够的硬件保护机制;例如,地址空间分离和指令执行控制。本文提出了一种新的可信显示服务,具有最小的可信代码库,并与商品计算平台保持完全兼容性。该服务依赖于GPU分离内核,(1)定义不同类型的GPU对象,(2)调解对安全敏感对象的访问,(3)在商品平台兼容性需要时呈现对象。分离内核采用新的地址空间分离机制,避免了GPU指令验证的具有挑战性问题,而无需足够的硬件支持。可信显示服务的实现具有代码库,该代码库是比其他类似服务小的两个数量级,例如基于完整GPU虚拟化的数量级。性能测量表明,在基础值得信赖的系统中添加的可信显示开销是相当谦虚的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号