首页> 外文会议>International Conference on Trust and Trustworthy Computing >Lockdown: Towards a Safe and Practical Architecture for Security Applications on Commodity Platforms
【24h】

Lockdown: Towards a Safe and Practical Architecture for Security Applications on Commodity Platforms

机译:锁定:用于在商品平台上的安全应用程序安全和实用的架构

获取原文

摘要

We investigate a new point in the design space of red/green systems [19,30], which provide the user with a highly-protected, yet also highly-constrained trusted ("green") environment for performing security-sensitive transactions, as well as a high-performance, general-purpose environment for all other (non-security-sensitive or "red") applications. Through the design and implementation of the Lockdown architecture, we evaluate whether partitioning, rather than virtualizing, resources and devices can lead to better security or performance for red/green systems. We also design a simple external interface to allow the user to securely learn which environment is active and easily switch between them. We find that partitioning offers a new tradeoff between security, performance, and usability. On the one hand, partitioning can improve the security of the "green" environment and the performance of the "red" environment (as compared with a virtualized solution). On the other hand, with current systems, partitioning makes switching between environments quite slow (13-31 seconds), which may prove intolerable to users.
机译:我们调查了红色/绿色系统的设计空间中的一个新点[19,30],它为用户提供了高度保护的,而且也是高度约束的信任(“绿色”)环境,用于执行安全敏感事务,如以及所有其他(非安全敏感或“红色”)应用的高性能,通用环境。通过锁定架构的设计和实现,我们评估是否分区,而不是虚拟化,资源和设备可以导致红色/绿色系统更好的安全性或性能。我们还设计了一个简单的外部接口,以允许用户安全地了解哪些环境处于活动状态,并且在它们之间轻松切换。我们发现分区提供安全,性能和可用性之间的新权衡。一方面,分区可以提高“绿色”环境的安全性和“红色”环境的性能(与虚拟化解决方案相比)。另一方面,使用当前系统,分区使环境之间的切换非常慢(13-31秒),这可能证明用户无法忍受。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号