首页> 外文会议>European Conference on Information Warfare and Security >Can Keys be Hidden Inside the CPU on Modern Windows Host
【24h】

Can Keys be Hidden Inside the CPU on Modern Windows Host

机译:可以在现代Windows主机上隐藏在CPU内的键

获取原文

摘要

The "Truly-Protect" trusted computing environment by Averbuch et al (2011) relies on encryption keys being hidden from external software and crackers. "Truly-Protect" saves the keys in internal registers inside the CPU. Such external keys should not be accessible by any software that runs on the machine prior to "Truly-Protect" validation or even after "Truly-Protect" validation. The assumption is that the hackers cannot reverse engineer the CPU and discover the content of these registers. But is it really possible to hide keys in such places? Internal CPU memory is indeed not available for user processes. However, the CPU memory and registers are accessible from the running operating system kernel. Truly protect uses a validation protocol that also verifies the Operating system kernel does not include malicious additions. These tests should ensure a cracker has not modified the OS. But Modern Windows operating system support loading new kernel code segments (drivers) even during the operating system runtime. Can we prevent modifying the kernel (loading drivers) after "Truly-protect" has verified the kernel? In this work we examine modern Intel CPUs available on desktop PCs and the latest releases of Microsoft Windows (windows 7,8) for existence of good hiding places for the encryption keys.
机译:Averbuch等人(2011)的“真正保护”可信计算环境依赖于从外部软件和饼干隐藏的加密密钥。 “真正的保护”将内部寄存器中的键保存在CPU内。在“真正保护”验证之前或甚至在“真正保护”验证之前,任何在机器上运行的软件都不应访问此类外部键。假设是黑客无法撤消CPU的工程并发现这些寄存器的内容。但它真的有可能隐藏这样的地方吗?内部CPU内存确实不适用于用户进程。但是,CPU存储器和寄存器可从运行的操作系统内核访问。真正的保护使用验证协议,该协议还验证操作系统内核不包括恶意添加。这些测试应确保饼干没有修改操作系统。但即使在操作系统运行时,现代Windows操作系统支持加载新的内核代码段(驱动程序)。我们可以在“真正保护”验证内核后防止修改内核(加载驱动程序)?在这项工作中,我们将在桌面PC上提供现代英特尔CPU,以及最新版本的Microsoft Windows(Windows 7,8),用于加密密钥的良好隐藏地点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号