首页> 外文会议>Design, Automation Test in Europe Conference Exhibition >ERASMUS: Efficient Remote Attestation via Self-Measurement for Unattended Settings
【24h】

ERASMUS: Efficient Remote Attestation via Self-Measurement for Unattended Settings

机译:Erasmus:通过自测量有效地证明无人值守的设置

获取原文

摘要

Remote attestation (RA) is a popular means of detecting malware in embedded and IoT devices. RA is usually realized as a protocol via which a trusted verifier measures software integrity of an untrusted remote device called prover. All prior RA techniques require on-demand operation. We identify two drawbacks of this approach in the context of unattended devices: First, it fails to detect mobile malware that enters and leaves the prover between successive RA instances. Second, it requires the prover to engage in a potentially expensive computation, which can negatively impact safety-critical or real-time devices. To this end, we introduce the concept of self-measurement whereby a prover periodically (and securely) measures and records its own software state. A verifier then collects and verifies these measurements. We demonstrate a concrete technique called ERASMUS, justify its features, and evaluate its performance. We show that ERASMUS is well-suited for safety-critical applications. We also define a new metric - Quality of Attestation (QoA).
机译:远程证明(RA)是一种嵌入式和IOT设备中的恶意软件的流行方法。 RA通常被实现为一个协议,可靠的验证者测量不受信用的远程设备的软件完整性,称为谚语。所有先前的RA技术都需要按需操作。我们在无人值守的设备的背景下识别出这种方法的两个缺点:首先,它无法检测到进入和离开连续的RA实例之间的手机恶意软件。其次,它要求箴言从事潜在昂贵的计算,这可能会对安全关键或实时设备产生负面影响。为此,我们介绍了自我测量的概念,在周期性地(并安全地)措施并记录其自己的软件状态。然后,验证器收集并验证这些测量。我们展示了一种称为erasmus的具体技术,证明其特征,评估其性能。我们表明Erasmus非常适合安全关键型应用。我们还定义了新的公制 - 质量的认证(Qoa)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号