首页> 外文会议>Proceedings of the Twenty-Third ACM symposium on operating systems principles. >Logical Attestation: An Authorization Architecture for Trustworthy Computing
【24h】

Logical Attestation: An Authorization Architecture for Trustworthy Computing

机译:逻辑证明:可信计算的授权架构

获取原文
获取原文并翻译 | 示例

摘要

This paper describes the design and implementation of a new operating system authorization architecture to support trustworthy computing. Called logical attestation, this architecture provides a sound framework for reasoning about run time behavior of applications. Logical attestation is based on attributable, unforgeable statements about program properties, expressed in a logic. These statements are suitable for mechanical processing, proof construction, and verification; they can serve as credentials, support authorization based on expressive authorization policies, and enable remote principals to trust software components without restricting the local user's choice of binary implementations. We have implemented logical attestation in a new operating system called the Nexus. The Nexus executes natively on x86 platforms equipped with secure coprocessors. It supports both native Linux applications and uses logical attestation to support new trustworthy-computing applications. When deployed on a trustworthy cloud-computing stack, logical attestation is efficient, achieves high-performance, and can run applications that provide qualitative guarantees not possible with existing modes of attestation.
机译:本文介绍了一种新的操作系统授权体系结构的设计和实现,以支持可信赖的计算。这种架构称为逻辑证明,为推理应用程序的运行时行为提供了一个合理的框架。逻辑证明基于以逻辑表示的关于程序属性的可归因的,不可伪造的陈述。这些陈述适用于机械加工,证明构造和验证;它们可以用作凭据,基于表达授权策略支持授权,并允许远程主体信任软件组件,而不会限制本地用户对二进制实现的选择。我们已经在称为Nexus的新操作系统中实现了逻辑证明。 Nexus在配备安全协处理器的x86平台上本地执行。它支持本机Linux应用程序,并使用逻辑证明来支持新的可信赖计算应用程序。当部署在可信赖的云计算堆栈上时,逻辑证明是高效的,可实现高性能的,并且可以运行提供现有证明模式无法提供定性保证的应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号