首页> 外文会议>Trusted systems >External Authenticated Non-volatile Memory with Lifecycle Management for State Protection in Trusted Computing
【24h】

External Authenticated Non-volatile Memory with Lifecycle Management for State Protection in Trusted Computing

机译:具有生命周期管理的外部认证非易失性存储器,可用于可信计算中的状态保护

获取原文
获取原文并翻译 | 示例

摘要

Contemporary processor ASICs for embedded devices often include a trusted execution environment (TrEE) typically realized using a secure, isolated processing mode. TrEEs are used for implementing security services. The isolation can be complete with on-board RAM and ROM reserved for the exclusive use of these environments, but ASICs that also include non-volatile memory (NVM) are not readily available or cost-effective. This makes it difficult to deploy security services where persistent storage of state is critical to security. One solution is to use external authenticated non-volatile memory (EANVM), e.g. in a different ASIC. This introduces the need for a key management scheme for pairing and secure communication between the processor and the EANVM unit. Design of such a key management scheme needs to allow for lifecycle management requirements such as field-replacement of EANVM units and testability, both of newly fabricated as well as field-returned units. In this paper we identify the requirements for lifecycle management of an EANVM which can be used by a TrEE for securing its state persistently. We then present a hardware design that meets both the usual security requirements as well as the lifecycle management requirements simultaneously. Although the design can constitute its own chip, it is intended to be added to a secondary ASIC on the device, one that already has NVM for other reasons (e.g. to store configuration parameters persistently), but has a few tens of NVM cells to spare for this design. Consequently, our design offers an inexpensive way for state protection for TrEEs.
机译:用于嵌入式设备的当代处理器ASIC通常包括通常使用安全的隔离处理模式实现的可信执行环境(TrEE)。 TrEE用于实现安全服务。通过专用于这些环境的板上RAM和ROM可以完成隔离,但是还包括非易失性存储器(NVM)的ASIC尚不容易获得或具有成本效益。这使得在状态的持久存储对安全至关重要的地方,难以部署安全服务。一种解决方案是使用外部认证的非易失性存储器(EANVM),例如。在不同的ASIC中。这引入了对用于处理器与EANVM单元之间的配对和安全通信的密钥管理方案的需求。这种密钥管理方案的设计需要考虑到生命周期管理要求,例如新制造的和现场退回的单元的EANVM单元的现场更换和可测试性。在本文中,我们确定了EANEE的生命周期管理要求,TrEE可以使用这些要求来持久地保护其状态。然后,我们提出一种既可以满足通常的安全要求又可以满足生命周期管理要求的硬件设计。尽管该设计可以构成其自己的芯片,但它打算被添加到设备上的辅助ASIC上,该辅助ASIC由于其他原因(例如,永久存储配置参数)已经具有NVM,但是有几十个NVM单元可用于备用对于这种设计。因此,我们的设计为TrEE的状态保护提供了一种廉价的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号