首页> 外文会议>Trusted systems >Scalable Remote Attestation with Privacy Protection (Work in Progress)
【24h】

Scalable Remote Attestation with Privacy Protection (Work in Progress)

机译:具有隐私保护功能的可扩展远程证明(正在进行中)

获取原文
获取原文并翻译 | 示例

摘要

Assurance of fulfillment of stakeholder's expectations on a target platform is termed as remote attestation. Without such an assurance, there is no way of knowing whether the policies of the remote owner will be enforced as expected. Existing approaches toward remote attestation work at different levels of the software stack and most of them only measure binary hashes of the applications on the remote platform. Several dynamic attestation techniques have been proposed that aim to measure the internal working of an application. As there can be more than one application running on a target system, we need to have mechanisms to remotely certify the internal behavior of multiple applications on a single system. Similarly in TCG-based attestations we use Platform Configuration Register (PCR) for storing and advocating the platform configuration to the remote party. Currently a single PCR is used to capture the behavior of one application/purpose. In this paper we propose the idea of using a single PCR for multiple instances of a target application, while preserving the privacy of other application instances. Moreover, our technique also keeps the trusted status of each application intact. We propose a protocol for measurement and verification of a single instance by its respective stakeholder. Further, the mechanism proposed in this paper can be applied to different attestation techniques that work at different levels of the software stack. We develop a proof-of-concept implementation of our idea and provide future implications of this research.
机译:确保在目标平台上实现利益相关者的期望被称为远程证明。没有这样的保证,就无法知道远程所有者的策略是否将按预期执行。现有的远程认证方法在软件堆栈的不同级别上起作用,并且大多数方法仅测量远程平台上应用程序的二进制哈希值。已经提出了几种动态证明技术,旨在衡量应用程序的内部工作。由于在目标系统上运行的应用程序可能不止一个,因此我们需要具有一种机制来远程认证单个系统上多个应用程序的内部行为。同样,在基于TCG的证明中,我们使用平台配置寄存器(PCR)来存储平台配置并将其提倡给远程方。当前,单个PCR用于捕获一个应用程序/用途的行为。在本文中,我们提出了对目标应用程序的多个实例使用单个PCR的想法,同时保留了其他应用程序实例的隐私。而且,我们的技术还可以保持每个应用程序的可信状态不变。我们提出了一个协议,用于由其各自的利益相关者衡量和验证单个实例。此外,本文提出的机制可以应用于在软件堆栈的不同级别工作的不同证明技术。我们开发了我们的想法的概念验证实现,并提供了该研究的未来启示。

著录项

  • 来源
    《Trusted systems》|2009年|p.73-87|共15页
  • 会议地点 Beijing(CN);Beijing(CN)
  • 作者单位

    Security Engineering Research Group,Institute of Management Sciences, Peshawar, Pakistan;

    Security Engineering Research Group,Institute of Management Sciences, Peshawar, Pakistan;

    Security Engineering Research Group,Institute of Management Sciences, Peshawar, Pakistan;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 计算技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号