首页> 外文期刊>Cloud Computing, IEEE Transactions on >Architectural Protection of Trusted System Services for SGX Enclaves in Cloud Computing
【24h】

Architectural Protection of Trusted System Services for SGX Enclaves in Cloud Computing

机译:云计算中SGX受信任系统服务的架构保护

获取原文
获取原文并翻译 | 示例
           

摘要

Data security and privacy are of great concern for users of cloud computing. In order to provide such guarantees in public clouds, hardware manufacturers have designed trusted execution environments such as Intel's Software Guard eXtensions (SGX). Intel SGX supports privacy-preserving, tamper-proof containments called enclaves. Regrettably, an SGX enclave has to rely on the untrusted operating system or hypervisor for underlying services, which contradicts the threat model of Intel SGX. Whereas much of the previous work concentrates on protecting trusted applications by means of modifying a hypervisor, we tackle the problem by reusing existing drivers and leveraging processor-enforced protection. We propose a novel approach, named SMK, to provide trusted system services for SGX enclaves. SMK leverages existing Intel architecture features, i.e., System Management Mode (SMM) and Uniform Extensible Firmware Interface (UEFI). Specifically, we retrofit UEFI firmware and design an isolated micro-kernel inside SMM to securely provision critical system services for enclaves. To highlight the effectiveness and extensibility of SMK, we implement two system services: trusted clock and trusted network. Furthermore, we harden two real-world security-sensitive applications, OpenSSL and OpenVPN, with SMK's system services. Our evaluation indicates that SMK can supply trusted system services for enclaves with modest runtime overheads.
机译:数据安全性和隐私对云计算用户非常关注。为了在公共云中提供此类保证,硬件制造商已经设计了可信任的执行环境,例如英特尔的软件保护扩展(SGX)。 Intel SGX支持隐私保留,防篡改遏制措施,称为COMMAVES。令人遗憾的是,一个SGX飞地必须依赖于不受信任的操作系统或管理程序的基础服务,这与英特尔SGX的威胁模型相矛盾。而以前的大部分工作专注于通过修改虚拟机管理程序保护可信应用,而我们通过重用现有驱动程序并利用处理器强制保护来解决问题。我们提出了一种名为SMK的新方法,为SGX环路提供可信系统服务。 SMK利用现有的英特尔架构功能,即系统管理模式(SMM)和均匀可扩展固件接口(UEFI)。具体而言,我们改造了UEFI固件并设计了SMM内的孤立的微内核,以安全地为环路提供关键系统服务。为了突出SMK的有效性和可扩展性,我们实施了两个系统服务:可信时钟和可信网络。此外,我们强化了两个现实世界的安全敏感应用程序,OpenSSL和OpenVPN,SMK的系统服务。我们的评估表明,SMK可以为具有适度运行时间开销的地管提供可信系统服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号