首页> 外文期刊>IEEE Transactions on Computers >Built-in Security Computer: Deploying Security-First Architecture Using Active Security Processor
【24h】

Built-in Security Computer: Deploying Security-First Architecture Using Active Security Processor

机译:内置安全计算机:使用主动安全处理器部署安全第一架构

获取原文
获取原文并翻译 | 示例

摘要

Continually disclosed vulnerabilities reveal that traditional computer architecture lacks the consideration of security. This article proposes a security-first architecture, with an Active Security Processor (ASP) integrated to conventional computer architectures. To reduce the attack surface of ASP and improve the security of the whole system, the ASP is physically isolated from Computation Processor Units (CPU) with an asymmetric address space, which enables both ASP and CPU to run their operating system and applications independently in their own memory space. Furthermore, the ASP, which has the highest privilege (Super Root) of the whole system, possesses two advantageous features. First, the ASP can efficiently access all CPU resources and collect multi-dimensional information to monitor malicious behaviors, meanwhile, the CPU cannot access the ASP's private resources in any way. Second, instead of being scheduled by CPUs, the ASP can actively manage the security mechanisms employed in either CPUs or the ASP. Based on the security-first architecture, we introduce several typical security tasks running on ASP. With different considerations in terms of system overhead, complexity and performance, we also explore four typical system-level implementations for integrating the ASP to the security-first architecture. The first-generation ASP was designed and implemented based on the 40nm technology, and a security computer system was implemented based on it. Evaluations on this real hardware platform demonstrate that the security-first architecture can protect the system effectively with minor performance impacts on computing workloads.
机译:持续披露的漏洞表明,传统的计算机架构缺乏对安全的考虑。本文提出了一种安全 - 第一架构,具有集成到传统计算机体系结构的活动安全处理器(ASP)。为了减少ASP的攻击表面并提高整个系统的安全性,ASP使用不对称的地址空间与计算处理器单元(CPU)物理隔离,这使得ASP和CPU能够独立地运行其操作系统和应用程序自己的记忆空间。此外,具有整个系统的最高特权(超级根)的ASP具有两个有利的特征。首先,ASP可以有效地访问所有CPU资源并收集多维信息以监控恶意行为,同时,CPU无法以任何方式访问ASP的私有资源。其次,而不是由CPU计划,ASP可以主动管理CPU或ASP中使用的安全机制。根据安全第一架构,我们在ASP上介绍了几个运行的典型安全任务。通过对系统开销,复杂性和性能方面的不同考虑,我们还探讨了四种典型的系统级实现,用于将ASP集成到安全第一架构。基于40nm技术设计和实现第一代ASP,并且基于它实现了安全计算机系统。对该实际硬件平台的评估表明,安全第一架构可以有效保护系统,对计算工作负载的次要性能影响有效。

著录项

  • 来源
    《IEEE Transactions on Computers》 |2020年第11期|1571-1583|共13页
  • 作者单位

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

    Chinese Acad Sci State Key Lab Informat Secur Inst Informat Engn Beijing 100049 Peoples R China|Univ Chinese Acad Sci Beijing 100049 Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Computer architecture; Task analysis; Central Processing Unit; Hardware; Computer security; Operating systems; Security-first architecture; active security processor; uni-directional physical isolation; asymmetric address space;

    机译:计算机架构;任务分析;中央处理单元;硬件;计算机安全;操作系统;安全第一架构;主动安全处理器;单向物理隔离;不对称地址空间;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号