首页> 外文OA文献 >EmLog: Tamper-Resistant System Logging for Constrained Devices with TEEs
【2h】

EmLog: Tamper-Resistant System Logging for Constrained Devices with TEEs

机译:EmLog:具有TEE的受限设备的防篡改系统日志记录

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Remote mobile and embedded devices are used to deliver increasingly impactful services, such as medical rehabilitation and assistive technologies. Secure system logging is beneficial in these scenarios to aid audit and forensic investigations particularly if devices bring harm to end-users. Logs should be tamper-resistant in storage, during execution, and when retrieved by a trusted remote verifier. In recent years, Trusted Execution Environments (TEEs) have emerged as the go-to root of trust on constrained devices for isolated execution of sensitive applications. Existing TEE-based logging systems, however, focus largely on protecting server-side logs and offer little protection to constrained source devices. In this paper, we introduce EmLog – a tamper-resistant logging system for constrained devices using the GlobalPlatform TEE. EmLog provides protection against complex software adversaries and offers several additional security properties over past schemes. The system is evaluated across three log datasets using an off-the-shelf ARM development board running an open-source, GlobalPlatform-compliant TEE. On average, EmLog runs with low run-time memory overhead (1MB heap and stack), 430–625 logs/second throughput, and five-times persistent storage overhead versus unprotected logs.
机译:远程移动和嵌入式设备用于提供影响力越来越大的服务,例如医疗康复和辅助技术。在这些情况下,安全的系统日志记录很有用,有助于审计和法医调查,尤其是在设备对最终用户造成危害的情况下。日志在存储过程中,在执行过程中以及由受信任的远程验证者检索时,都应防篡改。近年来,受信任的执行环境(TEE)成为受约束设备上信任的根源,用于隔离执行敏感应用程序。但是,现有的基于TEE的日志记录系统主要集中于保护服务器端日志,而对受约束的源设备几乎没有提供保护。在本文中,我们介绍了EmLog –一种使用GlobalPlatform TEE的受限设备的防篡改记录系统。 EmLog提供了针对复杂软件对手的保护,并在过去的方案中提供了其他一些安全属性。使用运行开源,兼容GlobalPlatform的TEE的现成的ARM开发板,可以在三个日志数据集中评估该系统。平均而言,EmLog的运行时内存开销(1MB堆和堆栈)低,430-625日志/秒的吞吐量和五倍的持久性存储开销(不受保护的日志)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号