StreamBox-TZ: Secure Stream Analytics at the Edge with TrustZone

StreamBox-TZ: Secure Stream Analytics at the Edge with TrustZone
复制标题

DOI:
--
复制
发表时间:
2018-08
期刊:
--
影响因子:
--
通讯作者:
Heejin Park;Shuang Zhai;Long Lu;F. Lin
Heejin Park;Shuang Zhai;Long Lu;F. Lin
中科院分区:
其他
文献类型:
--
作者:
Heejin Park;Shuang Zhai;Long Lu;F. Lin

文献摘要

被引文献

相似文献

虽然令人信服地处理云边缘上的大量物联网数据流,但这样做将数据暴露于边缘上复杂,脆弱的软件堆栈,从而使安全威胁的威胁。为此,我们主张在边缘的受信任的执行环境(TEE)中隔离数据及其计算,从而使它们免受我们认为不信任的剩余边缘软件堆栈。这种方法面临两个主要挑战:(1)在单个TEE中执行高通量,低延迟流分析,该分析受到低信任的计算基础(TCB)和有限的物理内存的约束; (2)验证流动分析的执行,因为执行涉及边缘的不信任软件组件。作为响应,我们介绍了Edge Platform的Stream Analytics引擎Streambox-TZ(SBT),可提供强大的数据安全性,可验证的结果和良好的性能。 SBT为基于ARM Trustzone设计和优化的数据平面贡献了数据平面。它支持连续的远程证明,以实现分析的正确性和结果新鲜感,同时又产生了低落的开销。 SBT仅在TCB(整个TCB的16%)中添加42.5 kb。在Octa Core ARMV8平台上,它通过处理最高140 MB/sec(12m事件/秒)的输入事件以延迟延迟来提供最先进的性能。 SBT安全机制所产生的间接费用小于25%。
While it is compelling to process large streams of IoT data on the cloud edge, doing so exposes the data to a sophisticated, vulnerable software stack on the edge and hence security threats. To this end, we advocate isolating the data and its computations in a trusted execution environment (TEE) on the edge, shielding them from the remaining edge software stack which we deem untrusted. This approach faces two major challenges: (1) executing high-throughput, low-delay stream analytics in a single TEE, which is constrained by a low trusted computing base (TCB) and limited physical memory; (2) verifying execution of stream analytics as the execution involves untrusted software components on the edge. In response, we present StreamBox-TZ (SBT), a stream analytics engine for an edge platform that offers strong data security, verifiable results, and good performance. SBT contributes a data plane designed and optimized for a TEE based on ARM TrustZone. It supports continuous remote attestation for analytics correctness and result freshness while incurring low overhead. SBT only adds 42.5 KB executable to the TCB (16% of the entire TCB). On an octa core ARMv8 platform, it delivers the state-of-the-art performance by processing input events up to 140 MB/sec (12M events/sec) with sub-second delay. The overhead incurred by SBT's security mechanism is less than 25%.