CASU: Compromise Avoidance via Secure Update for Low-end Embedded Systems

CASU: Compromise Avoidance via Secure Update for Low-end Embedded Systems
复制标题

DOI:
10.1145/3508352.3549450
复制
发表时间:
2022-09
期刊:
2022 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
I. O. Nunes;Sashidhar Jakkamsetti;Youngil Kim;G. Tsudik
I. O. Nunes;Sashidhar Jakkamsetti;Youngil Kim;G. Tsudik
中科院分区:
其他
文献类型:
--
作者:
I. O. Nunes;Sashidhar Jakkamsetti;Youngil Kim;G. Tsudik

文献摘要

相似文献

保证嵌入式系统软件运行时的完整性是一个公开的问题。安全和其他优先事项之间的权衡(例如,成本或性能)是固有的,解决这些问题既具有挑战性又很重要。引入恶意代码的运行时攻击激增(例如,通过注入)到嵌入式器件中已经促使了一系列缓解技术。一种流行的方法是远程证明(Remote Attestation,简称VMA),可信实体(verifier)检查不可信远程设备(prover)的当前软件状态。现有的RA方案要求验证者基于一些不明确的准则显式地发起验证者身份验证,验证者可以根据验证者身份验证的结果来判断是否发生了攻击。因此,在证明者妥协的情况下,验证者仅在下一个实例时才知道它。虽然足以进行入侵检测,但一些应用程序将受益于更主动、基于预防的方法。为此,我们构建了CASU:通过安全更新避免损害。CASU是一种廉价的硬件/软件协同设计,执行:(i)运行时软件不变性,从而排除任何非法的软件修改,以及(ii)认证更新作为修改软件的唯一手段。在CASU中,一个成功的CAXA实例作为成功更新的证明,由于运行时不变性保证,连续的后续软件完整性是隐含的。这消除了在软件更新之间对CNOAA的需要,并导致不引人注目的完整性保证,其保证类似于先前的CNOAA技术,具有更好的整体性能。
Guaranteeing runtime integrity of embedded system software is an open problem. Trade-offs between security and other priorities (e.g., cost or performance) are inherent, and resolving them is both challenging and important. The proliferation of runtime attacks that introduce malicious code (e.g., by injection) into embedded devices has prompted a range of mitigation techniques. One popular approach is Remote Attestation (ℛA), whereby a trusted entity (verifier) checks the current software state of an untrusted remote device (prover). RA yields a timely authenticated snapshot of prover state that verifier uses to decide whether an attack occurred.Current RA schemes require verifier to explicitly initiate ℛA, based on some unclear criteria. Thus, in case of prover’s compromise, verifier only learns about it late, upon the next ℛA instance. While sufficient for compromise detection, some applications would benefit from a more proactive, prevention-based approach. To this end, we construct CASU: Compromise Avoidance via Secure Updates. CASU is an inexpensive hardware/software co-design enforcing: (i) runtime software immutability, thus precluding any illegal software modification, and (ii) authenticated updates as the sole means of modifying software. In CASU, a successful ℛA instance serves as a proof of successful update, and continuous subsequent software integrity is implicit, due to the runtime immutability guarantee. This obviates the need for ℛA in between software updates and leads to unobtrusive integrity assurance with guarantees akin to those of prior ℛA techniques, with better overall performance.