CASU: Compromise Avoidance via Secure Update for Low-end Embedded Systems
CASU: Compromise Avoidance via Secure Update for Low-end Embedded Systems
复制标题
DOI:
10.1145/3508352.3549450
复制
发表时间:
2022-09
期刊:
影响因子:
--
通讯作者:
I. O. Nunes;Sashidhar Jakkamsetti;Youngil Kim;G. Tsudik
中科院分区:
文献类型:
--
作者:
I. O. Nunes;Sashidhar Jakkamsetti;Youngil Kim;G. Tsudik
Guaranteeing runtime integrity of embedded system software is an open problem. Trade-offs between security and other priorities (e.g., cost or performance) are inherent, and resolving them is both challenging and important. The proliferation of runtime attacks that introduce malicious code (e.g., by injection) into embedded devices has prompted a range of mitigation techniques. One popular approach is Remote Attestation (ℛA), whereby a trusted entity (verifier) checks the current software state of an untrusted remote device (prover). RA yields a timely authenticated snapshot of prover state that verifier uses to decide whether an attack occurred.Current RA schemes require verifier to explicitly initiate ℛA, based on some unclear criteria. Thus, in case of prover’s compromise, verifier only learns about it late, upon the next ℛA instance. While sufficient for compromise detection, some applications would benefit from a more proactive, prevention-based approach. To this end, we construct CASU: Compromise Avoidance via Secure Updates. CASU is an inexpensive hardware/software co-design enforcing: (i) runtime software immutability, thus precluding any illegal software modification, and (ii) authenticated updates as the sole means of modifying software. In CASU, a successful ℛA instance serves as a proof of successful update, and continuous subsequent software integrity is implicit, due to the runtime immutability guarantee. This obviates the need for ℛA in between software updates and leads to unobtrusive integrity assurance with guarantees akin to those of prior ℛA techniques, with better overall performance.