Minimizing a Smartphone's TCB for Security-Critical Programs with Exclusively-Used, Physically-Isolated, Statically-Partitioned Hardware

Minimizing a Smartphone's TCB for Security-Critical Programs with Exclusively-Used, Physically-Isolated, Statically-Partitioned Hardware
复制标题

DOI:
10.1145/3581791.3596864
复制
发表时间:
2023-06
期刊:
Proceedings of the 21st Annual International Conference on Mobile Systems, Applications and Services
影响因子:
--
通讯作者:
Zhihao Yao;Seyed Mohammadjavad Seyed Talebi-Seyed-Mohammadjavad-Seyed-Talebi-2220160600;M. Chen;Ardalan Amiri Sani;T. Anderson
Zhihao Yao;Seyed Mohammadjavad Seyed Talebi-Seyed-Mohammadjavad-Seyed-Talebi-2220160600;M. Chen;Ardalan Amiri Sani;T. Anderson
中科院分区:
其他
文献类型:
--
作者:
Zhihao Yao;Seyed Mohammadjavad Seyed Talebi-Seyed-Mohammadjavad-Seyed-Talebi-2220160600;M. Chen;Ardalan Amiri Sani;T. Anderson

文献摘要

相似文献

智能手机所有者通常需要与其他不受信任和潜在恶意程序同一设备上运行关键安全程序。这要求用户信任硬件和系统软件,以正确地使用沙盒恶意程序,这通常放错了位置。我们的目标是最大程度地减少智能手机所有者需要信任的硬件和软件组件的数量和复杂性。我们提出了由静态分配,物理分离的信任域组成的拆分信任硬件设计。我们介绍了一些简单的,正式验证的硬件组件,以使程序能够临时获得可证明的独家且同时访问计算和I/O。为了管理这个硬件,我们提出了章鱼,该操作系统由相互不信任的子系统组成。我们在CPU-FPGA板上介绍了该机器(硬件和操作系统)的原型,并表明与现代智能手机SoC相比,它会产生小型硬件成本。对于关键安全计划,我们表明,与主流TEE相比,这台机器在实现可用性能的同时大大降低了所需的信任。对于普通程序,性能类似于传统机器。
Smartphone owners often need to run security-critical programs on the same device as other untrusted and potentially malicious programs. This requires users to trust hardware and system software to correctly sandbox malicious programs, trust that is often misplaced. Our goal is to minimize the number and complexity of hardware and software components that a smartphone owner needs to trust. We present a split-trust hardware design composed of statically-partitioned, physically-isolated trust domains. We introduce a few simple, formally-verified hardware components to enable a program to gain provably exclusive and simultaneous access to both computation and I/O on a temporary basis. To manage this hardware, we present OctopOS, an OS composed of mutually distrustful subsystems. We present a prototype of this machine (hardware and OS) on a CPU-FPGA board and show that it incurs a small hardware cost compared to modern smartphone SoCs. For security-critical programs, we show that this machine significantly reduces the required trust compared to mainstream TEEs while achieving usable performance. For normal programs, performance is similar to a legacy machine.