Inheriting Software Security Policies within Hardware IP Components

Inheriting Software Security Policies within Hardware IP Components
复制标题

在硬件 IP 组件中继承软件安全策略

DOI:
10.1109/fccm.2018.00017
复制
发表时间:
2018
期刊:
2018 IEEE 26th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM)
影响因子:
--
通讯作者:
C. Bobda
C. Bobda
中科院分区:
--
文献类型:
--
作者:
Festus Hategekimana;Joel Mandebi Mbongue;Md Jubaer Hossain Pantho;C. Bobda

文献摘要

被引文献

相似文献

域隔离实施是软件环境中具有挑战性的问题之一。为了解决这个问题,NSA与Secure Computing Corporation和犹他州大学合作,开发了开源Flux高级安全内核(Flask),这是一种强制访问控制(MAC)安全架构,广泛部署在云/桌面环境中的主要操作系统/虚拟机管理程序。在这项工作中,我们将这种安全架构扩展到基于FPGA的异构系统。具体来说,我们探讨了一个安全框架的设计和实施控制共享FPGA硬件模块在基于MAC的操作系统/虚拟机管理程序的环境。所提出的设计保证了硬件模块在与调用它们的进程相同的安全上下文中执行,这是通过将在软件级别表达的后者安全策略传播到硬件来实现的。我们原型所提出的框架与SELinux和演示其效用,通过评估安全性能和执行开销之间的权衡所产生的示例应用程序。初步结果表明,我们提出的框架提供了平均0.6%的最坏情况下的性能开销隔离。
Domain isolation enforcement is one of the challenging issues in software environments. To address this problem, NSA, in conjunction with the Secure Computing Corporation and the University of Utah, developed the open-source Flux Advanced Security Kernel (Flask), the mandatory access control (MAC) security architecture underlying major Operating Systems/Hypervisors widely deployed in cloud/desktop environments. In this work, we extend this security architecture to FPGA-based heterogeneous systems. Specifically, we explore the design and implementation of a security framework for controlled sharing of FPGA hardware modules in MAC-based OS/Hypervisor environments. The proposed design guarantees that hardware modules execute in the same security context as of the processes calling them by propagating the latter security policies expressed at the software level, down to the hardware. We prototype the proposed framework with SELinux and demonstrate its utility by evaluating trade-offs between security performance and execution overhead incurred by example applications. The preliminary results show our proposed framework provides isolation with an average of 0.6% worst case performance overhead.