Running Language Interpreters Inside SGX: A Lightweight,Legacy-Compatible Script Code Hardening Approach

Running Language Interpreters Inside SGX: A Lightweight,Legacy-Compatible Script Code Hardening Approach
复制标题

DOI:
10.1145/3321705.3329848
复制
发表时间:
2019-07
期刊:
Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang
Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang

文献摘要

被引文献

相似文献

可信执行环境的最新进展,特别是英特尔在消费类处理器上推出SGX,为使用小型TCB创建安全应用提供了前所未有的机会。虽然已经提出了大量的SGX解决方案,但几乎所有的解决方案都专注于保护本地代码应用程序,使脚本语言不受保护。为了填补这一空白,本文提出了一个框架,能够运行遗留脚本代码,同时提供机密性和完整性的脚本代码和数据。与需要繁琐且耗时的重新开发或通过导入整个库OS或容器而导致大TCB的现有方案相比,EMTSHIELD保持TCB小并提供向后兼容性(即,不需要改变脚本代码本身)。核心思想是自定义脚本解释器,使其在SGX enclave内运行并向其传递脚本。我们已经实现了JavaScript SHIELD,并使用三种流行的脚本语言进行了测试:Lua,JavaScript和Squirrel。我们的实验结果表明,SHIELD不会引起明显的开销。ESTSHIELD的源代码已经作为一个开源项目公开提供。
Recent advances in trusted execution environments, specifically with Intel's introduction of SGX on consumer processors, have provided unprecedented opportunities to create secure applications with a small TCB. While a large number of SGX solutions have been proposed, nearly all of them focus on protecting native code applications, leaving scripting languages unprotected. To fill this gap, this paper presents SCRIPTSHIELD, a framework capable of running legacy script code while simultaneously providing confidentiality and integrity for scripting code and data. In contrast to the existing schemes that either require tedious and time-consuming re-development or result in a large TCB by importing an entire library OS or container, SCRIPTSHIELD keeps the TCB small and provides backwards compatibility (i.e., no changes needed to the scripting code itself). The core idea is to customize the script interpreter to run inside an SGX enclave and pass scripts to it. We have implemented SCRIPTSHIELD and tested with three popular scripting languages: Lua, JavaScript, and Squirrel. Our experimental results show that SCRIPTSHIELD does not cause noticeable overhead. The source code of SCRIPTSHIELD has been made publicly available as an open source project.