Tiered trust for useful embedded systems security

Tiered trust for useful embedded systems security
复制标题

DOI:
10.1145/3517208.3523752
复制
发表时间:
2022-04
期刊:
Proceedings of the 15th European Workshop on Systems Security
影响因子:
--
通讯作者:
Hudson Ayers;P. Dutta;P. Levis;A. Levy;P. Pannuto;Johnathan Van Why;Jean-Luc Watson
Hudson Ayers;P. Dutta;P. Levis;A. Levy;P. Pannuto;Johnathan Van Why;Jean-Luc Watson
中科院分区:
其他
文献类型:
--
作者:
Hudson Ayers;P. Dutta;P. Levis;A. Levy;P. Pannuto;Johnathan Van Why;Jean-Luc Watson

文献摘要

相似文献

传统的嵌入式系统依赖于部署在单片固件映像中的定制C代码。在这些系统中,所有代码必须完全可信,因为任何代码都可以直接修改内存或硬件寄存器。最近,一些嵌入式操作系统通过使用内存保护单元(MPU)形式的强硬件隔离,将用户空间应用程序与内核分离,从而提高了安全性。不幸的是,这种设计要么需要包含所有操作系统服务的大型可信计算基础(TCB),要么需要将许多操作系统服务移到用户空间中。大型TCB方法对看似正确的后门代码没有提供保护,不鼓励使用其他人生成的内核代码,并使安全审计复杂化。用户空间中的操作系统服务是以可用性和效率为代价的。我们假设一个为内核代码提供两层信任的模型更适合现代嵌入式软件实践。本文基于这一思想,提出了Tock操作系统的威胁模型。我们将此威胁模型与现有的安全方法进行比较,并展示它如何为不同的涉众提供有用的保证。
Traditional embedded systems rely on custom C code deployed in a monolithic firmware image. In these systems, all code must be trusted completely, as any code can directly modify memory or hardware registers. More recently, some embedded OSes have improved security by separating userspace applications from the kernel, using strong hardware isolation in the form of a memory protection unit (MPU). Unfortunately, this design requires either a large trusted computing base (TCB) containing all OS services, or moving many OS services into userspace. The large TCB approach offers no protection against seemingly-correct backdoored code, discouraging the use of kernel code produced by others and complicating security audits. OS services in userspace come at a cost to usability and efficiency. We posit that a model enabling two tiers of trust for kernel code is better suited to modern embedded software practices. In this paper, we present the threat model of the Tock Operating System, which is based on this idea. We compare this threat model to existing security approaches, and show how it provides useful guarantees to different stakeholders.