InkTag: Secure Applications on an Untrusted Operating System.

InkTag: Secure Applications on an Untrusted Operating System.
复制标题

DOI:
10.1145/2451116.2451146
复制
发表时间:
2013
期刊:
ASPLOS ... proceedings. International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Witchel E
Witchel E
中科院分区:
其他
文献类型:
--
作者:
Hofmann OS;Kim S;Dunn AM;Lee MZ;Witchel E

文献摘要

被引文献

相似文献

InkTag是一种基于虚拟化的体系结构,即使在存在恶意操作系统的情况下,也可以为高保证流程提供强大的安全保证。在不受信任的操作系统中,InkTag在其管理程序的设计和无需信任操作系统即可运行有用应用程序的能力方面都取得了进步。我们介绍了一种通过强制不受信任的操作系统参与自己的验证来简化InkTag管理程序的技术。基于属性的访问控制允许受信任的应用程序创建分散的访问控制策略。InkTag也是同类系统中第一个确保安全数据和元数据之间一致性的系统,确保系统崩溃时的可恢复性。
InkTag is a virtualization-based architecture that gives strong safety guarantees to high-assurance processes even in the presence of a malicious operating system. InkTag advances the state of the art in untrusted operating systems in both the design of its hypervisor and in the ability to run useful applications without trusting the operating system. We introduce paraverification, a technique that simplifies the InkTag hypervisor by forcing the untrusted operating system to participate in its own verification. Attribute-based access control allows trusted applications to create decentralized access control policies. InkTag is also the first system of its kind to ensure consistency between secure data and metadata, ensuring recoverability in the face of system crashes.