Hardware-assisted Remote Runtime Attestation for Critical Embedded Systems

Hardware-assisted Remote Runtime Attestation for Critical Embedded Systems
复制标题

DOI:
10.1109/pst47121.2019.8949036
复制
发表时间:
2019-08
期刊:
2019 17th International Conference on Privacy, Security and Trust (PST)
影响因子:
--
通讯作者:
Munir Geden;Kasper Bonne Rasmussen
Munir Geden;Kasper Bonne Rasmussen
中科院分区:
其他
文献类型:
--
作者:
Munir Geden;Kasper Bonne Rasmussen

文献摘要

被引文献

相似文献

远程证明是一种挑战 - 响应协议,使一个称为验证者的受信任的实体可以要求提供一种称为“鄙视的设备”,称为“供奉献者”,以保证其内部完整性。由于其强大的保证,远程证明在关键的嵌入式系统中变得越来越流行,可用于医疗,军事或工业控制目的。以前使用静态代码区域校验和确保加载时间完整性的校验和的提案错过了仅影响动态内存区域的运行时攻击。为了解决这些攻击,本文提出了一种新方案,该方案根据程序的控制和数据功能证明运行时完整性。可以借助连接到供摊贩的系统总线的新型硬件安全模块(HSM)设计实时执行运行时检查。建议的HSM通过检查地址和数据总线上的位置上的位置,并使用加载到其内存中的静态模型来检测运行时问题。我们的证明方案能够报告复杂的运行时攻击,例如代码 - reuse和非控制数据攻击。
Remote attestation, as a challenge-response protocol, enables a trusted entity, called verifier, to ask for an untrusted device, called prover, to provide assurance about its internal integrity. Due to its strong guarantees, remote attestation is becoming increasingly popular for critical embedded systems which can be used for medical, military or industrial control purposes. Previous proposals, which used checksums on static code regions to assure the load-time integrity, miss the runtime attacks that affect only dynamic memory regions. To address these attacks, this paper proposes a new scheme that attests the runtime integrity according to the control and data features of the program. The runtime check can be performed in real time with the help of a novel hardware security module (HSM) design which is connected to the prover's system bus. Proposed HSM detects runtime issues by checking compliance of the bits seen on the address and data bus with the static model loaded into its memory. Our attestation scheme is capable of reporting sophisticated runtime attacks such as code-reuse and non-control data attacks.