Property-based attestation for computing platforms: caring about properties, not mechanisms

Property-based attestation for computing platforms: caring about properties, not mechanisms
复制标题

DOI:
10.1145/1065907.1066038
复制
发表时间:
2004-09
期刊:
--
影响因子:
--
通讯作者:
A. Sadeghi;Christian Stüble
A. Sadeghi;Christian Stüble
中科院分区:
其他
文献类型:
--
作者:
A. Sadeghi;Christian Stüble

文献摘要

被引文献

相似文献

在过去的几年里,计算行业已经开始了各种各样的倡议,宣布通过新的硬件架构来提高计算机安全性。最值得注意的努力是可信计算组(TCG)和下一代安全计算基础(NGSCB)。该技术提供了有用的新功能,如验证平台的完整性(证明)或特定平台上的绑定量(密封)的可能性。在本文中,我们指出了TCG现有规范提出的证明和密封功能的不足之处:我们表明这些机制可能被滥用来区分某些平台,即,他们的操作系统以及相应的供应商。在这种情况下,一个特殊的问题是管理大量可能的配置。此外,我们强调其他缺点有关的证明,即系统更新和备份。显然,这些问题所造成的后果导致了私人和商业分支的不满意状况,以及当这些平台被广泛使用时的不平衡市场。为了普遍克服这些问题,我们提出了一种全新的方法:平台的证明不应依赖于特定的软件或/和硬件(配置),因为它是今天的做法,但只对“属性”,该平台提供。因此,基于属性的证明应该只验证这些属性是否足以满足要求证明的一方的某些(安全)要求。我们提出并讨论了各种解决方案的基础上现有的可信计算(TC)的功能。我们还演示了如何基于现有的TC硬件,如可信协议(TPM)的基础上实现基于属性的证明协议。
Over the past years, the computing industry has started various initiatives announced to increase computer security by means of new hardware architectures. The most notable effort is the Trusted Computing Group (TCG) and the Next-Generation Secure Computing Base (NGSCB). This technology offers useful new functionalities as the possibility to verify the integrity of a platform (attestation) or binding quantities on a specific platform (sealing).In this paper, we point out the deficiencies of the attestation and sealing functionalities proposed by the existing specification of the TCG: we show that these mechanisms can be misused to discriminate certain platforms, i.e., their operating systems and consequently the corresponding vendors. A particular problem in this context is that of managing the multitude of possible configurations. Moreover, we highlight other shortcomings related to the attestation, namely system updates and backup. Clearly, the consequences caused by these problems lead to an unsatisfactory situation both for the private and business branch, and to an unbalanced market when such platforms are in wide use.To overcome these problems generally, we propose a completely new approach: the attestation of a platform should not depend on the specific software or/and hardware (configuration) as it is today's practice but only on the "properties" that the platform offers. Thus, a property-based attestation should only verify whether these properties are sufficient to fulfill certain (security) requirements of the party who asks for attestation. We propose and discuss a variety of solutions based on the existing Trusted Computing (TC) functionality. We also demonstrate, how a property-based attestation protocol can be realized based on the existing TC hardware such as a Trusted Platform Module (TPM).