IDA: Hybrid Attestation with Support for Interrupts and TOCTOU

IDA: Hybrid Attestation with Support for Interrupts and TOCTOU
复制标题

DOI:
10.14722/ndss.2024.23059
复制
发表时间:
2024
期刊:
Proceedings 2024 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Fatemeh Arkannezhad;Justin Feng;Nader Sehatbakhsh
Fatemeh Arkannezhad;Justin Feng;Nader Sehatbakhsh
中科院分区:
其他
文献类型:
--
作者:
Fatemeh Arkannezhad;Justin Feng;Nader Sehatbakhsh

文献摘要

相似文献

- 由于嵌入式和物联网设备的泛滥,象征的证明最近受到了很多关注,但基于硬件 - 软件共同设计(Hybrid)的方法尤其受欢迎,因为它们的开销低下却有效。混合方法仍然遭受多种限制,例如认证键所需的严格保护以及限制性操作以及威胁模型,例如禁用中断和我们提出了一种称为IDA的新型混合证明方法,忽略了使用时间的时间(TOCTOU)攻击代码,改善了系统的整体安全性和灵活性,而不是使用秘密钥匙来计算响应只有遵循它的遵循,我们提出了IDA+的攻击和处理中断,该+在证明请求或中断期间监视程序内存,并告知我们实现的更改和评估IDA和IDA+ ON。开源MSP430体系结构,在运行时,内存足迹和硬件开销方面显示出合理的开销,同时在各种攻击方案上都具有强大的功能。将我们的方法与最先进的方法进行比较,我们表明它的开销很小,同时获得了重要的新属性,例如支持中断和DMA请求并检测TOCTOU攻击。
—Remote attestation has received much attention recently due to the proliferation of embedded and IoT devices. Among various solutions, methods based on hardware-software co-design (hybrid) are particularly popular due to their low overhead yet effective approaches. Despite their usefulness, hybrid methods still suffer from multiple limitations such as strict protections required for the attestation keys and restrictive operation and threat models such as disabling interrupts and neglecting time-of-check-time-of-use (TOCTOU) attacks. In this paper, we propose a new hybrid attestation method called IDA , which removes the requirement for disabling in-terrupts and restrictive access control for the secret key and attestation code, thus improving the system’s overall security and flexibility. Rather than making use of a secret key to calculate the response, IDA verifies the attestation process with trusted hardware monitoring and certifies its authenticity only if it was followed precisely. Further, to prevent TOCTOU attacks and handle interrupts, we propose IDA+ , which monitors program memory between attestation requests or during interrupts and informs the verifier of changes to the program memory. We implement and evaluate IDA and IDA+ on open-source MSP430 architecture, showing a reasonable overhead in terms of runtime, memory footprint, and hardware overhead while being robust against various attack scenarios. Comparing our method with the state-of-the-art, we show that it has minimal overhead while achieving important new properties such as support for interrupts and DMA requests and detecting TOCTOU attacks.