Sanctum: Minimal RISC Extensions for Isolated Execution

Sanctum: Minimal RISC Extensions for Isolated Execution
复制标题

DOI:
--
复制
发表时间:
2015
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Victor Costan;Ilia A. Lebedev;S. Devadas
Victor Costan;Ilia A. Lebedev;S. Devadas
中科院分区:
其他
文献类型:
--
作者:
Victor Costan;Ilia A. Lebedev;S. Devadas

文献摘要

被引文献

相似文献

Sanctum是对标准RISC架构的一组最小扩展,为并发运行和共享资源的软件模块提供了强大的可证明隔离。Sanctum在其API方面与SGX相似,但可以防御一类重要的附加软件攻击,包括缓存计时和内存访问模式攻击。它通过一种原则性的方法来消除整个攻击面,通过隔离而不是堵塞特定于攻击的隐私泄露。Sanctum在标准RISC架构上的硬件变化不会影响周期时间,因为它们不会延长关键执行路径。Sanctum不会改变任何主要的CPU构建块(例如,ALU、MMU、高速缓存),并且仅需要在这些构建块之间的接口处的附加硬件,对应于小于百分之二的芯片面积开销。在一组基准测试中,Sanctum最糟糕的孤立执行开销是理想化的不安全基线的14.6%。
Sanctum is a set of minimal extensions to a standard RISC architecture that offers strong provable isolation of software modules running concurrently and sharing resources. Sanctum is similar to SGX in its API, but protects against an important class of additional software attacks, including cache timing and memory access pattern attacks. It does so via a principled approach to eliminating entire attack surfaces through isolation rather than plugging attack-specific privacy leaks. Sanctum’s hardware changes over a standard RISC architecture do not impact the cycle time, as they do not extend critical execution paths. Sanctum does not change any major CPU building block (e.g., ALU, MMU, cache), and only requires additional hardware at the interfaces between these building blocks corresponding to less than two percent chip area overhead. Over a set of benchmarks, Sanctum’s worst observed overhead for isolated execution is 14.6% over an idealized insecure baseline.