Remote Attestation via Self-Measurement

Remote Attestation via Self-Measurement
复制标题

通过自我测量进行远程认证

DOI:
10.1145/3279950
复制
发表时间:
2019
影响因子:
1.4
通讯作者:
Tsudik, Gene
Tsudik, Gene
中科院分区:
计算机科学4区
文献类型:
--
作者:
Carpent, Xavier;Rattanavipanon, Norrathep;Tsudik, Gene

文献摘要

参考文献

相似文献

远程认证(RA)是一种流行的检测嵌入式和物联网设备中的恶意软件的方法。RA通常是作为一种交互协议实现的,通过这种协议,受信任的一方(验证者)可以测量可能受到损害的远程设备(证明者)的软件完整性。早期的工作集中在纯粹基于软件和完全基于硬件的技术上,这两种技术都不适合低端嵌入式设备。最近的结果产生了混合(SW/HW)架构,具有最少的功能集,可以在低端设备上支持高效和安全的RA。所有先前的技术都需要按需操作,即实时执行RA。我们确定了这种通用方法在无人值守设备环境中的一些缺点:首先,它无法检测在连续RA实例之间进入和离开证明器的移动恶意软件。其次,它要求证明者进行潜在的昂贵(在时间和精力方面)计算,这可能对任务关键型设备或实时设备有害。为了解决这些缺点,我们引入了自我度量的概念,由此证明者基于预先建立的时间表,定期且安全地度量并记录其自己的软件状态。(可能是不可信的)验证者偶尔会收集并验证这些度量。我们提出了一种具体技术的设计,称为通过无人值勤设置的自我测量进行有效远程认证(ERASMUS),证明其功能并评估其性能。在此过程中,我们还定义了一个新的度量,即认证质量(QoA)。我们相信ERASMUS非常适合时间敏感和/或安全关键应用,而按需RA无法很好地提供服务。最后,我们表明ERASMUS是处理具有高移动性的多个设备(即一组或一群)认证的有希望的垫脚石。
Remote attestation (RA) is a popular means of detecting malware in embedded and IoT devices. RA is usually realized as an interactive protocol, whereby a trusted party (verifier) measures software integrity of a potentially compromised remote device (prover). Early work focused on purely software-based and fully hardware-based techniques, neither of which is ideal for low-end embedded devices. More recent results yielded hybrid (SW/HW) architectures with a minimal set of features to support efficient and secure RA on low-end devices.All prior techniques requireon-demand operation, i.e., RA is performed inreal time. We identify some drawbacks of this general approach in the context of unattended devices: First, it fails to detectmobile malwarethat enters and leaves prover between successive RA instances. Second, it requires prover to engage in a potentially expensive (in terms of time and energy) computation, which can be harmful for mission-critical or real-time devices.To address these drawbacks, we introduce the concept ofself-measurement, whereby prover periodically and securely measures and records its own software state, based on a pre-established schedule. A (possibly untrusted) verifier occasionally collects and verifies these measurements. We present the design of a concrete technique, called Efficient Remote Attestation via Self-Measurement for Unattended Settings, (ERASMUS), justify its features and evaluate its performance. In the process, we also define a new metric,Quality of Attestation(QoA). We believe that ERASMUS is well suited for time-sensitive and/or safety-critical applications that are not served well by on-demand RA. Finally, we show that ERASMUS is a promising stepping stone toward handling attestation of multiple devices (i.e., a group or swarm) with high mobility.
DOI: 10.1145/3098243.3098261
发表时间: 2017-03
期刊: Proceedings of the 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子: --
作者:
Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik
通讯作者: Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik