Remote Attestation via Self-Measurement
Remote Attestation via Self-Measurement
复制标题
通过自我测量进行远程认证
DOI:
10.1145/3279950
复制
发表时间:
2019
影响因子:
1.4
通讯作者:
Tsudik, Gene
中科院分区:
文献类型:
--
作者:
Carpent, Xavier;Rattanavipanon, Norrathep;Tsudik, Gene
Remote attestation (RA) is a popular means of detecting malware in embedded and IoT devices. RA is usually realized as an interactive protocol, whereby a trusted party (verifier) measures software integrity of a potentially compromised remote device (prover). Early work focused on purely software-based and fully hardware-based techniques, neither of which is ideal for low-end embedded devices. More recent results yielded hybrid (SW/HW) architectures with a minimal set of features to support efficient and secure RA on low-end devices.All prior techniques requireon-demand operation, i.e., RA is performed inreal time. We identify some drawbacks of this general approach in the context of unattended devices: First, it fails to detectmobile malwarethat enters and leaves prover between successive RA instances. Second, it requires prover to engage in a potentially expensive (in terms of time and energy) computation, which can be harmful for mission-critical or real-time devices.To address these drawbacks, we introduce the concept ofself-measurement, whereby prover periodically and securely measures and records its own software state, based on a pre-established schedule. A (possibly untrusted) verifier occasionally collects and verifies these measurements. We present the design of a concrete technique, called Efficient Remote Attestation via Self-Measurement for Unattended Settings, (ERASMUS), justify its features and evaluate its performance. In the process, we also define a new metric,Quality of Attestation(QoA). We believe that ERASMUS is well suited for time-sensitive and/or safety-critical applications that are not served well by on-demand RA. Finally, we show that ERASMUS is a promising stepping stone toward handling attestation of multiple devices (i.e., a group or swarm) with high mobility.
DOI:
10.1145/3098243.3098261
发表时间:
2017-03
期刊:
Proceedings of the 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
作者:
Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik
通讯作者:
Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik