HYDRA: hybrid design for remote attestation (using a formally verified microkernel)
HYDRA: hybrid design for remote attestation (using a formally verified microkernel)
复制标题
DOI:
10.1145/3098243.3098261
复制
发表时间:
2017-03
期刊:
影响因子:
--
通讯作者:
Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik
中科院分区:
文献类型:
--
作者:
Karim M. El Defrawy;Norrathep Rattanavipanon;G. Tsudik
Remote Attestation (RA) allows a trusted entity (verifier) to securely measure internal state of a remote untrusted hardware platform (prover). RA can be used to establish a static or dynamic root of trust in embedded and cyber-physical systems. It can also be used as a building block for other security services and primitives, such as software updates and patches, verifiable deletion and memory resetting. There are three major types of RA designs: hardware-based, software-based, and hybrid, each with its own set of benefits and drawbacks. This paper presents the first hybrid RA design - called HYDRA - that builds upon formally verified software components that ensure memory isolation and protection, as well as enforce access control to memory and other resources. HYDRA obtains these properties by using the formally verified seL4 microkernel. (Until now, this was only attainable with purely hardware-based designs.) Using seL4 imposes fewer hardware requirements on the underlying microprocessor. Also, building upon a formally verified software component increases confidence in security of the overall design of HYDRA and its implementation. We instantiate HYDRA on two commodity hardware platforms and assess the performance and overhead of performing RA on such platforms via experimentation; we show that HYDRA can attest 10MB of memory in less than 250msec when using a Speck-based cryptographic checksum.