Shielding Applications from an Untrusted Cloud with Haven

Shielding Applications from an Untrusted Cloud with Haven
复制标题

DOI:
10.1145/2799647
复制
发表时间:
2015-09-01
影响因子:
1.5
通讯作者:
Hunt, Galen
Hunt, Galen
中科院分区:
计算机科学2区
文献类型:
--
作者:
Baumann, Andrew;Peinado, Marcus;Hunt, Galen

文献摘要

被引文献

相似文献

当今的云计算基础设施需要充分的信任。云用户依赖提供商的员工及其全球分布的软件/硬件平台来避免暴露任何私人数据。我们引入了屏蔽执行的概念,它可以保护程序及其数据的机密性和完整性,使其免受其运行平台(即云运营商的操作系统、虚拟机和固件)的影响。我们的原型 Haven 是第一个在商用操作系统 (Windows) 和商用硬件上实现未经修改的遗留应用程序(包括 SQL Server 和 Apache)的屏蔽执行的系统。 Haven 利用 Intel SGX 的硬件保护来防御特权代码和内存探测等物理攻击,还解决了执行未修改的旧二进制文件和保护它们免受恶意主机侵害的双重挑战。这项工作促使 SGX 规范最近发生了变化。
Today's cloud computing infrastructure requires substantial trust. Cloud users rely on both the provider's staff and its globally distributed software/hardware platform not to expose any of their private data.We introduce the notion of shielded execution, which protects the confidentiality and integrity of a program and its data from the platform on which it runs (i.e., the cloud operator's OS, VM, and firmware). Our prototype, Haven, is the first system to achieve shielded execution of unmodified legacy applications, including SQL Server and Apache, on a commodity OS (Windows) and commodity hardware. Haven leverages the hardware protection of Intel SGX to defend against privileged code and physical attacks such as memory probes, and also addresses the dual challenges of executing unmodified legacy binaries and protecting them from a malicious host. This work motivated recent changes in the SGX specification.