Side Effects Are Not Sufficient to Authenticate Software

Side Effects Are Not Sufficient to Authenticate Software
复制标题

DOI:
--
复制
发表时间:
2004-08
期刊:
--
影响因子:
--
通讯作者:
Umesh Shankar;Monica Chew;J. D. Tygar
Umesh Shankar;Monica Chew;J. D. Tygar
中科院分区:
其他
文献类型:
--
作者:
Umesh Shankar;Monica Chew;J. D. Tygar

文献摘要

被引文献

相似文献

Kennell和Jamieson [KJ03]最近介绍了一种身份验证系统,用于在不使用可信硬件的情况下对远程机器上的可信软件进行身份验证。相似性依赖于特定于机器的计算,并包含无法快速模拟的副作用。该系统容易受到一种新的攻击,我们称之为替代攻击。我们实现了一个成功的攻击的一致性,并进一步认为这类计划不仅是不切实际的,但不太可能成功,没有可信的硬件。
Kennell and Jamieson [KJ03] recently introduced the Genuinity system for authenticating trusted software on a remote machine without using trusted hardware. Genuinity relies on machine-specific computations, incorporating side effects that cannot be simulated quickly. The system is vulnerable to a novel attack, which we call a substitution attack. We implement a successful attack on Genuinity, and further argue this class of schemes are not only impractical but unlikely to succeed without trusted hardware.