MPTEE: bringing flexible and efficient memory protection to Intel SGX

MPTEE: bringing flexible and efficient memory protection to Intel SGX
复制标题

DOI:
10.1145/3342195.3387536
复制
发表时间:
2020-04
期刊:
Proceedings of the Fifteenth European Conference on Computer Systems
影响因子:
--
通讯作者:
Wenjia Zhao;Kangjie Lu;Yong Qi;Saiyu Qi
Wenjia Zhao;Kangjie Lu;Yong Qi;Saiyu Qi
中科院分区:
其他
文献类型:
--
作者:
Wenjia Zhao;Kangjie Lu;Yong Qi;Saiyu Qi

文献摘要

相似文献

Intel Software Guard extensions(SGX)是一种基于硬件的可信执行环境(TEE),已成为阻止内部攻击和远程攻击等关键威胁的有前途的解决方案。新交所最近在两个方向进行了广泛的研究-用它来保护敏感数据的机密性和完整性,以及保护自己免受攻击。SGX的应用程序和防御机制都有一个基本的需求--灵活的内存保护,动态更新内存页面权限并执行最小特权原则。遗憾的是,由于缺乏硬件支持和操作系统的不可信性,SGX没有提供这样的内存保护机制。本文提出了一种内存保护机制MPTEE,该机制在SGX中提供了灵活有效的内存页权限执行。执行依赖于我们的弹性跨区域边界检查技术,只使用三个绑定寄存器,但提供六个内存权限。为了保护MPTEE免受潜在的攻击,我们进一步开发了一种有效的机制,利用就地边界检查技术,以确保内存保护的完整性。通过MPTEE,开发人员可以增强对SGX安全区中数据和代码的保护,并实施最小特权原则,例如执行不读取内存。我们已经实施了MPTEE,并广泛评估其有效性,实用性和性能。实验结果表明,MPTEE的性能开销仅为2%~ 8%,在保证内存保护和抵御潜在攻击方面是有效的。
Intel Software Guard extensions (SGX), a hardware-based Trusted Execution Environment (TEE), has become a promising solution to stopping critical threats such as insider attacks and remote exploits. SGX has recently drawn extensive research in two directions---using it to protect the confidentiality and integrity of sensitive data, and protecting itself from attacks. Both the applications and defense mechanisms of SGX have a fundamental need---flexible memory protection that updates memory-page permissions dynamically and enforces the least-privilege principle. Unfortunately, SGX does not provide such a memory-protection mechanism due to the lack of hardware support and the untrustedness of operating systems. This paper proposes MPTEE, a memory-protection mechanism that provides flexible and efficient enforcement of memory-page permissions in SGX. The enforcement relies on our elastic cross-region bound check technique which uses only three bound registers but provides six memory permissions. To defend MPTEE against potential attacks, we further develop an efficient mechanism that exploits the in-place bound-check technique to ensure the integrity of the memory protection. With MPTEE, developers can enhance the protection for data and code in SGX enclaves and enforce the least-privilege principle such as Execute-no-Read memory readily. We have implemented MPTEE and extensively evaluated its effectiveness, utility, and performance. The results show that MPTEE incurs a performance overhead of only 2%--8%, and is effective in ensuring memory protection and in defending against potential attacks.