ProtectIOn: Root-of-Trust for IO in Compromised Platforms

ProtectIOn: Root-of-Trust for IO in Compromised Platforms
复制标题

保护:受感染平台中 IO 的信任根

DOI:
--
复制
发表时间:
2019
期刊:
IACR Cryptology ePrint Archive
影响因子:
--
通讯作者:
Srdjan Capkun
Srdjan Capkun
中科院分区:
--
文献类型:
--
作者:
Aritra Dhar;Enis Ulqinaku;Kari Kostiainen;Srdjan Capkun

文献摘要

参考文献

被引文献

相似文献

安全和安全关键的远程应用程序,如电子投票,网上银行,工业控制系统和医疗设备依赖于用户交互,通常通过Web应用程序执行。在存在控制用户计算机的攻击者的情况下,到此类远程系统的可信路径至关重要。这样的攻击者可以观察和修改任何IO数据,而不会被用户或服务器检测到。我们调查了之前研究提案的安全性,并观察到使它们容易受到攻击的几个缺陷。基于这些观察,我们确定了新的安全IO操作的要求,在存在一个受损的主机。作为一种解决方案,我们提出了保护,一个系统,确保IO的完整性,使用可信的低TCB设备之间的攻击者控制的主机和IO设备。PROTECTION拦截来自键盘和鼠标的显示信号和用户输入,并将安全UI覆盖在不受信任主机生成的HDMI帧之上。保护的指导设计原则是:(i)用户输入和输出的完整性不能分开考虑,(ii)所有用户输入模式需要同时保护,(iii)完整性保护不应依赖于容易出错的用户任务,如检查安全指示器的存在。通过遵循这些准则,PROTECTION实现了对IO完整性的强大保护。我们还提出了一个扩展的保护IO机密性,实现了即插即用的原型,并评估其性能。
Security and safety-critical remote applications such as e-voting, online banking, industrial control systems and medical devices rely upon user interaction that is typically performed through web applications. Trusted path to such remote systems is critical in the presence of an attacker that controls the user’s computer. Such an attacker can observe and modify any IO data without being detected by the user or the server. We investigate the security of previous research proposals and observe several drawbacks that make them vulnerable. Based on these observations we identify novel requirements for secure IO operation in the presence of a compromised host. As a solution, we propose PROTECTION, a system that ensures IO integrity using a trusted low-TCB device that sits between the attacker-controlled host and the IO devices. PROTECTION intercepts the display signal and user inputs from the keyboard and mouse, and overlays secure UI on top of the HDMI frames generated by the untrusted host. The guiding design principles of PROTECTION are: (i) integrity of user input and output cannot be considered separately, (ii) all user input modalities need to be protected simultaneously, and (iii) integrity protection should not rely on error prone user tasks like checking the presence of security indicators. By following these guidelines, PROTECTION achieves strong protection for IO integrity. We also propose an extension of PROTECTION for IO confidentiality, implement a plug-and-play prototype, and evaluate its performance.
DOI: 10.1145/3210240.3210338
发表时间: 2018-06
期刊: Proceedings of the 16th Annual International Conference on Mobile Systems, Applications, and Services
影响因子: --
作者:
Kailiang Ying;A. Ahlawat;B. Alsharifi;Yuexin Jiang;Priyank Thavai;Wenliang Du
通讯作者: Kailiang Ying;A. Ahlawat;B. Alsharifi;Yuexin Jiang;Priyank Thavai;Wenliang Du