Architectural Support for Containment-based Security

Architectural Support for Containment-based Security
复制标题

基于遏制的安全性的架构支持

DOI:
10.1145/3297858.3304020
复制
发表时间:
2019
期刊:
Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
August, David I.
August, David I.
中科院分区:
--
文献类型:
--
作者:
Zhang, Hansen;Ghosh, Soumyadeep;Fix, Jordan;Apostolakis, Sotiris;Beard, Stephen R.;Nagendra, Nayana P.;Oh, Taewook;August, David I.

文献摘要

参考文献

被引文献

相似文献

软件安全技术依赖于硬件的正确执行。由于硬件组件的复杂性以及它们在设计、制造、部署和操作期间呈现的成比例的攻击面,因此保护硬件组件一直具有挑战性。认识到外部通信是对系统安全的最大威胁之一,本文介绍了TrustGuard遏制体系结构。TrustGuard包含恶意和错误的行为,使用一个相对简单和可插拔的看门硬件组件称为哨兵。Sentry在不可信系统和其外部接口之间架起了一座物理桥梁。TrustGuard只允许正确执行受信任软件所产生的通信,从而防止恶意硬件或软件的操作对系统造成不良影响。Sentry的简单性和可插入性,在不到简单有序处理器一半的代码行中实现,使额外的措施能够确保这种信任的根源,包括正式验证,监督制造和供应链多样化,对性能的影响不到15%。
Software security techniques rely on correct execution by the hardware. Securing hardware components has been challenging due to their complexity and the proportionate attack surface they present during their design, manufacture, deployment, and operation. Recognizing that external communication represents one of the greatest threats to a system's security, this paper introduces the TrustGuard containment architecture. TrustGuard contains malicious and erroneous behavior using a relatively simple and pluggable gatekeeping hardware component called the Sentry. The Sentry bridges a physical gap between the untrusted system and its external interfaces. TrustGuard allows only communication that results from the correct execution of trusted software, thereby preventing the ill effects of actions by malicious hardware or software from leaving the system. The simplicity and pluggability of the Sentry, which is implemented in less than half the lines of code of a simple in-order processor, enables additional measures to secure this root of trust, including formal verification, supervised manufacture, and supply chain diversification with less than a 15% impact on performance.
用于硬件设计的工业强度形式验证技术
DOI: --
发表时间: 1997
期刊: Proceedings Tenth International Conference on VLSI Design
影响因子: --
作者:
S. Rajan;Natarajan Shankar;M. Srivas
通讯作者: M. Srivas
使用 WEB 改进自动验证类似 XScale 的处理器模型的安全性和活性
DOI: --
发表时间: 2004
期刊: Proceedings Design, Automation and Test in Europe Conference and Exhibition
影响因子: --
作者:
P. Manolios;S. Srinivasan
通讯作者: S. Srinivasan
参数变化下基于延迟的木马检测技术的性能
DOI: 10.1109/hst.2009.5224966
发表时间: 2009
期刊: 2009 IEEE International Workshop on Hardware-Oriented Security and Trust
影响因子: --
作者:
Devendra Rai;J. Lach
通讯作者: J. Lach
使用 ACL2 对 SHA-1 电路核心进行形式验证
DOI: --
发表时间: 2005
期刊: International Conference on Theorem Proving in Higher Order Logics
影响因子: --
作者:
Diana Toma;D. Borrione
通讯作者: D. Borrione
更安全的路径:使用分段执行和复制的安全架构来防范木马硬件
DOI: --
发表时间: 2012
期刊: Design, Automation and Test in Europe
影响因子: --
作者:
Mark R. Beaumont;Bradley D. Hopkins;Tristan Newby
通讯作者: Tristan Newby