Trusted Browsers for Uncertain Times

Trusted Browsers for Uncertain Times
复制标题

不确定时期值得信赖的浏览器

DOI:
--
复制
发表时间:
2016
期刊:
USENIX Security Symposium
影响因子:
--
通讯作者:
H. Shacham
H. Shacham
中科院分区:
--
文献类型:
--
作者:
David Kohlbrenner;H. Shacham

文献摘要

被引文献

相似文献

一个源中的JavaScript可以使用浏览器中的定时通道来了解有关用户与其他源交互的敏感信息,这违反了浏览器的划分保证。浏览器供应商试图通过重写敏感代码以在恒定时间内运行和降低参考时钟的分辨率来关闭定时通道。我们认为,这些临时性的努力不太可能成功。我们的技术,提高了两个数量级的退化时钟的有效分辨率,我们提出和评估多个,新的隐式时钟:技术,通过该技术JavaScript可以在没有咨询一个明确的时钟事件。我们展示了如何“模糊时间”的想法,在可信的操作系统的文学可以适应构建可信的浏览器,降低所有的时钟和减少所有的定时通道的带宽。我们描述了下一代浏览器的设计,称为Fermata,其中所有的定时源完全介导。作为可行性的证明,我们提出了Fuzzyfox,Firefox浏览器的一个分支,它在当今浏览器架构的约束下实现了许多Fermata原则。我们表明,Fuzzyfox实现了足够的兼容性和性能部署今天的隐私敏感的用户。
JavaScript in one origin can use timing channels in browsers to learn sensitive information about a user’s interaction with other origins, violating the browser’s compartmentalization guarantees. Browser vendors have attempted to close timing channels by trying to rewrite sensitive code to run in constant time and by reducing the resolution of reference clocks. We argue that these ad-hoc efforts are unlikely to succeed. We show techniques that increase the effective resolution of degraded clocks by two orders of magnitude, and we present and evaluate multiple, new implicit clocks: techniques by which JavaScript can time events without consulting an explicit clock at all. We show how “fuzzy time” ideas in the trusted operating systems literature can be adapted to building trusted browsers, degrading all clocks and reducing the bandwidth of all timing channels. We describe the design of a next-generation browser, called Fermata, in which all timing sources are completely mediated. As a proof of feasibility, we present Fuzzyfox, a fork of the Firefox browser that implements many of the Fermata principles within the constraints of today’s browser architecture. We show that Fuzzyfox achieves sufficient compatibility and performance for deployment today by privacysensitive users.