RIPTE: Runtime Integrity Protection Based on Trusted Execution for IoT Device

RIPTE: Runtime Integrity Protection Based on Trusted Execution for IoT Device
复制标题

RIPTE:基于物联网设备可信执行的运行时完整性保护

DOI:
10.1155/2020/8957641
复制
发表时间:
2020-09
影响因子:
--
通讯作者:
Feng Wei
Feng Wei
中科院分区:
计算机科学4区
文献类型:
--
作者:
Qin Yu;Liu Jingbin;Zhao Shijun;Feng Dengguo;Feng Wei

文献摘要

参考文献

相似文献

蠕虫、僵尸网络、DDoS等软件攻击是物联网中日益严重的问题,已造成大规模网络攻击,甚至导致重要信息基础设施瘫痪。软件度量和证明是物联网中检测软件完整性及其执行状态的常用方法。然而,由于其静态特性,它们无法抵抗TOCT攻击,并且很少验证控制流完整性的正确性。提出了一种新颖实用的基于轻量级信任的软件可信执行方案。我们的方案RIPTE结合了动态测量和控制流的完整性与PUF设备绑定密钥。+通过PUF密钥对程序函数的返回地址进行粗加密,RIPTE可以在物联网设备上保护软件运行时的完整性,从而防止代码重用攻击。+e我们的原型实验结果表明,它只增加了一个小规模的TCB,在函数调用的约束下,在物联网设备中的开销很小。总之,RIPTE在运行时的IoT设备保护方面是安全和高效的。
Software attacks like worm, botnet, and DDoS are the increasingly serious problems in IoT, which had caused large-scale cyber attack and even breakdown of important information infrastructure. Software measurement and attestation are general methods to detect software integrity and their executing states in IoT. However, they cannot resist TOCTOU attack due to their static features and seldom verify correctness of control flow integrity. In this paper, we propose a novel and practical scheme for software trusted execution based on lightweight trust. Our scheme RIPTE combines dynamic measurement and control flow integrity with PUF device binding key. +rough encrypting return address of program function by PUF key, RIPTE can protect software integrity at runtime on IoTdevice, enabling to prevent the code reuse attacks. +e results of our prototype’s experiment show that it only increases a small size TCB and has a tiny overhead in IoTdevices under the constraint on function calling. In sum, RIPTE is secure and efficient in IoT device protection at runtime.
DOI: 10.1145/1133058.1133063
发表时间: 2006-06
期刊: --
影响因子: --
作者:
T. Jaeger;R. Sailer;U. Shankar
通讯作者: T. Jaeger;R. Sailer;U. Shankar
DOI: 10.2307/j.ctvxhrhv4.8
发表时间: 2020-03
期刊: Unmanning
影响因子: --
作者:
John D. Anderson;P. A. Laing;E. Lau;A. Liu;M. Nieto
通讯作者: John D. Anderson;P. A. Laing;E. Lau;A. Liu;M. Nieto
DOI: --
发表时间: 2004-08
期刊: --
影响因子: --
作者:
Umesh Shankar;Monica Chew;J. D. Tygar
通讯作者: Umesh Shankar;Monica Chew;J. D. Tygar
DOI: 10.1109/sp.2012.12
发表时间: 2012-05
期刊: 2012 IEEE Symposium on Security and Privacy
影响因子: --
作者:
Yinglei Wang;Wing-Kei S. Yu;Shuo Wu;G. Malysa;G. Suh;E. Kan
通讯作者: Yinglei Wang;Wing-Kei S. Yu;Shuo Wu;G. Malysa;G. Suh;E. Kan
DOI: 10.1007/3-540-44887-x_47
发表时间: 2003-06
期刊: --
影响因子: --
作者:
J. Linnartz;P. Tuyls
通讯作者: J. Linnartz;P. Tuyls