Glamdring: Automatic Application Partitioning for Intel SGX

Glamdring: Automatic Application Partitioning for Intel SGX
复制标题

DOI:
--
复制
发表时间:
2017-07
期刊:
--
影响因子:
--
通讯作者:
Joshua Lind;Christian Priebe;D. Muthukumaran;Dan O'Keeffe;Pierre-Louis Aublin;Florian Kelbert;T. Reiher-T.-R
Joshua Lind;Christian Priebe;D. Muthukumaran;Dan O'Keeffe;Pierre-Louis Aublin;Florian Kelbert;T. Reiher-T.-R
中科院分区:
其他
文献类型:
--
作者:
Joshua Lind;Christian Priebe;D. Muthukumaran;Dan O'Keeffe;Pierre-Louis Aublin;Florian Kelbert;T. Reiher-T.-R

文献摘要

相似文献

由Intel SGX enclave提供的现代cpu中的可信执行支持可以保护不可信环境中的应用程序。虽然先前的工作表明遗留应用程序可以在飞地中完整地运行,但这导致了一个大型可信计算基础(TCB)。相反,我们将探索一种方法,在这种方法中,我们对应用程序进行分区,并使用enclave仅保护对安全敏感的数据和功能,从而获得较小的TCB。我们描述了Glamdring,这是第一个源代码级分区框架,用于保护使用Intel SGX用C编写的应用程序。开发人员首先对安全敏感的应用程序数据进行注释。然后,Glamdring自动将应用程序划分为不受信任的和封闭的部分:(i)为了保护数据的机密性,Glamdring使用数据流分析来识别可能暴露于敏感数据的功能;(ii)为了数据完整性,它使用反向切片来识别可能影响敏感数据的函数。然后,Glamdring将安全敏感的功能放在飞地内,并在飞地边界添加运行时检查和加密操作,以保护它免受攻击。我们对Memcached存储、LibreSSL库和Digital Bitbox比特币钱包的Glamdring的评估表明,它实现了较小的TCB大小,并且具有可接受的性能开销。
Trusted execution support in modern CPUs, as offered by Intel SGX enclaves, can protect applications in untrusted environments. While prior work has shown that legacy applications can run in their entirety inside enclaves, this results in a large trusted computing base (TCB). Instead, we explore an approach in which we partition an application and use an enclave to protect only security-sensitive data and functions, thus obtaining a smaller TCB. We describe Glamdring, the first source-level partitioning framework that secures applications written in C using Intel SGX. A developer first annotates security-sensitive application data. Glamdring then automatically partitions the application into untrusted and enclave parts: (i) to preserve data confidentiality, Glamdring uses dataflow analysis to identify functions that may be exposed to sensitive data; (ii) for data integrity, it uses backward slicing to identify functions that may affect sensitive data. Glamdring then places security-sensitive functions inside the enclave, and adds runtime checks and cryptographic operations at the enclave boundary to protect it from attack. Our evaluation of Glamdring with the Memcached store, the LibreSSL library, and the Digital Bitbox bitcoin wallet shows that it achieves small TCB sizes and has acceptable performance overheads.