Reconciling remote attestation and safety-critical operation on simple IoT devices

Reconciling remote attestation and safety-critical operation on simple IoT devices
复制标题

协调简单物联网设备上的远程认证和安全关键操作

DOI:
10.1145/3195970.3199853
复制
发表时间:
2018
期刊:
DAC '18 Proceedings of the 55th Annual Design Automation Conference
影响因子:
--
通讯作者:
Tsudik, Gene
Tsudik, Gene
中科院分区:
--
文献类型:
--
作者:
Carpent, Xavier;Eldefrawy, Karim;Rattanavipanon, Norrathep;Sadeghi, Ahmad-Reza;Tsudik, Gene

文献摘要

相似文献

远程证明(RA)是恶意软件检测的一种手段,通常实现为可信验证者和可能受到危害的远程设备(证明者)之间的交互。RA尤其适用于无法保护自己免受恶意软件感染的低端嵌入式设备。大多数当前的RA技术需要按需和不可中断(原子)操作。前者无法检测在连续RA实例之间进出的瞬时恶意软件;后者涉及对证明者的内存和/或存储执行可能耗时的计算,这可能会损害设备的安全关键功能和一般可用性。然而,放松按需或原子RA操作都是棘手的,而且容易出现漏洞。本文指出了在协调安全关键操作的要求和安全远程证明的要求时出现的一些问题,包括检测瞬时恶意软件和自我重定位恶意软件。它还研究了缓解技术,包括定期自我测量以及涉及混洗内存遍历和各种内存锁定机制的可中断证明方式。
Remote attestation (RA) is a means of malware detection, typically realized as an interaction between a trusted verifier and a potentially compromised remote device (prover). RA is especially relevant for low-end embedded devices that are incapable of protecting themselves against malware infection. Most current RA techniques require on-demand and uninterruptible (atomic) operation. The former fails to detect transient malware that enters and leaves between successive RA instances; the latter involves performing potentially time-consuming computation over prover's memory and/or storage, which can be harmful to the device's safety-critical functionality and general availability. However, relaxing either on-demand or atomic RA operation is tricky and prone to vulnerabilities. This paper identifies some issues that arise in reconciling requirements of safety-critical operation with those of secure remote attestation, including detection of transient and self-relocating malware. It also investigates mitigation techniques, including periodic self-measurements as well as interruptible attestation modality that involves shuffled memory traversals and various memory locking mechanisms.