Terra: a virtual machine-based platform for trusted computing

Terra: a virtual machine-based platform for trusted computing
复制标题

DOI:
10.1145/945445.945464
复制
发表时间:
2003-10
期刊:
--
影响因子:
--
通讯作者:
Tal Garfinkel;Ben Pfaff;Jim Chow;M. Rosenblum;D. Boneh
Tal Garfinkel;Ben Pfaff;Jim Chow;M. Rosenblum;D. Boneh
中科院分区:
其他
文献类型:
--
作者:
Tal Garfinkel;Ben Pfaff;Jim Chow;M. Rosenblum;D. Boneh

文献摘要

被引文献

相似文献

我们提出了一个灵活的可信计算架构,称为Terra,它允许具有广泛的安全要求的应用程序同时运行在商品硬件上。Terra上的应用程序享受在一个单独的、专用的、防篡改的硬件平台上运行的语义,同时保留了在通用计算平台上与普通应用程序并行运行的能力。Terra通过使用可信虚拟机监视器(TVMM)实现这种合成,该监视器将防篡改硬件平台划分为多个隔离的虚拟机(VM),从而在单个通用平台上提供多个框的外观。对于每个VM,TVMM提供“开放盒子”(即,像今天的PC和工作站的通用硬件平台)或“封闭盒子”(保护其内容的隐私和完整性的不透明专用平台,像今天的游戏控制台和蜂窝电话)的语义。每个虚拟机中的软件堆栈都可以从硬件接口进行定制,以满足其应用程序的安全要求。硬件和TVMM可以充当受信任方,以允许封闭式VM以加密方式向远程方识别它们运行的软件,即盒子中的内容。我们通过描述我们的原型实现和我们为它开发的几个应用程序来探索这种架构的优势和局限性。
We present a flexible architecture for trusted computing, called Terra, that allows applications with a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a general-purpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an "open box," i.e. a general-purpose hardware platform like today's PCs and workstations, or a "closed box," an opaque special-purpose platform that protects the privacy and integrity of its contents like today's game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it.