CAREER: Taming the Side-Channel Hazards in the Shielded Execution Paradigm
CAREER: Taming the Side-Channel Hazards in the Shielded Execution Paradigm
批准号:
1750809
负责人:
Yinqian Zhang
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-04-01 至 2020-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Intel's Software Guard Extension (SGX) is a hardware extension available in recent Intel processors, which provides software applications with shielded execution environments, called enclaves, to protect their confidentiality and integrity against compromised operating systems. The wide adoption of SGX will foster a shielded execution paradigm for enhancing software security in situations where the operating systems are not entirely trusted, such as public clouds. However, recent studies have suggested that SGX is vulnerable to side-channel threats, in which the system software measures the enclaves' use of system resources or micro-architectural resources to infer their secrets. Such a threat will significantly imperil the potential positive impacts that SGX could bring to the society, such as protecting software intellectual property and securely distributing and processing secret data.This research aims to address the side-channel hazards in SGX and advance the field in two aspects: First, it will develop novel principles and techniques to detect vulnerabilities in enclave programs, by modeling side-channel vulnerabilities and differentially analyzing their memory access patterns according to the model specification. Second, it will enhance enclave programs to thwart side-channel attacks at runtime by leveraging novel Timed Execution techniques and/or Address Space Layout Obfuscation mechanisms. The research will not only push forward the frontier of side-channel studies, but have broader societal impacts in the following aspects: First, because side-channels are major security concerns of security-critical applications to which shielded execution is the most valuable, the project will accelerate the broader acceptance of the shielded execution paradigm and the SGX technology. Second, through a set of educational tasks, the project will promote awareness of side-channel hazards to students, researchers, industry partners, and the general public, and hence motivate the adoption of the side-channel defense techniques in real-world applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(11)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/dsc47296.2019.8937682
发表时间:
2019-11
期刊:
2019 IEEE Conference on Dependable and Secure Computing (DSC)
影响因子:
--
作者:
[Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang]
通讯作者:
Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Mengya Zhang;Xiaokuan Zhang;Yinqian Zhang;Zhiqiang Lin]
通讯作者:
Mengya Zhang;Xiaokuan Zhang;Yinqian Zhang;Zhiqiang Lin
DOI:
10.14722/ndss.2019.23210
发表时间:
2019
期刊:
Proceedings 2019 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang]
通讯作者:
Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang
DOI:
10.1145/3321705.3329848
发表时间:
2019-07
期刊:
Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子:
--
作者:
[Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang]
通讯作者:
Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang
DOI:
10.14722/ndss.2020.23105
发表时间:
2019-12
期刊:
ArXiv
影响因子:
--
作者:
[Yuan Xiao;Yinqian Zhang;R. Teodorescu]
通讯作者:
Yuan Xiao;Yinqian Zhang;R. Teodorescu
共 7 条
CSR: Small: Self-Monitoring Virtual Machines for Performance Guarantees in Public Clouds
-
批准号:1718084
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Yinqian Zhang
-
依托单位:
CRII: SaTC: Rethinking Side Channel Security on Untrusted Operating Systems
-
批准号:1566444
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2016
-
负责人:Yinqian Zhang
-
依托单位:
海外基金