TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
批准号:
1834213
负责人:
Zhiqiang Lin
金额:
$46.15万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-01-01 至 2022-05-31
中文摘要
英特尔软件防护扩展(SGX)是一项新技术,用于在恶劣环境中实现安全可靠的计算。然而,SGX仅仅是一组指令。它的软件支持,包括操作系统支持,工具链和库,目前以封闭的方式开发,将其影响限制在英特尔和微软等大公司的边界内。同时,SGX不会自动保护一切,它仍然面临各种攻击,如受控侧通道和飞地内存损坏。本研究探讨了如何使应用程序开发人员能够安全地使用SGX指令,并提供开源软件支持,包括工具链、编程抽象(例如库)和操作系统支持(例如内核模块)。此外,本研究系统地探索了保护SGX程序免受enclave本身攻击和击败底层操作系统恶意使用SGX所需的系统和软件防御。
英文摘要
The Intel Software Guard Extensions (SGX) is a new technology introduced to make secure and trustworthy computing in a hostile environment practical. However, SGX is merely just a set of instructions. Its software support that includes the OS support, toolchain and libraries, is currently developed in a closed manner, limiting its impact only within the boundary of big companies such as Intel and Microsoft. Meanwhile, SGX does not automatically secure everything and it still faces various attacks such as controlled-side channel and enclave memory corruption.This research investigates how to enable application developers to securely use the SGX instructions, with an open source software support including a toolchain, programming abstractions (e.g., library), and operating system support (e.g., kernel modules). In addition, this research systematically explores the systems and software defenses necessary to secure the SGX programs from the enclave itself and defeat the malicious use of SGX from the underlying OS.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
-
批准号:2330264
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2023
-
负责人:Zhiqiang Lin
-
依托单位:
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
-
批准号:2207202
-
项目类别:Continuing Grant
-
资助金额:$88.0万
-
财政年份:2022
-
负责人:Zhiqiang Lin
-
依托单位:
Collaborative Research: PPoSS: Planning: Scaling Autonomous Vehicle Systems at the Edge: from On-Board Processing to Cloud Infrastructure
-
批准号:2118491
-
项目类别:Standard Grant
-
资助金额:$4.24万
-
财政年份:2021
-
负责人:Zhiqiang Lin
-
依托单位:
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
-
批准号:1834214
-
项目类别:Standard Grant
-
资助金额:$11.09万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1834216
-
项目类别:Continuing Grant
-
资助金额:$39.34万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
-
批准号:1834215
-
项目类别:Continuing Grant
-
资助金额:$48.8万
-
财政年份:2018
-
负责人:Zhiqiang Lin
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700507
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Zhiqiang Lin
-
依托单位:
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
-
批准号:1564112
-
项目类别:Standard Grant
-
资助金额:$52.82万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
EDU: Collaborative: Using Virtual Machine Introspection for Deep Cyber Security Education
-
批准号:1623325
-
项目类别:Standard Grant
-
资助金额:$14.99万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
CI-P: Collaborative: A Community-Driven Open Research Infrastructure for Intel SGX
-
批准号:1629951
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2016
-
负责人:Zhiqiang Lin
-
依托单位:
CAREER: A Dual-VM Binary Code Reuse Based Framework for Automated Virtual Machine Introspection
-
批准号:1453011
-
项目类别:Continuing Grant
-
资助金额:$53.51万
-
财政年份:2015
-
负责人:Zhiqiang Lin
-
依托单位:
海外基金