课题基金 / 基金详情

A TEE-aware compartmentalization framework based on DSbD

A TEE-aware compartmentalization framework based on DSbD
基于 DSbD 的 TEE 感知划分框架
批准号:
10004575
负责人:
金额:
$10.11万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2021
资助国家:
英国
项目状态:
已结题
起止时间:
2021 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Through this project, we will contribute to our industry's understanding of how to build a capability architecture based Trusted Execution Environment (TEE) that provides strong isolation and secure data sharing across the secure and normal worlds. As a company, we require this for our products but the opportunity is much bigger than our sector alone (identity verification). Many use cases exist, for example in financial services, in enterprise and in media to enhance security around transactions, data and content.With this grant, our objective is to investigate a solution that could mitigate current vulnerabilities posed by existing TEEs, by researching a capability architecture based TEE development framework for strong isolation and secure sharing of systems resources and application data across secure and normal worlds by controlling dataflows within object capabilities via isolated compartments with assured pipelines.We are a passionate AIOT SME but security underpins our technology, our positioning and our growth. TEEs is an area our CTO has done a lot of work in. Winning this grant would allow us to put resource behind this real market problem. Our vision is that this research could be used as a basis for us to build a prototype in the future, which would strengthen not only our product's security, but also play our part in radicalising the UK's digital computing infrastructure.Using the FVP platform with CHERI processor prototype, CheriBSD kernel, Clang/LLVM and CheriBSD's userspace, our key objectives are to:* Investigate the performance, semantics, vulnerability mitigations and merits of compartmentalized TEE in comparison to existing standard TEE environments Intel SGX and ARM TrustZone TEE* Understand if a framework like this helps towards ease of development and adoption as well as knowing if it supports hardware independence* Explore enclave life cycle managementWe will focus on the application layer compartmentalization by separation of concerns between the normal world and secure world functions, and further decomposition of capabilities within the secure (enclave) world including modular abstraction with isolated compartments with single responsibility principles and the separation of privileges.This is innovative because working with DSbD technologies, it aims to move the separation of concerns between the two worlds away from the hardware or the OS stack while retaining the integrity of TEE but addressing the vulnerabilities of existing approaches.After completing this research, we endeavour to build a prototype framework for further testing internally, and ideally with the wider software and DSbD community.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
动态无线传感器网络弹性化容错组网技术与传输机制研究
  • 批准号:
    61001096
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2010
  • 负责人:
    化存卿
  • 依托单位:
基于计算和存储感知的运动估计算法与结构研究
  • 批准号:
    60803013
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    18.0万元
  • 批准年份:
    2008
  • 负责人:
    邓磊
  • 依托单位: