课题基金 / 基金详情

From Trusted Computing to Trustworthy Execution

From Trusted Computing to Trustworthy Execution
从可信计算到可信执行
批准号:
RGPIN-2020-04734
负责人:
Zhao, Lianying
金额:
$2.11万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31

项目摘要

项目成果

Zhao, Lianying的其他基金

相似基金

相关文献

中文摘要
翻译
当计算机用户访问涉及敏感信息的远程服务时,在可以信任服务结果之前,确保服务程序以完整性和机密性执行非常重要。为此,引入了可信计算(TC),它对初始完整性执行一定的加密度量,并将程序与外部隔离以实现完整性和机密性。为了最终向用户提供这种保护的证据,一种称为认证的机制将测量结果签名为永远不会暴露在其他地方的长期秘密,并将其发送给用户。用户选择信任执行,因为测量结果来自长期秘密(使用该秘密的公开部分进行验证),并且在密码学上与预期的程序匹配。
英文摘要
When a computer user accesses a remote service involving sensitive information, ensuring that the service program has executed with integrity and confidentiality is important before the service outcome can be trusted. For this purpose, trusted computing (TC) is introduced, which performs certain cryptographic measurements for inital integrity and isolates the program from outside for integrity and confidentiality. To eventually provide evidence of such protection to the user, a mechanism called attestation signs the measurements with a long-term secret that never gets exposed elsewhere and sends them to the user. The user chooses to trust the execution, seeing the measurements come from the long-term secret (verified with the public part of that secret) and cryptographically match the intended program. Nonetheless, current TC is still sub-ideal to be considered trustworthy. Things can go wrong in the following ways (examples): 1) the long-term secret can be learned by an adversary from intrinsic side channels, i.e., even when hardware never exposes the secret as the computer architecture specifies, the unspecified (mostly timing) behavior still leaks the secret. 2) with guaranteed initial integrity, a program's execution dynamics can largely be affected by data exchange with the outside, even if the program itself is isolated. Such dynamics include control/data flow and memory access safety. Therefore, the execution can deviate from what was originally measured. 3) the attestation request can be relayed to and fulfilled by a computer possessing the correct long-term secret, but different from where the program has actually run. I propose to advance TC to be closer to trustworthiness, embodied mainly by architectural discretization of secure elements and execution binding. The secure element (SE) is a hardware component where the long-term secrets are stored and protected. Compared to merely physical discreteness, the proposed architectural discretization makes sure that secrets in the SE never get exposed to the rich processor environment (never leaving the SE), and the involved operations are not visible to any system software and firmware. The discrete SE is designed with minimal complexity. This way, the aforementioned side channels are no longer applicable, due to no resource sharing. Execution binding (as opposed to platform binding to avoid attestation relay) is to include the execution dynamics into attestation so that correct attestation result can reflect (to a larger extent) correct execution. Such an SE design also allows the trust to be user-oriented, e.g., open provisioning and multi-purpose/multi-user SE.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
From Trusted Computing to Trustworthy Execution
  • 批准号:
    RGPIN-2020-04734
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.11万
  • 财政年份:
    2022
  • 负责人:
    Zhao, Lianying
  • 依托单位:
From Trusted Computing to Trustworthy Execution
  • 批准号:
    RGPIN-2020-04734
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.11万
  • 财政年份:
    2021
  • 负责人:
    Zhao, Lianying
  • 依托单位:
Towards 5G-ready Security Evaluation
  • 批准号:
    560273-2020
  • 项目类别:
    Alliance Grants
  • 资助金额:
    $2.19万
  • 财政年份:
    2021
  • 负责人:
    Zhao, Lianying
  • 依托单位:
Towards 5G-ready Security Evaluation
  • 批准号:
    560273-2020
  • 项目类别:
    Alliance Grants
  • 资助金额:
    $2.19万
  • 财政年份:
    2020
  • 负责人:
    Zhao, Lianying
  • 依托单位:
海外基金