课题基金 / 基金详情

基于RISC-V架构的可信执行环境研究

批准号:
62102175
项目类别:
青年科学基金项目(C类)
资助金额:
30.0 万元
负责人:
宁振宇
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2021
项目状态:
已结题
项目参与者:
宁振宇

项目摘要

结项摘要

相似基金

相关文献

中文摘要
随着国际形势的发展,传统芯片架构的不可控风险逐渐增大。由于开放性高、自主可控性强,开源的RISC-V架构逐步赢得了市场青睐。然而,RISC-V架构中并未提供对可信执行环境的支持,关于可信执行环境的研究也存在较多缺陷和限制。本项目聚焦于RISC-V架构下可信执行环境的研究。首先,从自身的安全保护策略和对恶意开发者的限制等方面研究可信执行环境的安全性。其次,为可信执行环境提供充分的功能支持,并允许其以动态管理的方式新增支持或修复已有漏洞。最后,通过在不修改RISC-V架构、不新增硬件支持的基础上构建标准化的可信执行环境来促进其在不同硬件设备上的部署,同时通过简化相关应用开发流程以方便开发者的使用。本项目提出的在RISC-V架构下构建可信执行环境的方案具有安全性高、功能完备、易用性好的优势,研究成果对提升商用RISC-V架构的安全性、促进RISC-V产业链的发展具有理论研究意义和实际应用价值。
英文摘要
With the development of international relations, the risk of facing restrictions on devices with traditional instruction architecture is growing. Meantime, the open-source RISC-V architecture won the favor of the market due to its open nature and high controllability. However, RISC-V architecture did not offer official support for Trusted Execution Environment (TEE), and the existing TEE-related research suffers from design flaws and hardware restrictions. This project focuses on the research of RISC-V-based TEE. First, we carefully design security policies to guarantee the security of the TEE itself and place additional restrictions to defend against malicious developers. Secondly, to enrich the functionality supported by the proposed TEE, we design a dynamic management mechanism to facilitate dynamically adding components or patching buggy components. Last but not least, we propose a standard design of TEE on RISC-V architecture without modifying the ISA or requiring additional hardware to promote its deployment on various hardware devices. Moreover, we plan to simplify the development of TEE applications to make the proposed TEE easy to use. In summary, this project introduces a design of TEE on RISC-V architecture with high security, full functionality, and optimized ease of use. The outcome of the project is expected to improve the security of commercial RISC-V devices and promote the development and deployment of the RISC-V environment.
本项目是针对RISC-V架构下可信执行环境的研究。首先,项目利用RISC-V架构中的PMP实现了可信执行环境中的内存隔离,确保了其安全性。其次,通过设计反向PMP和逻辑PMP,项目实现了可信执行环境中功能的可扩展性和热拔插热性。最后,本项目的方案提供了对标准RISC-V架构和Linux中原生可执行文件格式的支持,提升了系统的易用性。项目组申请国家专利3项,共发表论文10篇,其中CCF-A类期刊3篇,CCF-A类会议5篇(包括安全顶会3篇),培养博士1人,硕士4人,参加国际学术活动/会议并报告研究成果2次,参加国内学术会议2次,举办交流讲座2次。研究成果对提升RISC-V架构中软件生态的安全性具有重要意义。
国内基金
海外基金