RT-trust: automated refactoring for trusted execution under real-time constraints

RT-trust: automated refactoring for trusted execution under real-time constraints
复制标题

RT-trust:实时约束下可信执行的自动重构

DOI:
10.1145/3278122.3278137
复制
发表时间:
2018
期刊:
International Conference on Generative Programming: Concepts & Experience
影响因子:
--
通讯作者:
Tilevich, Eli
Tilevich, Eli
中科院分区:
--
文献类型:
--
作者:
Liu, Yin;An, Kijin;Tilevich, Eli

文献摘要

参考文献

被引文献

相似文献

实时系统必须满足严格的时效性要求。这些系统还经常需要保护其关键程序信息(CPI)免受对抗性干扰和知识产权盗窃。可信执行环境(TEE)在专用处理器上执行CPI任务,从而提供硬件保护。然而,使编写的系统在没有TEE的环境中执行需要将代码划分为常规和可信部分。这个过程涉及复杂的手动程序转换,不仅费力和智力上令人厌倦,而且难以验证和验证对实时约束的遵守。为了解决这些问题,本文提出了新的程序分析和转换技术,开发人员通过声明式元编程模型。开发人员声明性地指定系统的CPI部分。自定义静态分析检查CPI规范的有效性,而基于探测的分析有助于确定转换后的系统是否继续满足原始实时约束,并通过反馈循环建议如何修改代码,以便隔离其CPI。最后,自动化重构隔离CPI部分以用于基于TEE的执行,通过生成的对TEE API的调用进行通信。我们已经通过成功实现几个微基准和无人机自动驾驶仪的CPI部分的可信执行来评估我们的方法。我们的方法表明,声明性元编程的承诺,减少程序员的努力,以适应系统的实时约束下的可信执行。
Real-time systems must meet strict timeliness requirements. These systems also often need to protect their critical program information (CPI) from adversarial interference and intellectual property theft. Trusted execution environments (TEE) execute CPI tasks on a special-purpose processor, thus providing hardware protection. However, adapting a system written to execute in environments without TEE requires partitioning the code into the regular and trusted parts. This process involves complex manual program transformations that are not only laborious and intellectually tiresome, but also hard to validate and verify for the adherence to real-time constraints. To address these problems, this paper presents novel program analyses and transformation techniques, accessible to the developer via a declarative meta-programming model. The developer declaratively specifies the CPI portion of the system. A custom static analysis checks CPI specifications for validity, while probe-based profiling helps identify whether the transformed system would continue to meet the original real-time constraints, with a feedback loop suggesting how to modify the code, so its CPI can be isolated. Finally, an automated refactoring isolates the CPI portion for TEE-based execution, communicated with through generated calls to the TEE API. We have evaluated our approach by successfully enabling the trusted execution of the CPI portions of several microbenchmarks and a drone autopilot. Our approach shows the promise of declarative meta-programming in reducing the programmer effort required to adapt systems for trusted execution under real-time constraints.
GPCE’18,2018年11月5日至6日,美国马萨诸塞州波士顿
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者:
Ahmad Salim Al;T. P. Jensen;A. S. Dimovski;A. Wąsowski
通讯作者: A. Wąsowski
DOI: --
发表时间: 2002
期刊: Object Modeling with the OCL
影响因子: --
作者:
S. Flake;W. Müller
通讯作者: W. Müller
在运行时监控实时约束的形式主义
DOI: --
发表时间: 1990
期刊: [1990] Digest of Papers. Fault-Tolerant Computing: 20th International Symposium
影响因子: --
作者:
F. Jahanian;A. Goyal
通讯作者: A. Goyal
面向对象的实时语言设计:时序约束的构造
DOI: --
发表时间: 1990
期刊:
影响因子: --
作者:
IshikawaYutaka;TokudaHideyuki
通讯作者: TokudaHideyuki
TZSlicer:用于硬件隔离的安全感知动态程序切片
DOI: --
发表时间: 2018
期刊: IEEE International Symposium on Hardware Oriented Security and Trust
影响因子: --
作者:
Mengmei Ye;Jonathan M. Sherman;W. Srisa;Sheng Wei
通讯作者: Sheng Wei