Initializing trust in smart devices via presence attestation

Initializing trust in smart devices via presence attestation
复制标题

通过存在证明初始化对智能设备的信任

DOI:
10.1016/j.comcom.2018.07.004
复制
发表时间:
2018
影响因子:
6
通讯作者:
Tsudik, Gene
Tsudik, Gene
中科院分区:
计算机科学3区
文献类型:
--
作者:
Ding, Xuhua;Tsudik, Gene

文献摘要

被引文献

相似文献

许多个人计算和更专业的设备(例如,高端物联网)现在都配备了复杂的处理器,而这些处理器在几年前只存在于高端台式机和服务器上。这样的处理器通常包括DRTM(用于测量的动态信任根)形式的重要硬件安全组件,其发起信任并抵抗软件(甚至一些物理)攻击。然而,尽管之前对使用安全硬件建立信任进行了大量研究,但DRTM安全性始终被认为没有人类用户的任何参与,这代表了一个重要的缺失环节。这就提出了一个重要的挑战:用户(所有者)如何确定他或她的设备上当前是否有真正的DRTM?我们认为,为了应对这一挑战,需要一种新的安全服务,称为“存在证明”(PA)。虽然PA本身仅具有短暂的价值,但它可以用于在设备的DRTM和具有用户信任的另一设备之间建立长期安全信道。在本文中,我们概述了PA的概念,这是基于强制性的(虽然,理想情况下是最小的)用户参与,概述了最近的结果,并讨论了未来的研究方向。
Many personal computing and more specialized (eg, high-end IoT) devices are now equipped with sophisticated processors that only a few years ago were present only on high-end desktops and servers. Such processors often include an important hardware security component in the form of a DRTM (Dynamic Root of Trust for Measurement) which initiates trust and resists software (and even some physical) attacks. However, despite substantial prior research on trust establishment with secure hardware, DRTM security was always considered without any involvement of the human user, who represents a vital missing link. This prompts an important challenge: how can a user (owner) determine whether a genuine DRTM is currently active on his or her device? We believe that, in order to address this challenge, a new security service–called “Presence Attestation”(P A)–is needed. While P A, by itself, has only ephemeral value, it can be used to set up a long-term secure channel between the device’s DRTM and another device with the user’s trust. In this paper, we outline the notion of P A, which is based on mandatory (though, ideally minimal) user participation, overview recent results, and discuss directions for future research.