CAREER: Taming the Side-Channel Hazards in the Shielded Execution Paradigm
CAREER: Taming the Side-Channel Hazards in the Shielded Execution Paradigm
批准号:
1750809
负责人:
Yinqian Zhang
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-04-01 至 2020-12-31
中文摘要
英特尔的软件保护扩展(SGX)是在最新的英特尔处理器中可用的硬件扩展,它为软件应用程序提供称为Enclaves的屏蔽执行环境,以保护它们的机密性和完整性,使其免受操作系统的攻击。SGX的广泛采用将促进在操作系统不完全受信任的情况下(如公共云)增强软件安全性的屏蔽执行范例。然而,最近的研究表明,新交所很容易受到旁路威胁的影响,在旁路威胁中,系统软件测量飞地对系统资源或微体系结构资源的使用,以推断其秘密。该研究旨在解决SGX中的侧通道危害,并在两个方面推进该领域的研究:首先,通过对侧通道漏洞进行建模,并根据模型规范对其内存访问模式进行差异化分析,开发新的检测Enclave程序漏洞的原理和技术。其次,它将通过利用新的定时执行技术和/或地址空间布局混淆机制来增强Enclave程序,以在运行时阻止侧通道攻击。该研究不仅将推动侧通道研究的前沿,还将在以下方面产生更广泛的社会影响:首先,由于侧通道是屏蔽执行最有价值的安全关键型应用程序的主要安全问题,该项目将加速屏蔽执行范例和SGX技术的更广泛接受。其次,通过一系列教育任务,该项目将提高学生、研究人员、行业合作伙伴和普通公众对侧通道危害的认识,从而推动在实际应用中采用侧通道防御技术。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Intel's Software Guard Extension (SGX) is a hardware extension available in recent Intel processors, which provides software applications with shielded execution environments, called enclaves, to protect their confidentiality and integrity against compromised operating systems. The wide adoption of SGX will foster a shielded execution paradigm for enhancing software security in situations where the operating systems are not entirely trusted, such as public clouds. However, recent studies have suggested that SGX is vulnerable to side-channel threats, in which the system software measures the enclaves' use of system resources or micro-architectural resources to infer their secrets. Such a threat will significantly imperil the potential positive impacts that SGX could bring to the society, such as protecting software intellectual property and securely distributing and processing secret data.This research aims to address the side-channel hazards in SGX and advance the field in two aspects: First, it will develop novel principles and techniques to detect vulnerabilities in enclave programs, by modeling side-channel vulnerabilities and differentially analyzing their memory access patterns according to the model specification. Second, it will enhance enclave programs to thwart side-channel attacks at runtime by leveraging novel Timed Execution techniques and/or Address Space Layout Obfuscation mechanisms. The research will not only push forward the frontier of side-channel studies, but have broader societal impacts in the following aspects: First, because side-channels are major security concerns of security-critical applications to which shielded execution is the most valuable, the project will accelerate the broader acceptance of the shielded execution paradigm and the SGX technology. Second, through a set of educational tasks, the project will promote awareness of side-channel hazards to students, researchers, industry partners, and the general public, and hence motivate the adoption of the side-channel defense techniques in real-world applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(11)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/dsc47296.2019.8937682
发表时间:
2019-11
期刊:
2019 IEEE Conference on Dependable and Secure Computing (DSC)
影响因子:
--
作者:
[Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang]
通讯作者:
Guoxing Chen;Mengyuan Li;Fengwei Zhang;Yinqian Zhang
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Mengya Zhang;Xiaokuan Zhang;Yinqian Zhang;Zhiqiang Lin]
通讯作者:
Mengya Zhang;Xiaokuan Zhang;Yinqian Zhang;Zhiqiang Lin
DOI:
10.1145/3321705.3329848
发表时间:
2019-07
期刊:
Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子:
--
作者:
[Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang]
通讯作者:
Huibo Wang;Erick Bauman;Vishal M. Karande;Zhiqiang Lin;Yueqiang Cheng;Yinqian Zhang
DOI:
10.1145/3372297.3423344
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Haohuang Wen;Zhiqiang Lin;Yinqian Zhang]
通讯作者:
Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
DOI:
10.14722/ndss.2019.23210
发表时间:
2019
期刊:
Proceedings 2019 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang]
通讯作者:
Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang
共 7 条
CSR: Small: Self-Monitoring Virtual Machines for Performance Guarantees in Public Clouds
-
批准号:1718084
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Yinqian Zhang
-
依托单位:
CRII: SaTC: Rethinking Side Channel Security on Untrusted Operating Systems
-
批准号:1566444
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2016
-
负责人:Yinqian Zhang
-
依托单位:
海外基金