A TEE-aware compartmentalization framework based on DSbD
A TEE-aware compartmentalization framework based on DSbD
批准号:
10004575
负责人:
金额:
$10.11万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2021
资助国家:
英国
项目状态:
已结题
起止时间:
2021 至 --
中文摘要
通过这个项目,我们将有助于我们的行业了解如何建立一个基于可信执行环境(TEE)的能力架构,在安全和正常的世界中提供强大的隔离和安全的数据共享。作为一家公司,我们的产品需要这一点,但机会远远大于我们单独的部门(身份验证)。许多用例存在,例如在金融服务中,在企业和媒体中,以增强交易,数据和内容的安全性。有了这笔赠款,我们的目标是研究一种解决方案,可以减轻现有TEE造成的当前漏洞,通过研究基于能力架构的TEE开发框架,用于在安全和正常世界中强隔离和安全共享系统资源和应用数据,通过具有可靠管道的隔离隔间控制对象功能内的故障。我们是一家充满激情的AIoT SME,但安全性支撑着我们的技术,我们的定位和我们的增长。TEES是我们的CTO做了大量工作的领域。赢得这笔赠款将使我们能够把资源背后的真实的市场问题。我们的愿景是,这项研究可以作为我们未来构建原型的基础,这不仅可以加强我们产品的安全性,还可以在英国数字计算基础设施的激进化中发挥我们的作用。使用FVP平台与CHERI处理器原型,CheriBSD内核,Clang/LLVM和CheriBSD的用户空间,我们的主要目标是:* 调查性能、语义、与现有标准TEE环境相比,分区TEE的漏洞缓解措施和优点英特尔SGX和ARM TrustZone TEE* 了解这样的框架是否有助于简化开发和采用,以及它是否支持硬件独立性 * 探索飞地生命周期管理我们将通过分离正常世界和安全世界功能之间的关注点来关注应用层划分,以及在安全(飞地)世界中进一步分解功能,包括具有隔离隔间的模块化抽象,这些隔离隔间具有单一责任原则和特权分离。这是创新的,因为使用DSbD技术,它旨在将两个世界之间的关注点从硬件或操作系统堆栈中分离出来,同时保持TEE的完整性,但解决在完成这项研究之后,我们努力构建一个原型框架,以便在内部进行进一步测试,最好是与更广泛的软件和DSbD社区一起进行测试。
英文摘要
Through this project, we will contribute to our industry's understanding of how to build a capability architecture based Trusted Execution Environment (TEE) that provides strong isolation and secure data sharing across the secure and normal worlds. As a company, we require this for our products but the opportunity is much bigger than our sector alone (identity verification). Many use cases exist, for example in financial services, in enterprise and in media to enhance security around transactions, data and content.With this grant, our objective is to investigate a solution that could mitigate current vulnerabilities posed by existing TEEs, by researching a capability architecture based TEE development framework for strong isolation and secure sharing of systems resources and application data across secure and normal worlds by controlling dataflows within object capabilities via isolated compartments with assured pipelines.We are a passionate AIOT SME but security underpins our technology, our positioning and our growth. TEEs is an area our CTO has done a lot of work in. Winning this grant would allow us to put resource behind this real market problem. Our vision is that this research could be used as a basis for us to build a prototype in the future, which would strengthen not only our product's security, but also play our part in radicalising the UK's digital computing infrastructure.Using the FVP platform with CHERI processor prototype, CheriBSD kernel, Clang/LLVM and CheriBSD's userspace, our key objectives are to:* Investigate the performance, semantics, vulnerability mitigations and merits of compartmentalized TEE in comparison to existing standard TEE environments Intel SGX and ARM TrustZone TEE* Understand if a framework like this helps towards ease of development and adoption as well as knowing if it supports hardware independence* Explore enclave life cycle managementWe will focus on the application layer compartmentalization by separation of concerns between the normal world and secure world functions, and further decomposition of capabilities within the secure (enclave) world including modular abstraction with isolated compartments with single responsibility principles and the separation of privileges.This is innovative because working with DSbD technologies, it aims to move the separation of concerns between the two worlds away from the hardware or the OS stack while retaining the integrity of TEE but addressing the vulnerabilities of existing approaches.After completing this research, we endeavour to build a prototype framework for further testing internally, and ideally with the wider software and DSbD community.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
动态无线传感器网络弹性化容错组网技术与传输机制研究
-
批准号:61001096
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2010
-
负责人:化存卿
-
依托单位:
基于计算和存储感知的运动估计算法与结构研究
-
批准号:60803013
-
项目类别:青年科学基金项目
-
资助金额:18.0万元
-
批准年份:2008
-
负责人:邓磊
-
依托单位: