课题基金 / 基金详情

CAP-TEE: Capability Architectures for Trusted Execution

CAP-TEE: Capability Architectures for Trusted Execution
CAP-TEE:可信执行的能力架构
批准号:
EP/V000454/1
负责人:
David Oswald
金额:
$127.45万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --

项目摘要

项目成果

David Oswald的其他基金

相似基金

相关文献

中文摘要
翻译
可信执行环境(TEE)使用安全“飞地”内的安全敏感数据(例如,个人数据、银行信息或加密密钥)将计算与不可信操作系统的其余部分屏蔽。TEE保护其数据和代码,即使攻击者已经获得了对系统不受信任部分的完全根访问权限。如今,ARM Trustzone和Intel SGX等TEE因此广泛用于通用设备,包括大多数笔记本电脑和智能手机。但随着越来越广泛的使用,TEE已被证明容易受到许多基于硬件和软件的攻击,通常会导致受保护数据的完全妥协。在这个项目中,我们将使用能力架构(例如由CHERI项目开发的)来保护TEE免受这种最先进的攻击。我们解决了从软件漏洞(如缓冲区溢出)到复杂的硬件攻击(如故障注入)的各种威胁。CAP-TEE将为未来一代更安全的TEE提供强大的开源基础。在开发这种颠覆性技术时,关键是要尽量减少将现有代码库移植到新系统的工作,以促进实际应用。因此,在CAP-TEE中,我们专注于简化向功能启用TEE过渡的技术。在汽车和铁路行业的工业案例研究中,我们将展示如何将用内存不安全的语言(如C(++))编写的复杂代码无缝地迁移到我们的平台上,从而在不进行全面重新设计的情况下受益于更高的安全性。
英文摘要
Trusted Execution Environments (TEEs) shield computations using security-sensitive data (e.g. personal data, banking information, or encryption keys) inside a secure "enclave" from the rest of the untrusted operating system. A TEE protects its data and code even if an attacker has gained full root access to the untrusted parts of the system. Today, TEEs like ARM Trustzone and Intel SGX are therefore widely used in general-purposes devices, including most laptops and smartphones. But with increasingly wide-spread use, TEEs have proven vulnerable to a number of hardware and software-based attacks, often leading to the complete compromise of the protected data. In this project, we will use capability architectures (as e.g. developed by the CHERI project) to protect TEEs against such state-of-the-art attacks. We address a wide range of threats from software vulnerabilities such as buffer overflows to sophisticated hardware attacks like fault injection. CAP-TEE will provide a strong, open-source basis for the future generation of more secure TEEs. When developing such disruptive technologies, it is key to minimise the efforts for porting existing codebases to the new system to facilitate adoption in practice. In CAP-TEE, we therefore focus on techniques to ease the transition to our capability-enabled TEE. In industrial cases studies for the automotive and rail sector, we will demonstrate how complex code written in a memory-unsafe language like C(++) can be seamlessly moved to our platform to benefit from increased security without a full redesign.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者: [Zitai Chen;G. Vasilakis;Kit Murdock;Edward Dean;David F. Oswald;Flavio D. Garcia]
通讯作者: Zitai Chen;G. Vasilakis;Kit Murdock;Edward Dean;David F. Oswald;Flavio D. Garcia
Computer Security - ESORICS 2022 - 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26-30, 2022, Proceedings, Part II
计算机安全 - ESORICS 2022 - 第 27 届欧洲计算机安全研究研讨会,丹麦哥本哈根,2022 年 9 月 26-30 日,会议记录,第二部分
DOI: 10.1007/978-3-031-17146-8_12
发表时间: 2022
期刊:
影响因子: --
作者: [Aldoseri A]
通讯作者: Aldoseri A
DOI: 10.48550/arxiv.2301.05538
发表时间: 2023-01
期刊: ArXiv
影响因子: --
作者: [Zitai Chen;David F. Oswald]
通讯作者: Zitai Chen;David F. Oswald
DOI: 10.1145/3491264
发表时间: 2021-10
期刊: Digital Threats: Research and Practice (DTRAP)
影响因子: --
作者: [F. Alder;Jo Van Bulck;Jesse Spielman;David F. Oswald;Frank Piessens]
通讯作者: F. Alder;Jo Van Bulck;Jesse Spielman;David F. Oswald;Frank Piessens
共 6 条
    IOTEE: Securing and analysing trusted execution beyond the CPU
    • 批准号:
      EP/X03738X/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $57.12万
    • 财政年份:
      2023
    • 负责人:
      David Oswald
    • 依托单位:
    国内基金
    海外基金
    基于AI算法4D-TEE自动化定量分析技术辅助评估心脏瓣膜病应用研究
    • 批准号:
      JCZRLH202500705
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2025
    • 负责人:
    • 依托单位:
    基于TEE双模态图像引导生成模型的MitraClip术前模拟研究
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      15.0万元
    • 批准年份:
      2024
    • 负责人:
      王青
    • 依托单位:
    以契约为层间安全承诺的TEE系统隔离机制分层验证研究
    • 批准号:
      62372311
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      张倩颖
    • 依托单位:
    面向机密虚拟机TEE架构的安全操作系统研究