SGX-UAM: A Secure Unified Access Management Scheme With One Time Passwords via Intel SGX
نویسندگان
چکیده
With the convergence of fixed and mobile networks, heterogeneous networks are becoming ubiquitous. Internet giants seeing plight identity authentication. To address this issue, unified access management (UAM) was conceived. This paper provides a novel scheme, named SGX-UAM, with one-time passwords (OTPs) based on Intel software guard extensions (SGX). SGX-UAM outperforms generic UAM for providing resistance to most client attacks, man-in-the-middle (MITM) phishing replay attacks denial service (DoS) which implementaions vulnerable. Specifically, prevented by ensuring input security memory security, where former is achieved through shuffle mapping “periodic hooking” strategy, latter mainly guaranteed SGX; MITM transferring ciphertext rather than plaintext; avoided authorization control; cannot succeed because we adopts OTPs, contain time-related dynamic factors that expire in few seconds; as DoS attack, blunted its edge blocking-invocation identical user connection. also differs from it relieves concerns sevice providers (SPs) protects users' privacy at little cost performance. An exceptional value brings lightweight OTP solution eliminates need additional hardware devices, thus reducing costs. The experimental results show consumes almost same time OpenID OAuth2.0 one login request performs steadily when handling sequential requests. Furthermore, resource usage acceptable.
منابع مشابه
SCONE: Secure Linux Containers with Intel SGX
Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, and Andre Martin, Technische Universität Dresden; Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O’Keeffe, and Mark L Stillwell, Imperial College London; David Goltzsche, Technische Universität Braunschweig; Dave Eyers, University of Otago; Rüdiger Kapitza, Technische Universität Braunschweig; Peter Pietzuch, Imperial College L...
متن کاملSecure Cloud Micro Services Using Intel SGX
The micro service paradigm targets the implementation of large and scalable systems while enabling fine-grained service-level maintainability. Due to their scalability, such architectures are frequently used in cloud environments, which are often subject to privacy and trust issues hindering the deployment of services dealing with sensitive data. In this paper we investigate the integration of ...
متن کاملIntel SGX Explained
Intel’s Software Guard Extensions (SGX) is a set of extensions to the Intel architecture that aims to provide integrity and confidentiality guarantees to securitysensitive computation performed on a computer where all the privileged software (kernel, hypervisor, etc) is potentially malicious. This paper analyzes Intel SGX, based on the 3 papers [14, 79, 139] that introduced it, on the Intel Sof...
متن کاملGlamdring: Automatic Application Partitioning for Intel SGX
Trusted execution support in modern CPUs, as offered by Intel SGX enclaves, can protect applications in untrusted environments. While prior work has shown that legacy applications can run in their entirety inside enclaves, this results in a large trusted computing base (TCB). Instead, we explore an approach in which we partition an application and use an enclave to protect only security-sensiti...
متن کاملSecure Multiparty Computation from SGX
Isolated Execution Environments (IEE) offered by novel commodity hardware such as Intel’s SGX deployed in Skylake processors permit executing software in a protected environment that shields it from a malicious operating system; it also permits a remote user to obtain strong interactive attestation guarantees on both the code running in an IEE and its input/output behaviour. In this paper we sh...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: IEEE Access
سال: 2021
ISSN: ['2169-3536']
DOI: https://doi.org/10.1109/access.2021.3063770