ICE : A Passive , High - Speed , State - Continuity Scheme ( Extended
نویسندگان
چکیده
The amount of trust that can be placed in commodity computing platforms is limited by the likelihood of vulnerabilities in their huge software stacks. Protected-module architectures, such as Intel SGX, provide an interesting alternative by isolating the execution of software modules. To minimize the amount of code that provides support for the protected-module architecture, persistent storage of (confidentiality and integrity protected) states of modules can be delegated to the untrusted operating system. But precautions should be taken to ensure state continuity: an attacker should not be able to cause a module to use stale states (a so-called rollback attack), and while the system is not under attack, a module should always be able to make progress, even when the system could crash or lose power at unexpected, random points in time (i.e., the system should be crash resilient). Providing state-continuity support is non-trivial as many algorithms are vulnerable to attack, require on-chip non-volatile memory, wear-out existing offchip secure non-volatile memory and/or are too slow for many applications. We introduce ICE, a system and algorithm providing state-continuity guarantees to protected modules. ICE’s novelty lies in the facts that (1) it does not rely on secure non-volatile storage for every state update (e.g., the slow TPM chip). (2) ICE is a passive security measure. An attacker interrupting the main power supply or any other source of power, cannot break state-continuity. (3) Benchmarks show that ICE already enables state-continuous updates almost 5x faster than writing to TPM NVRAM. With dedicated hardware, performance can be increased 2 orders of magnitude. We present a machine-checked proof of ICE’s security guarantees and evaluate a prototype implementation on commodity hardware. ICE: A Passive, High-Speed, State-Continuity Scheme (Extended Version) Raoul Strackx iMinds-Distrinet, KU Leuven Celestijnenlaan 200A 3001 Heverlee Bart Jacobs iMinds-Distrinet, KU Leuven Celestijnenlaan 200A 3001 Heverlee [email protected] Frank Piessens iMinds-Distrinet, KU Leuven Celestijnenlaan 200A 3001 Heverlee
منابع مشابه
ICE: A Passive, High-Speed, State-Continuity Scheme (Extended Version)
The amount of trust that can be placed in commodity computing platforms is limited by the likelihood of vulnerabilities in their huge software stacks. Protected-module architectures, such as Intel SGX, provide an interesting alternative by isolating the execution of software modules. To minimize the amount of code that provides support for the protected-module architecture, persistent storage o...
متن کاملHigh speed Radix-4 Booth scheme in CNTFET technology for high performance parallel multipliers
A novel and robust scheme for radix-4 Booth scheme implemented in Carbon Nanotube Field-Effect Transistor (CNTFET) technology has been presented in this paper. The main advantage of the proposed scheme is its improved speed performance compared with previous designs. With the help of modifications applied to the encoder section using Pass Transistor Logic (PTL), the corresponding capacitances o...
متن کاملShallow shelf approximation as a ‘‘sliding law’’ in a thermomechanically coupled ice sheet model
[1] The shallow shelf approximation, a balance of membrane stresses for ice flow, is an effective ‘‘sliding law’’ for ice sheet modeling. Our use of it as a sliding law becomes a standard model for ice stream flow when the sliding velocity is large (100 m a 1 and faster). Following Schoof (2006a), we describe the basal resistance as plastic till for which the yield stress is given by a Mohr-Cou...
متن کاملThe Development of a Passive False Twister Mechanism in Handling Low Strength Cotton Slivers on High Draft Spinning Machine
A passive false twist unit (spiral) has been developed to assist with the handling lowstrength slivers on a high speed-spinning machine with a high-speed feed. In the first trial, a falsetwist simulator device was constructed to determine whether the passive false twist unit can be usedon high speed feeding with different can distance from the feeding device. In the second trial, theeffects of ...
متن کاملSnow and ice products from Suomi NPP VIIRS
[1] The Visible Infrared Imager Radiometer Suite (VIIRS) instrument was launched in October 2011 on the satellite now known as the Suomi National Polar-orbiting Partnership. VIIRS was designed to improve upon the capabilities of the operational Advanced Very High Resolution Radiometer and provide observation continuity with NASA’s Earth Observing System’s Moderate Resolution Imaging Spectroradi...
متن کامل