题名 | SHELTER: Extending Arm CCA with Isolation in User Space |
作者 | |
通讯作者 | Zhang, Fengwei |
发表日期 | 2023
|
会议名称 | 32nd USENIX Security Symposium
|
会议录名称 | |
会议日期 | AUG 09-11, 2023
|
会议地点 | null,Anaheim,CA
|
出版地 | SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA
|
出版者 | |
摘要 | ["The increasing adoption of confidential computing is providing individual users with a more seamless interaction with numerous mobile and server devices. TrustZone is a promising security technology for the use of partitioning sensitive private data into a trusted execution environment (TEE). Unfortunately, third-party developers have limited accessibility to TrustZone. This is because TEE vendors need to validate such security applications to preserve their security rigorously. Moreover, TrustZone-based systems suffer from vulnerabilities affecting Trusted App and trusted OS, possibly causing the entire system to be compromised.","Advanced virtualization-based TEE introduced in the recently new concept of Confidential Compute Architecture (CCA) creates a new physical address space called Realm world for confidential computing to protect the data confidentiality and integrity. The current version of CCA primarily targets the VM level in the Realm world and does not provide user-level isolated environments. To fill up this gap, we present SHELTER, which is a complement to CCA's primary Realm VM-style architecture. SHELTER allows thirdparty developers to deploy their applications with isolation in userspace. SHELTER is designed by cooperating with Arm CCA hardware primitive available in Armv9.2 to provide hardware-based isolation while removing the need for software workloads to trust their data to a Host OS, hypervisor, or privileged software (e.g., trusted OS, Secure/Realm hypervisor). We have implemented and evaluated SHELTER, and the results demonstrated that SHELTER guarantees the security of applications with a modest performance overhead (<15%) on real-world workloads."] |
学校署名 | 第一
; 通讯
|
语种 | 英语
|
相关链接 | [来源记录] |
收录类别 | |
资助项目 | National Natural Science Foundation of China["62002151","62102175"]
; Shenzhen Science and Technology Program["SGDX20201103095408029","ZDSYS20210623092007023"]
; PolyU Grant[ZVG0]
; Hong Kong RGC Project[PolyU15222320]
|
WOS研究方向 | Computer Science
|
WOS类目 | Computer Science, Information Systems
; Computer Science, Interdisciplinary Applications
; Computer Science, Theory & Methods
|
WOS记录号 | WOS:001066451506026
|
来源库 | Web of Science
|
引用统计 |
被引频次[WOS]:3
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/673966 |
专题 | 工学院_斯发基斯可信自主研究院 工学院_计算机科学与工程系 |
作者单位 | 1.Research Institute of Trustworthy Autonomous Systems, Southern University of Science and Technology, China 2.Department of Computer Science and Engineering, Southern University of Science and Technology, China 3.Department of Computing, The Hong Kong Polytechnic University, Hong Kong 4.College of Computer Science and Electronic Engineering, Hunan University, China 5.Ant Group |
第一作者单位 | 斯发基斯可信自主系统研究院; 计算机科学与工程系 |
通讯作者单位 | 斯发基斯可信自主系统研究院; 计算机科学与工程系 |
第一作者的第一单位 | 斯发基斯可信自主系统研究院 |
推荐引用方式 GB/T 7714 |
Zhang, Yiming,Hu, Yuxin,Ning, Zhenyu,et al. SHELTER: Extending Arm CCA with Isolation in User Space[C]. SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA:USENIX ASSOC,2023.
|
条目包含的文件 | ||||||
文件名称/大小 | 文献类型 | 版本类型 | 开放类型 | 使用许可 | 操作 | |
usenixsecurity23-zha(807KB) | -- | -- | 开放获取 | -- | 浏览 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论