中文版 | English
题名

SHELTER: Extending Arm CCA with Isolation in User Space

作者
通讯作者Zhang, Fengwei
发表日期
2023
会议名称
32nd USENIX Security Symposium
会议录名称
会议日期
AUG 09-11, 2023
会议地点
null,Anaheim,CA
出版地
SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA
出版者
摘要
["The increasing adoption of confidential computing is providing individual users with a more seamless interaction with numerous mobile and server devices. TrustZone is a promising security technology for the use of partitioning sensitive private data into a trusted execution environment (TEE). Unfortunately, third-party developers have limited accessibility to TrustZone. This is because TEE vendors need to validate such security applications to preserve their security rigorously. Moreover, TrustZone-based systems suffer from vulnerabilities affecting Trusted App and trusted OS, possibly causing the entire system to be compromised.","Advanced virtualization-based TEE introduced in the recently new concept of Confidential Compute Architecture (CCA) creates a new physical address space called Realm world for confidential computing to protect the data confidentiality and integrity. The current version of CCA primarily targets the VM level in the Realm world and does not provide user-level isolated environments. To fill up this gap, we present SHELTER, which is a complement to CCA's primary Realm VM-style architecture. SHELTER allows thirdparty developers to deploy their applications with isolation in userspace. SHELTER is designed by cooperating with Arm CCA hardware primitive available in Armv9.2 to provide hardware-based isolation while removing the need for software workloads to trust their data to a Host OS, hypervisor, or privileged software (e.g., trusted OS, Secure/Realm hypervisor). We have implemented and evaluated SHELTER, and the results demonstrated that SHELTER guarantees the security of applications with a modest performance overhead (<15%) on real-world workloads."]
学校署名
第一 ; 通讯
语种
英语
相关链接[来源记录]
收录类别
资助项目
National Natural Science Foundation of China["62002151","62102175"] ; Shenzhen Science and Technology Program["SGDX20201103095408029","ZDSYS20210623092007023"] ; PolyU Grant[ZVG0] ; Hong Kong RGC Project[PolyU15222320]
WOS研究方向
Computer Science
WOS类目
Computer Science, Information Systems ; Computer Science, Interdisciplinary Applications ; Computer Science, Theory & Methods
WOS记录号
WOS:001066451506026
来源库
Web of Science
引用统计
被引频次[WOS]:3
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/673966
专题工学院_斯发基斯可信自主研究院
工学院_计算机科学与工程系
作者单位
1.Research Institute of Trustworthy Autonomous Systems, Southern University of Science and Technology, China
2.Department of Computer Science and Engineering, Southern University of Science and Technology, China
3.Department of Computing, The Hong Kong Polytechnic University, Hong Kong
4.College of Computer Science and Electronic Engineering, Hunan University, China
5.Ant Group
第一作者单位斯发基斯可信自主系统研究院;  计算机科学与工程系
通讯作者单位斯发基斯可信自主系统研究院;  计算机科学与工程系
第一作者的第一单位斯发基斯可信自主系统研究院
推荐引用方式
GB/T 7714
Zhang, Yiming,Hu, Yuxin,Ning, Zhenyu,et al. SHELTER: Extending Arm CCA with Isolation in User Space[C]. SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA:USENIX ASSOC,2023.
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
usenixsecurity23-zha(807KB)----开放获取--浏览
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Zhang, Yiming]的文章
[Hu, Yuxin]的文章
[Ning, Zhenyu]的文章
百度学术
百度学术中相似的文章
[Zhang, Yiming]的文章
[Hu, Yuxin]的文章
[Ning, Zhenyu]的文章
必应学术
必应学术中相似的文章
[Zhang, Yiming]的文章
[Hu, Yuxin]的文章
[Ning, Zhenyu]的文章
相关权益政策
暂无数据
收藏/分享
文件名: usenixsecurity23-zhang-yiming.pdf
格式: Adobe PDF
文件名: usenixsecurity23-zhang-yiming.pdf
格式: Adobe PDF
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。