Policy-Based Implicit Attestation for Microkernel-Based Virtualized Systems

被引:0
|
作者
Wagner, Steffen [1 ]
Eckert, Claudia [2 ]
机构
[1] Fraunhofer Inst AISEC, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
来源
关键词
Remote attestation; Trusted platform module; Policy; Data integrity; Microkernel;
D O I
10.1007/978-3-319-45871-7_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an attestation mechanism that enables a remote verifier to implicitly evaluate the trustworthiness of the prover's system through policies. Those policies are verified and enforced by a TPM 2.0, when the attestor interacts with a virtualized hardware component of the prover's system. For instance, when the verifier reads a virtualized sensor device and requests integrity-protected sensor data, such as the average temperature, a heartbeat value, or an anomaly detection score, the prover's TPM, which acts as a trust anchor, checks and enforces the policies specified by the verifier. The prover, in turn, is also able to define policies, which can limit access to certain hardware components and are also enforced by the TPM. As a result, both parties have to cooperate for a successful attestation, which implicitly creates verifiable proof of the prover's trustworthiness using mainly symmetric instead of expensive asymmetric cryptographic operations like digital signatures.
引用
收藏
页码:305 / 322
页数:18
相关论文
共 50 条
  • [1] Dependability of COTS microkernel-based systems
    Arlat, J
    Fabre, JC
    Rodríguez, M
    Salles, F
    IEEE TRANSACTIONS ON COMPUTERS, 2002, 51 (02) : 138 - 163
  • [2] Secure APIs for Applications in Microkernel-based Systems
    Hamad, Mohammad
    Prevelakis, Vassilis
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 553 - 558
  • [3] The B-method for the construction of microkernel-based systems
    Hoffmann, Sarah
    Haugou, Germain
    Gabriele, Sophie
    Burdy, Lilian
    B 2007: Formal Specification and Development in B, Proceedings, 2007, 4355 : 257 - 259
  • [4] CAmkES: A component model for secure microkernel-based embedded systems
    Kuz, Ihor
    Liu, Yan
    Gorton, Ian
    Heiser, Gernot
    JOURNAL OF SYSTEMS AND SOFTWARE, 2007, 80 (05) : 687 - 699
  • [5] CHORUS SPREADS MICROKERNEL-BASED UNIX
    WILLIAMS, T
    COMPUTER DESIGN, 1992, 31 (12): : 10 - 10
  • [6] Building dependable COTS microkernel-based systems using MAFALDA
    Fabre, JC
    Rodríguez, M
    Arlat, J
    Salles, F
    Sizun, JM
    2000 PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2000, : 85 - 92
  • [7] Policy-Based Management for Federation of Virtualized Infrastructures
    Kryftis, Yiannos
    Grammatikou, Maria
    Kalogeras, Dimitris
    Maglaris, Vasilis
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2017, 25 (02) : 229 - 252
  • [8] Policy-Based Management for Federation of Virtualized Infrastructures
    Yiannos Kryftis
    Maria Grammatikou
    Dimitris Kalogeras
    Vasilis Maglaris
    Journal of Network and Systems Management, 2017, 25 : 229 - 252
  • [9] Microkernel-based OSs satisfy multiple CAR requirements
    Computer Technology Review, 1995, 15 (07):
  • [10] Enabling Hardware Performance Counters for Microkernel-Based Virtualization on Embedded Systems
    Mathew, Deepa
    Jose, Bijoy Antony
    Mathew, Jimson
    Patra, Priyadarsan
    IEEE ACCESS, 2020, 8 : 110550 - 110564