Policy-Based Implicit Attestation for Microkernel-Based Virtualized Systems

被引:0
|
作者
Wagner, Steffen [1 ]
Eckert, Claudia [2 ]
机构
[1] Fraunhofer Inst AISEC, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
来源
关键词
Remote attestation; Trusted platform module; Policy; Data integrity; Microkernel;
D O I
10.1007/978-3-319-45871-7_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an attestation mechanism that enables a remote verifier to implicitly evaluate the trustworthiness of the prover's system through policies. Those policies are verified and enforced by a TPM 2.0, when the attestor interacts with a virtualized hardware component of the prover's system. For instance, when the verifier reads a virtualized sensor device and requests integrity-protected sensor data, such as the average temperature, a heartbeat value, or an anomaly detection score, the prover's TPM, which acts as a trust anchor, checks and enforces the policies specified by the verifier. The prover, in turn, is also able to define policies, which can limit access to certain hardware components and are also enforced by the TPM. As a result, both parties have to cooperate for a successful attestation, which implicitly creates verifiable proof of the prover's trustworthiness using mainly symmetric instead of expensive asymmetric cryptographic operations like digital signatures.
引用
收藏
页码:305 / 322
页数:18
相关论文
共 50 条
  • [21] User-level real-time network system on microkernel-based operating systems
    Nakajima, T
    Tokuda, H
    REAL-TIME SYSTEMS, 1998, 14 (01) : 45 - 60
  • [22] User-level Real-Time Network System on Microkernel-based Operating Systems
    Tatsuo Nakajima
    Hideyuki Tokuda
    Real-Time Systems, 1998, 14 : 45 - 60
  • [23] Policy-Based Reserves for Power Systems
    Warrington, Joseph
    Goulart, Paul
    Mariethoz, Sebastien
    Morari, Manfred
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2013, 28 (04) : 4427 - 4437
  • [24] Engineering Policy-Based Ubiquitous Systems
    Sloman, Morris
    Lupu, Emil
    COMPUTER JOURNAL, 2010, 53 (07): : 1113 - 1127
  • [25] Incremental validation of policy-based systems
    Graham, A
    Radhakrishnan, T
    Grossner, C
    FIFTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2004, : 240 - 249
  • [26] A global synchronization solution for racing servers in the microkernel-based OS, MISIX
    Nam, JJ
    Kim, JM
    Kim, HJ
    INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, VOLS I-III, PROCEEDINGS, 1997, : 156 - 161
  • [27] Priority inversion handling in microkernel-based real-time Mike
    Shim, J
    Choi, K
    Jung, GY
    Park, S
    Shin, HS
    Kim, D
    THIRD INTERNATIONAL WORKSHOP ON REAL-TIME COMPUTING SYSTEMS AND APPLICATIONS, PROCEEDINGS, 1996, : 238 - 245
  • [28] A Microkernel-based Resource Loading Manager on Geographic Information Technology Platform
    Zhang, Fan
    Wu, Xincai
    Zhang, Fan
    Wu, Xincai
    2013 3RD INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, COMMUNICATIONS AND NETWORKS (CECNET), 2013, : 15 - 18
  • [29] The design and implementation of a microkernel-based parallel OS ''Cenju-3/DE''
    Takano, Y
    Howson, C
    Konishi, K
    Sugawara, T
    Araki, H
    Konagaya, A
    NEC RESEARCH & DEVELOPMENT, 1996, 37 (02): : 260 - 266
  • [30] Policy transformation techniques in policy-based systems management
    Beigi, MS
    Calo, S
    Verma, D
    FIFTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2004, : 13 - 22