Policy-Based Implicit Attestation for Microkernel-Based Virtualized Systems

被引:0
|
作者
Wagner, Steffen [1 ]
Eckert, Claudia [2 ]
机构
[1] Fraunhofer Inst AISEC, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
来源
关键词
Remote attestation; Trusted platform module; Policy; Data integrity; Microkernel;
D O I
10.1007/978-3-319-45871-7_19
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an attestation mechanism that enables a remote verifier to implicitly evaluate the trustworthiness of the prover's system through policies. Those policies are verified and enforced by a TPM 2.0, when the attestor interacts with a virtualized hardware component of the prover's system. For instance, when the verifier reads a virtualized sensor device and requests integrity-protected sensor data, such as the average temperature, a heartbeat value, or an anomaly detection score, the prover's TPM, which acts as a trust anchor, checks and enforces the policies specified by the verifier. The prover, in turn, is also able to define policies, which can limit access to certain hardware components and are also enforced by the TPM. As a result, both parties have to cooperate for a successful attestation, which implicitly creates verifiable proof of the prover's trustworthiness using mainly symmetric instead of expensive asymmetric cryptographic operations like digital signatures.
引用
收藏
页码:305 / 322
页数:18
相关论文
共 50 条
  • [41] Policy-based memoization for ILP-based concept discovery systems
    Alev Mutlu
    Pinar Karagoz
    Journal of Intelligent Information Systems, 2016, 46 : 99 - 120
  • [42] Policy-Based Profiles for Network Intrusion Response Systems
    Hughes, Kieran
    McLaughlin, Kieran
    Sezer, Sakir
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 279 - 286
  • [43] Dynamic conflict detection in policy-based management systems
    Dunlop, N
    Indulska, J
    Raymond, K
    SIXTH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2002, : 15 - 26
  • [44] An Architecture for a Cached Policy-based Decision Making Systems
    Pelc, Mariusz
    Stach, Tomasz
    Swierczynska, Dominika
    2016 21ST INTERNATIONAL CONFERENCE ON METHODS AND MODELS IN AUTOMATION AND ROBOTICS (MMAR), 2016, : 565 - 570
  • [45] Policy-based quality of service mapping in distributed systems
    Rudack, M
    Jobmann, K
    Pajares, A
    Esteve, M
    NOMS 2002: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM: MANAGEMENT SOLUTIONS FOR THE NEW COMMUNICATIONS WORLD, 2002, : 947 - 949
  • [46] Methods for conflict resolution in policy-based management systems
    Dunlop, N
    Indulska, J
    Raymond, K
    SEVENTH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2003, : 98 - 109
  • [47] A DSL Framework for Policy-based Security of Distributed Systems
    Hamdi, Hedi
    Mosbah, Mohamed
    2009 THIRD IEEE INTERNATIONAL CONFERENCE ON SECURE SOFTWARE INTEGRATION AND RELIABILITY IMPROVEMENT, PROCEEDINGS, 2009, : 150 - 158
  • [48] A Policy-based Accountability Tool for Grid Computing Systems
    Squicciarini, Anna Cinzia
    Lee, Wonjun
    Bertino, Elisa
    Song, Carol X.
    2008 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE, VOLS 1-3, PROCEEDINGS, 2008, : 95 - +
  • [49] Policy-based security for distributed manufacturing execution systems
    Morariu, Octavian
    Morariu, Cristina
    Borangiu, Theodor
    INTERNATIONAL JOURNAL OF COMPUTER INTEGRATED MANUFACTURING, 2018, 31 (03) : 306 - 317
  • [50] Integrated policy-based governance of virtual enterprises and systems
    Mitropoulos S.
    Douligeris C.
    International Journal of Applied Systemic Studies, 2010, 3 (03) : 326 - 342