Security model oriented attestation on dynamically reconfigurable component-based systems

被引:3
|
作者
Gu, Liang [1 ]
Bai, Guangdong [1 ]
Guo, Yao [1 ]
Chen, Xiangqun [1 ]
Mei, Hong [1 ]
机构
[1] Peking Univ, Sch Elect Engn & Comp Sci, Key Lab High Confidence Software Technol, Minist Educ, Beijing 100871, Peoples R China
关键词
Remote attestation; Component-based systems; Security model; Security policy; Dynamically reconfigurable CBS; TRUST-MANAGEMENT; REMOTE ATTESTATION; INTEGRITY; CHECKING; SOFTWARE; POLICIES; ACCESS;
D O I
10.1016/j.jnca.2011.03.014
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As more and more component-based systems (CBS) run in the open and dynamic Internet, it is very important to establish trust between clients and CBS in mutually distrusted domains. One of the key mechanisms to establish trust among different platforms in an open and dynamic environment is remote attestation, which allows a platform to vouch for its trust-related characteristics to a remote challenger. This paper proposes a novel attestation scheme for a dynamically reconfigurable CBS to reliably prove whether its execution satisfies the specified security model, by introducing a TPM-based attestation service to dynamically monitor the execution of the CBS. When only parts of the dynamic CBS are concerned, our scheme enables fine-grained attestation on the execution of an individual component or a sub-system in the dynamic CBS, such that it involves only minimal overhead for attesting the target parts of the CBS. With flexible attestation support, the proposed attestation service can attest a CBS at the granularity from an individual component to the whole CBS. As a case study, we have applied the proposed scheme on OSGi systems and implemented a prototype based on JVMTI for Felix. The evaluation results show that the proposed scheme is both effective and practical. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:974 / 981
页数:8
相关论文
共 50 条
  • [1] A dynamically reconfigurable component-based architecture
    Talevski, A
    Chang, E
    [J]. ENGINEERING INTELLIGENT SYSTEMS FOR ELECTRICAL ENGINEERING AND COMMUNICATIONS, 2002, 10 (01): : 27 - 36
  • [2] An Approach to Assure QoS for Dynamically Reconfigurable Component-Based Software Systems
    Reeta, R.
    Mariappan, A. K.
    [J]. 2014 INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND SIGNAL PROCESSING (ICCSP), 2014,
  • [3] Component-based reconfigurable systems
    Lowry, MR
    [J]. COMPUTER, 1998, 31 (04) : 44 - +
  • [4] An integrated security model for component-based systems
    Nissanke, Nimal
    [J]. ETFA 2007: 12TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOLS 1-3, 2007, : 638 - 645
  • [5] A model for developing component-based and aspect-oriented systems
    Pessemier, Nicolas
    Seinturier, Lionel
    Coupaye, Thierry
    Duchien, Laurence
    [J]. SOFTWARE COMPOSITION, 2006, 4089 : 259 - 274
  • [6] A security mechanism for component-based systems
    Grechanik, M
    Perry, DE
    Batory, D
    [J]. FIFTH INTERNATIONAL CONFERENCE ON COMMERCIAL-OFF-THE-SHELF (COTS) - BASED SOFTWARE SYSTEM, PROCEEDINGS, 2006, : 53 - +
  • [7] Architecting reconfigurable component-based operating systems
    Polakovic, Juraj
    Stefani, Jean-Bernard
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2008, 54 (06) : 562 - 575
  • [8] A framework for evolutionary, dynamically updatable, component-based systems
    Bialek, R
    Jul, E
    [J]. 24TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS, PROCEEDINGS, 2004, : 326 - 331
  • [9] Component-based protocol stack management for reconfigurable systems
    Chi, Cheng
    Feng, Zhiyong
    Xue, Yuan
    Cai, Huying
    Zhang, Ping
    [J]. 2008 IEEE 67TH VEHICULAR TECHNOLOGY CONFERENCE-SPRING, VOLS 1-7, 2008, : 2616 - 2620
  • [10] On Specifying Reconfigurable Component-Based Systems Using Strategies
    Djoudi, Brahim
    Bouanaka, Chafia
    Zeghib, Nadia
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2014, PT 1, 2014, 8579 : 656 - 670