Establishing Software Root of Trust Unconditionally

被引:1
|
作者
Gligor, Virgil D. [1 ]
Woo, Maverick S. L. [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
关键词
TIME;
D O I
10.14722/ndss.2019.23170
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Root-of-Trust (RoT) establishment ensures either that the state of an untrusted system contains all and only content chosen by a trusted local verifier and the system code begins execution in that state, or that the verifier discovers the existence of unaccounted for content. This ensures program booting into system states that are free of persistent malware. An adversary can no longer retain undetected control of one's local system. We establish RoT unconditionally; i.e., without secrets, trusted hardware modules and instructions, or bounds on the adversary's computational power. The specification of a system's chipset and device controllers, and an external source of true random numbers, such as a commercially available quantum RNG, is all that is needed. Our system specifications are those of a concrete Word Random Access Machine (cWRAM) model - the closest computation model to a real system with a large instruction set. We define the requirements for RoT establishment and explain their differences from past attestation protocols. Then we introduce a RoT establishment protocol based on a new computation primitive with concrete (non-asymptotic) optimal space-time bounds in adversarial evaluation on the cWRAM. The new primitive is a randomized polynomial, which has kindependent uniform coefficients in a prime order field. Its collision properties are stronger than those of a k-independent (almost) universal hash function in cWRAM evaluations, and are sufficient to prove existence of malware-free states before RoT is established. Preliminary measurements show that randomizedpolynomial performance is practical on commodity hardware even for very large k. To prove the concrete optimality of randomized polynomials, we present a result of independent complexity interest: a Hornerrule program is uniquely optimal whenever the cWRAM execution space and time are simultaneously minimized.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] Defining, Establishing and Measuring Digital Trust
    Kelley, K. Brian
    ISACA Journal, 2023, 1 : 13 - 15
  • [32] Establishing and maintaining trust in online systems
    McInerney, C
    NATIONAL ONLINE MEETING, PROCEEDINGS 2000, 2000, : 257 - 269
  • [33] Establishing trust in emergency telehealth consultations
    Hutton, Jennie
    Michael, Veal
    Miller, Suzanne M.
    Baines, Belinda
    Kirjanenko, Marija
    Sher, Loren
    Lawrence, Joanna
    Boyd, James
    Semciw, Adam
    Jessup, Rebecca
    Talevski, Jason
    EMERGENCY MEDICINE AUSTRALASIA, 2025, 37 (01)
  • [34] Ritual: The Root of Trust
    Warren G. Frisina
    Dao, 2021, 20 : 667 - 673
  • [35] The aortic root: establishing the norm
    Pather, N
    Ramsey, S
    FASEB JOURNAL, 2005, 19 (04): : A246 - A247
  • [36] Establishing chain of trust in reconfigurable hardware
    Eisenbarth, Thomas
    Gueneysu, Tim
    Paar, Christof
    Sadeghi, Ahmad-Reza
    Wolf, Marko
    Tessier, Russell
    FCCM 2007: 15TH ANNUAL IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, PROCEEDINGS, 2007, : 289 - +
  • [37] Establishing trust in distributed storage providers
    Caronni, G
    Waldvogel, M
    THIRD INTERNATIONAL CONFERENCE ON PEER-TO-PEER COMPUTING (P2P2003), PROCEEDINGS, 2003, : 128 - 133
  • [38] In software we trust
    Mecham, Michael
    Aviation Week and Space Technology (New York), 2007, 166 (01): : 54 - 55
  • [39] TRUST in software engineering
    Brandl, Dennis
    CONTROL ENGINEERING, 2009, 56 (06) : 14 - 14
  • [40] Establishing a software architecting environment
    Riva, C
    Selonen, P
    Systä, T
    Tuovinen, AP
    Xu, JL
    Yang, YJ
    FOURTH WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE (WICSA 2004), PROCEEDINGS, 2004, : 188 - 197