论文标题

关于远程证明中的toctou问题

On the TOCTOU Problem in Remote Attestation

论文作者

Nunes, Ivan De Oliveira, Jakkamsetti, Sashidhar, Rattanavipanon, Norrathep, Tsudik, Gene

论文摘要

我们提出远程证明(toctou Revedeence(Rata)):一种可靠的安全方法来解决RA Toctou问题。借助拉塔(Rata),即使是在执行下一个RA之前就会擦除自身的恶意软件,也无法隐藏其短暂的存在。 Rata针对混合RA体系结构(以硬件/软件共同设计实现),该架构针对低端嵌入式设备。我们提出了两种替代技术 - rataa和ratab-分别适用于具有和不实时时钟的设备。每个人都证明是安全的,并伴随着公开可用和正式验证的实现。我们的评估表明,这两种技术的硬件开销低。与当前的RA体系结构(不提供TOCTOU保护)相比,Rata不会造成额外的运行时间开销。实际上,Rata大大降低了RA执行的计算成本。

We propose Remote Attestation with TOCTOU Avoidance (RATA): a provably secure approach to address the RA TOCTOU problem. With RATA, even malware that erases itself before execution of the next RA, can not hide its ephemeral presence. RATA targets hybrid RA architectures (implemented as Hardware/Software co-designs), which are aimed at low-end embedded devices. We present two alternative techniques - RATAa and RATAb - suitable for devices with and without real-time clocks, respectively. Each is shown to be secure and accompanied by a publicly available and formally verified implementation. Our evaluation demonstrates low hardware overhead of both techniques. Compared with current RA architectures - that offer no TOCTOU protection - RATA incurs no extra runtime overhead. In fact, RATA substantially reduces computational costs of RA execution.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源