首页> 外文会议>European Dependable Computing Conference >Exploiting New CPU Extensions for Secure Exchange of eHealth Data at the EU Level
【24h】

Exploiting New CPU Extensions for Secure Exchange of eHealth Data at the EU Level

机译:开发新的CPU扩展以在欧盟级别安全交换eHealth数据

获取原文

摘要

Cross-border healthcare requires that secure mechanisms for patient data exchange among distinct eHealth infrastructures be implemented. OpenNCP is a major initiative for achieving interoperability of eHealth data among European Member States. It is an Open Source implementation of a broker-based solution that enables the exchange of clinical data among countries having different languages and regulations. It provides some level of protection - using common security technologies (e.g., TLS) - but it has not been designed with the specific goal of achieving high levels of security, and therefore it is vulnerable to more subtle attacks, such as those by privileged users and/or software. In this paper we discuss how the new extension of COTS processors - namely Software Guard eXtension (SGX) - can be exploited to implement effective mechanisms against this specific category of attacks, which is particularly challenging. We present a general approach to harden systems, and discuss in detail how we implemented it in the context of OpenNCP. Also importantly, we evaluate the performance degradation induced by SGX.
机译:跨境医疗保健要求在不同的eHealth基础设施之间实施用于患者数据交换的安全机制。 OpenNCP是一项重要计划,旨在实现欧洲成员国之间电子卫生保健数据的互操作性。它是基于代理的解决方案的开源实现,可在具有不同语言和法规的国家之间交换临床数据。它使用常见的安全技术(例如TLS)来提供某种程度的保护,但其设计目标并不是要实现高级别的安全性,因此它容易受到更细微的攻击,例如特权用户的攻击和/或软件。在本文中,我们讨论了如何利用COTS处理器的新扩展,即Software Guard eXtension(SGX),来实施针对这种特定攻击类别的有效机制,这尤其具有挑战性。我们提出了一种强化系统的通用方法,并详细讨论了我们如何在OpenNCP上下文中实现它。同样重要的是,我们评估了SGX导致的性能下降。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号