首页> 外文会议>ACM/ESDA/IEEE Design Automation Conference >Invited: Reconciling Remote Attestation and Safety-Critical Operation on Simple IoT Devices
【24h】

Invited: Reconciling Remote Attestation and Safety-Critical Operation on Simple IoT Devices

机译:邀请:在简单的物联网设备上调协调制远程证明和安全关键操作

获取原文

摘要

Remote attestation (RA) is a means of malware detection, typically realized as an interaction between a trusted verifier and a potentially compromised remote device (prover). RA is especially relevant for low-end embedded devices that are incapable of protecting themselves against malware infection. Most current RA techniques require on-demand and uninterruptible (atomic) operation. The former fails to detect transient malware that enters and leaves between successive RA instances; the latter involves performing potentially time-consuming computation over prover's memory and/or storage, which can be harmful to the device's safety-critical functionality and general availability. However, relaxing either on-demand or atomic RA operation is tricky and prone to vulnerabilities. This paper identifies some issues that arise in reconciling requirements of safety-critical operation with those of secure remote attestation, including detection of transient and self-relocating malware. It also investigates mitigation techniques, including periodic self-measurements as well as interruptible attestation modality that involves shuffled memory traversals and various memory locking mechanisms.
机译:远程证明(RA)是恶意软件检测的手段,通常实现为可信验证者和潜在受损的远程设备(谚语)之间的交互。 RA特别适用于不能保护自己免受恶意软件感染的低端嵌入式设备。大多数电流RA技术都需要按需和不间断(原子)操作。前者未能检测进入和留在连续的RA实例之间的瞬态恶意软件;后者涉及通过谚语的存储器和/或存储来执行潜在的耗时的计算,这可能对设备的安全关键功能和一般可用性有害。然而,轻松按需或原子RA操作棘手且易于漏洞。本文确定了一些问题,即协调安全遥控操作的安全关键操作的要求,包括检测瞬态和自迁的恶意软件。它还研究了缓解技术,包括周期性的自我测量以及可中断的证明模态,其涉及洗机的内存遍历和各种存储器锁定机构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号