Migrating SGX Enclaves with Persistent State

Fritz Alder, Arseny Kurnikov, Andrew Paverd, N. Asokan

Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference article in proceedingsScientificvertaisarvioitu

Abstrakti

Hardware-supported security mechanisms like Intel Software Guard Extensions (SGX) provide strong security guarantees, which are particularly relevant in cloud settings. However, their reliance on physical hardware conflicts with cloud practices, like migration of VMs between physical platforms. For instance, the SGX trusted execution environment (enclave) is bound to a single physical CPU. Although prior work has proposed an effective mechanism to migrate an enclave's data memory, it overlooks the migration of persistent state, including sealed data and monotonic counters; the former risks data loss whilst the latter undermines the SGX security guarantees. We show how this can be exploited to mount attacks, and then propose an improved enclave migration approach guaranteeing the consistency of persistent state. Our software-only approach enables migratable sealed data and monotonic counters, maintains all SGX security guarantees, minimizes developer effort, and incurs negligible performance overhead.
AlkuperäiskieliEnglanti
Otsikko48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
KustantajaIEEE
Sivut195-206
ISBN (elektroninen)978-1-5386-5595-5
DOI - pysyväislinkit
TilaJulkaistu - 23 heinäk. 2018
OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
TapahtumaANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS - Luxembourg, Luxemburg
Kesto: 25 kesäk. 201828 kesäk. 2018
Konferenssinumero: 48

Conference

ConferenceANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS
LyhennettäDSN
Maa/AlueLuxemburg
KaupunkiLuxembourg
Ajanjakso25/06/201828/06/2018

Sormenjälki

Sukella tutkimusaiheisiin 'Migrating SGX Enclaves with Persistent State'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.
  • CloSer: Cloud-assisted Security Services (CloSer)

    Asokan, N. (Vastuullinen tutkija)

    01/09/201631/08/2018

    Projekti: Business Finland: Other research funding

Siteeraa tätä