Scalable architectural support for trusted software

High Performance Computer Architecture(2010)

引用 248|浏览378
暂无评分
摘要
We present Bastion, a new hardware-software architecture for protecting security-critical software modules in an untrusted software stack. Our architecture is composed of enhanced microprocessor hardware and enhanced hypervisor software. Each trusted software module is provided with a secure, fine-grained memory compartment and its own secure persistent storage area. Bastion is the first architecture to provide direct hardware protection of the hypervisor from both software and physical attacks, before employing the hypervisor to provide the same protection to security-critical OS and application modules. Our implementation demonstrates the feasibility of bypassing an untrusted commodity OS to provide application security and shows better security with higher performance when compared to the Trusted Platform Module (TPM), the current industry state-of-the-art security chip. We provide a proof-of-concept implementation on the OpenSPARC platform.
更多
查看译文
关键词
microprocessor chips,safety-critical software,secure storage,software architecture,Bastion,OpenSPARC platform,enhanced hypervisor software,enhanced microprocessor hardware,fine grained memory compartment,hardware-software architecture,scalable architectural support,secure persistent storage,security critical software modules,trusted software
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要