Secure Processors Part II - Victor Costan, Ilia Lebedev, Srinivas Devadas

Secure Processors Part II

Intel SGX Security Analysis and MIT Sanctum Architecture
Buch | Softcover
128 Seiten
2017
now publishers Inc (Verlag)
978-1-68083-302-7 (ISBN)
89,95 inkl. MwSt
Surveys the state of the art in secure processor systems, with a specific focus on remote software attestation and software isolation. This two part work advocates a principled, transparent approach to system design, and argues that practical guarantees of privacy and integrity for remote computation are achievable.
This monograph is the second of a two-part survey and analysis of the state of the art in secure processor systems, with a specific focus on remote software attestation and software isolation. The first part established the taxonomy and prerequisite concepts relevant to an examination of the state of the art in trusted remote computation: attested software isolation containers (enclaves). This second part extends Part I’s description of Intel’s Software Guard Extensions (SGX), an available and documented enclave-capable system, with a rigorous security analysis of SGX as a system for trusted remote computation. This part documents the authors’ concerns over the shortcomings of SGX as a secure system and introduces the MIT Sanctum processor developed by the authors: a system designed to offer stronger security guarantees, lend itself better to analysis and formal verification, and offer a more straightforward and complete threat model than the Intel system, all with an equivalent programming model. This two-part work advocates a principled, transparent, and well scrutinized approach to system design, and argues that practical guarantees of privacy and integrity for remote computation are achievable at a reasonable design cost and performance overhead. See also: Secure Processors Part I: Background, Taxonomy for Secure Enclaves and Intel SGX Architecture (ISBN 978-1-68083-300-3). Part I of this survey establishes the taxonomy and prerequisite concepts relevant to an examination of the state of the art in trusted remote computation: attested software isolation containers (enclaves).

1: Introduction; 2: An Analysis of Intel’s Software Guard Extensions (SGX) 3: The MIT Sanctum Processor; 4: Conclusion; 5: Acknowledgements; References.

Erscheinungsdatum
Reihe/Serie Foundations and Trends in Electronic Design Automation
Verlagsort Hanover
Sprache englisch
Themenwelt Informatik Theorie / Studium Kryptologie
Technik Maschinenbau
ISBN-10 1-68083-302-2 / 1680833022
ISBN-13 978-1-68083-302-7 / 9781680833027
Zustand Neuware
Haben Sie eine Frage zum Produkt?
Mehr entdecken
aus dem Bereich