arrow
Return

Securing TEEs With Verifiable Execution Contracts

delete2023-07-01
delete1
PRE
AI
G
Guoxing Chen
Y
Yinqian Zhang *
DOI:10.1109/TDSC.2022.3194871delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Recent works have demonstrated that trusted execution environments, such as Intel Software Guard Extensions, are vulnerable to various attacks from the privileged software, including side-channel attacks. Existing solutions, such as T-SGX, Deja Vu, Cloak and Varys, detect side-channel attacks at runtime. But they are limited by design, because false detection is unavoidable in these detection methods and therefore any security policy developed atop these mechanisms has to tolerate some malicious operations to achieve practical false positive detection rates. In this article, we propose the concept of verifiable execution contracts, which request the privileged software to provide a benign execution environment for enclaves within which launching attacks becomes very difficult, if not impossible. Since the privileged software is untrusted, we design methods for verifying that the execution contracts are observed. With the proposed verifiable execution contracts, we analyzed how existing attacks could be mitigated.
Keywords:
Trusted execution environments
Intel SGX
side channels

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

S
shanghai jiao tong university
Scholars:
15.5W
Papers: 11.6W
Citations: 159