arrow
返回

TEEnder: SGX enclave migration using HSMs

delete2020-09-01
delete5
PRE
AI
J
João Guerreiro
R
Rui Moura
J
João Nuno Silva *
DOI:10.1016/j.cose.2020.101874delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Intel Software Guard Extensions (SGX) is a new method of enhancing application security by creating safe areas of memory (enclaves) where data and code are protected from inspection and tampering. This technology is being applied to cloud computing as well, however, software deployed with SGX enclaves is complex to migrate between machines using traditional methods as SGX uses unique hardware keys for data sealing. This paper proposes a novel method of migrating SGX enclaves between different machines using Hardware Security Modules (HSMs) to encrypt and decrypt data using HSM generated keys. The use of HSMs achieves faster migration for large enclaves or during multiple concurrent migrations. Since the this solution does not depend on the security of remote attestation, and uses the keys stored in the HSM it provides a higher degree of security than current enclave migration solutions. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Trusted execution environment
Intel SGX
Hardware security module
Enclave migration
Cloud computing
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
universidade de lisboa
学者数:
3.4W
论文数: 3.1W
被引数: 29
引用论文

引用论文

eMotion: An SGX extension for migrating enclaves
err2019-01-01
err10
PREAI
errPark, Jaemin; Park, Sungjin; Kang, Brent Byunghoon; Kim, Kwangjo
err分享
err收藏
A survey on virtual machine migration and server consolidation frameworks for cloud data centers
err2015-06-01
err266
PREAI
errAhmad, Raja Wasim; Gani, Abdullah; Ab Hamid, Siti Hafizah; Shiraz, Muhammad; Yousafzai, Abdullah; Xia, Feng
err分享
err收藏