arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.11466cs.CR

Prezta:使用SNARKs实现可证明的零信任授权远程执行

Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKs

Zhongjing Wei, Osaid Muhammad Ameer, Nikita Borisov, Yupeng Zhang

首次发表
浏览论文内容

中文总结 AI 辅助

针对运营技术系统安全挑战,提出Prezta架构,通过在客户端zkVM内评估策略消除应用网关。用RISC Zero zkVM实现原型,采取编译策略等措施减轻证明开销,减少证明者时间,编译器实现部分XACML 3.0套件,验证快速,适用于边缘设备。

中文摘要 AI 辅助

现代化控制关键基础设施的运营技术系统的安全性是一项紧迫挑战。由于边缘设备能力有限,现代化依赖与身份管理系统接口并执行访问策略的应用网关。这些网关虽能执行复杂授权决策并支持零信任架构,但带来部署和管理负担。我们提出Prezta架构,通过在客户端运行的零知识虚拟机(zkVM)内评估策略来消除这些网关。zkVM生成简洁授权证明供边缘设备高效验证,扩展零信任安全范围到边缘。为证明可行性,我们用支持XACML 3.0策略和JWT身份声明的RISC Zero zkVM实现原型。通过编译策略到Rust代码和预编译正则表达式减轻zkVM证明开销,结合优化签名验证和JWT解析,减少证明者时间超一个数量级。我们的编译器正确实现83%的XACML 3.0一致性套件,桌面端证明生成耗时数十秒,验证仅需数十毫秒,适用于资源受限的边缘设备。

英文摘要

Modernizing the security of operational technology systems that control critical infrastructure has become a pressing challenge. Because edge devices have limited capabilities, modernization has relied on application gateways that interface with identity management systems and enforce access policies. These gateways are powerful enough to perform complex authorization decisions and support zero-trust architectures, but they create major deployment and management burdens: they must be collocated with remote, distributed edge devices, kept up to date with security patches, and managed with minimal downtime. We propose Provable Remote Execution of Zero-Trust Authorization (Prezta), an architecture that eliminates these gateways by evaluating policies within a zero-knowledge virtual machine (zkVM) running on the client. The zkVM produces a succinct proof of authorization that edge devices can verify efficiently, extending the zero-trust security envelope to the edge. Policies and identity management schemes can evolve without updating edge devices. To demonstrate the feasibility of Prezta, we implement a prototype built using the RISC Zero zkVM that supports XACML 3.0 policies and JWT identity claims. While zkVMs introduce substantial proof overhead, we mitigate this overhead by compiling policies to Rust code and precompiling regular expressions. Combined with optimized signature verification and JWT parsing, these measures reduce prover time by more than an order of magnitude. Our compiler correctly implements 83\% of the XACML 3.0 conformance suite, with proof generation completing in tens of seconds on a desktop. Verification, by contrast, takes only tens of milliseconds, which is fast enough for resource-constrained edge devices.

↑