arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Linux磁盘加密与自加密驱动器——关于Opal2驱动器安全性的案例研究

Linux disk encryption and self-encrypting drives -- A case study on Opal2 drives security

Milan Brož, Tamara Čierniková, Ondřej Kozina, Vladimír Sedláček

arXiv 2607.11563首次发表:更新:

AI 中文总结

研究Opal2驱动器在Linux环境中的安全性,采用黑盒方法在多供应商测试平台开展案例研究,识别固件安全问题并告知供应商,推动Linux磁盘加密工具改进,还发布开源测试场景工具集。

AI 中文摘要

Opal2自加密驱动器提供基于硬件的磁盘加密,可作为基于软件解决方案的额外保护层或替代品。本文对Opal2驱动器在实际Linux环境中的集成及Opal2固件安全性进行案例研究。通过黑盒方法在38个来自不同供应商的商用现货Opal2驱动器测试平台上开展研究。识别出若干固件安全问题与不兼容性并告知供应商,研究结果推动了所有主流Linux发行版中磁盘加密工具的改进。为便于公众独立评估,将Opal2驱动器测试场景作为开源工具集发布。

英文摘要

Opal2 self-encrypting drives provide hardware-based disk encryption serving as an additional layer of protection, or a replacement, for software-based solutions. This paper presents a case study of real-world Linux integration of Opal2 drives and the security of Opal2 firmware. The study was conducted on a testbed of 38 commercial off-the-shelf Opal2 drives from various vendors using a black-box approach. We identified several firmware security issues and incompatibilities, which we responsibly disclosed to respective vendors. Our findings led to improvements in Linux disk encryption tools used across all major Linux distributions. To enable independent evaluation for the public, we release our test scenarios for Opal2 drives as an open-source toolset.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑