发表机构
Confidential Computing Lab Acompany Co., Ltd.(Acompany公司保密计算实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对无中心可信方的双向远程证明参考值引导问题,将其转化为不动点方程,利用Kleene第二递归定理提出架构无关方案,开发PyReflect和NixReflect实现原型,无需TTP或外部参考值即可完成证明。
AI 中文摘要
在无中心可信操作方的节点间进行双向远程证明,要求每个节点持有其对等节点的参考值(预期代码度量)。将这些参考值相互嵌入节点代码的朴素方法会导致无限回归,我们将解决该无限回归的问题称为双向远程证明的参考值引导问题。现有解决方案通过依赖第三方可信方(TTP)、外部提供的参考值或特定架构的度量机制来避免这种回归。我们转而将引导问题表示为一组相互的不动点方程,并通过Kleene第二递归定理求解。该构造生成的节点相互引用对方的代码,仅从内置数据中重构每个对等节点的精确源代码。当对部署的源文件(如Python脚本)进行度量时,节点通过直接对重构后的源代码应用度量函数来获取对等节点的参考值;当对构建的镜像(如AWS Nitro Enclaves)进行度量时,节点则从重构后的源代码中可复现地构建对等节点的镜像,并推导其参考度量。对于第一种情况,我们开发了Python转译器PyReflect,并用其实现了TPM双向远程证明的原型验证(PoC);对于第二种情况,我们开发了Nix转译器NixReflect,并将其用于一个原型验证中,其中两个Nitro Enclaves仅从内置数据中复现彼此的参考PCR。我们的解决方案与架构无关,既不需要TTP也不需要外部提供的参考值,且可与现有远程证明栈兼容使用。
英文摘要
Remote attestation is a procedure by which a system (such as a Trusted Execution Environment) proves its own configuration to a remote peer. Here, the configuration includes the measurements (hash digests) of software components. When multiple nodes perform mutual attestation, each node must maintain the reference values for its peers' measurements. We refer to this as the reference-value bootstrapping problem for mutual attestation. In this paper, we formulate the problem as a fixed-point equation and solve it directly using Kleene's second recursion theorem. In our approach, nodes can reconstruct one another's source code, thereby allowing each node to derive the reference values at runtime. When a source code itself is deployed, as with a Python script, a node derives the peer's reference value directly from its reconstructed source. When a build artifact is deployed, as with AWS Nitro Enclaves, a node instead reproducibly builds the peer's artifact from its reconstructed source and derives the reference value from it. As a proof of concept, we develop transpilers in Python and Nix to generate mutually referencing programs. Using these transpilers, we demonstrate the mutual derivation of reference values for the two deployment models mentioned above. Our solution is architecture-independent, requires no trusted third party, and works with existing attestation stacks without modification.
CommentsRevised