arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.20909cs.CR

TPM-Attest:基于硬件根信任的完整性证明,作为Linux内核级反作弊的替代方案

TPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux

Anudeep Gedela, A. Yaswanth

首次发表
浏览论文内容

中文总结 AI 辅助

TPM-Attest利用TPM 2.0和IMA实现硬件根信任的远程证明,无需内核驱动即可检测篡改,500次测试中实现100%检测率,并开源发布。

中文摘要 AI 辅助

Linux上的多人PC游戏面临一个结构性问题:发行商要求的反作弊系统以专有的Ring 0内核模块形式运行,这些模块在架构上与Linux的安全模型、GPL许可和稳定ABI保证不兼容。我们认为正确的回应不是将这些侵入性模块移植到Linux,而是完全替换它们。本文提出TPM-Attest,一个基于硬件根信任的远程证明框架,利用可信平台模块(TPM)2.0和Linux完整性度量架构(IMA)来以密码学方式证明客户端干净启动且仅运行了授权软件——无需任何内核驱动程序,无需专有代码,也无需扫描玩家内存。该系统通过用户空间的LD_PRELOAD钩子拦截Epic在线服务(EOS)SDK调用,将会话访问门控于绑定服务器颁发的nonce的实时TPM引用,并在IMA日志上构建索引前缀的Merkle树,该树对重复叶碰撞攻击免疫。在500个构造的篡改会话中,我们实现了100%的检测率;增量叶缓存将真实TPM 2.0硬件上的重复证明延迟降至3秒以下。针对实时演示游戏的受控红队评估确认所有四个基于文件的攻击向量均被阻止,同时精确描述了两种已确认的绕过条件。完整实现已作为开源软件发布。

英文摘要

Multiplayer PC gaming on Linux faces a structural problem: the anti-cheat systems that publishers require operate as proprietary Ring 0 kernel modules that are architecturally incompatible with Linux's security model, GPL licensing, and stable ABI guarantees. We argue the right response is not to port these invasive modules to Linux, but to replace them entirely. This paper presents TPM-Attest, a hardware-rooted remote attestation framework that uses the Trusted Platform Module (TPM) 2.0 and the Linux Integrity Measurement Architecture (IMA) to prove, cryptographically, that a client booted cleanly and ran only authorised software -- without any kernel driver, without proprietary code, and without scanning player memory. The system intercepts Epic Online Services (EOS) SDK calls via a userspace LD_PRELOAD hook, gates session access on a live TPM quote bound to a server-issued nonce, and constructs an index-prefixed Merkle tree over the IMA log that is immune to duplicate-leaf collision attacks. Across 500 constructed tamper sessions we achieve a 100% detection rate; incremental leaf caching reduces repeat-attestation latency to under 3 seconds on real TPM 2.0 hardware. A controlled red-team evaluation against a live demo game confirms all four file-backed attack vectors are blocked while precisely characterising the two confirmed bypass conditions. The full implementation is released as open-source software.

发表机构

  • GITAM School of Technology, GITAM (Deemed to be University)(GITAM科技学院,GITAM(视为大学))

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑