发表机构
Confidential Computing Lab, Acompany Co., Ltd.(Acompany有限公司机密计算实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
TEE Anchor通过基于X.509的组织证书绑定芯片ID,证明机器组织归属,以缓解物理访问攻击,轻量且跨TEE适用,操作耗时毫秒级。
AI 中文摘要
2025年,针对TEE的实际物理访问攻击(如this http URL和Battering RAM)被披露,对当前TEE构成严重威胁。目标机器受到越严格的守护,此类攻击就越难以实施。因此,处于可信管理之下已成为一项新的安全要求。然而,现有的证明无法证明机器的组织归属。这给攻击者留下了可乘之机,使其能够将受其控制的物理可访问机器冒充为在合法环境中运行的机器。我们提出了TEE Anchor,一种通过证明哪家组织管理机器来缓解物理攻击的机制。TEE Anchor是一种基于X.509的轻量级设计,无需(v)TPM等额外信任根。组织颁发覆盖芯片ID(每个CPU的唯一标识符)的证书,形成自己的PKI。然后,验证者通过将证明证据中的芯片ID与该证书进行匹配来证明归属。这在运营成本和可部署性方面优于基于(v)TPM的先前工作,适用于各大TEE且无供应商锁定,并允许任何组织独立于TEE供应商声明归属。我们实现了原型,并确认包括配置和验证在内的所有操作均在几毫秒内完成。
英文摘要
In 2025, practical physical-access attacks against TEEs, such as TEE.fail and Battering RAM, were disclosed, posing a serious threat to current TEEs. The more strictly the target machine is guarded, the harder such attacks are to mount. Residing under trusted management has therefore emerged as a new security requirement. Yet existing attestation cannot prove a machine's organizational affiliation. This leaves room for an attacker to pass off a physically accessible machine under their control as one operated in a legitimate environment. We propose TEE Anchor, a mechanism that mitigates physical attacks by proving which organization manages a machine. TEE Anchor is a lightweight, X.509-based design that needs no additional root of trust such as a (v)TPM. The organization issues a certificate over the Chip ID, a unique per-CPU identifier, forming its own PKI. A Verifier then proves affiliation by matching the Chip ID in the attestation evidence against that certificate. This outperforms (v)TPM-based prior work in operational cost and deployability, applies across major TEEs without vendor lock-in, and lets any organization assert affiliation independently of TEE vendors. We implemented a prototype and confirmed that all operations, including provisioning and verification, complete within a few milliseconds.