arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.06061cs.CRcs.OS

PRA-TLS:面向TEE的客户端应用认证

PRA-TLS: Attestation of a Client Application for TEE

Reina Sasaki, Yutaka Ishikawa, Atsuko Takefusa, Masato Oguchi

首次发表
浏览论文内容

中文总结 AI 辅助

针对TEE中enclave与不可信应用间边界的安全风险,提出PRA-TLS协议,通过可信守护进程测量主机与应用状态,实现客户端应用认证,并形式化验证及原型实现。

中文摘要 AI 辅助

可信执行环境(TEE)是保护敏感信息和对机密数据执行计算的安全基础。在隔离执行环境(enclave)中的处理由富执行环境(REE)中的不可信应用调用,随后enclave将执行结果返回给该不可信应用。即使enclave已通过认证,enclave与不可信应用之间的边界仍会带来风险,例如篡改输入参数或返回值,以及操纵应用调用函数的顺序。因此,不仅需要建立enclave本身的真实性和完整性,还需要建立应用及其执行环境的真实性和完整性。在本研究中,我们提出了一种认证协议——可移植远程认证TLS(PRA-TLS),用于调用enclave的客户端应用。我们引入了一个充当认证者的守护进程。PRA-TLS使用可信的认证者守护进程在运行时测量主机环境和应用代码的状态,并将这些测量结果作为认证证据提供给远程验证者进行验证。该机制使得仅当软件环境处于预期状态且应用代码被验证为合法时,enclave才能继续执行。我们为所提出的协议定义了攻击模型和安全要求,并使用Tamarin Prover对其安全性进行了正式评估。此外,我们使用Intel SGX实现了PRA-TLS的原型,并评估了其性能。

英文摘要

Trusted Execution Environments (TEEs) are secure foundations for protecting sensitive information and executing computations over confidential data. Processing in an isolated execution environment (enclave) is invoked by an untrusted application in the Rich Execution Environment (REE). Then the enclave returns the execution results to the untrusted application. Even if the enclave has been attested, the boundary between the enclave and the untrusted application poses risks, such as tampering with input arguments or return values and manipulating the order in which the application invokes functions. Therefore, it is necessary to establish the authenticity and integrity of not only the enclave itself but also the application and its execution environment. In this study, we propose an attestation protocol, Portable Remote Attestation TLS (PRA-TLS), for a client application that invokes an enclave. We introduce a daemon that acts as an attester. PRA-TLS uses a trusted Attester Daemon to measure the state of the host environment and application code at runtime, providing these measurements as attestation evidence for verification by a remote Verifier. This mechanism allows the enclave to proceed only when the software environment is in the expected state and the application code is verified as legitimate. We define attack models and security requirements for the proposed protocol and formally evaluate its security using the Tamarin Prover. Furthermore, we implement a prototype of PRA-TLS using Intel SGX and evaluate its performance.

发表机构

  • Ochanomizu University(御茶水女子大学)
  • Otsuma Women’s University(大妻女子大学)
  • National Institute of Informatics(国立情报学研究所)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑