Agora: Trust Less and Open More in Verification for Confidential Computing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Hongbo, Zhou, Quan, Yang, Sen, Han, Xing, Zhang, Fan, Zhang, Danfeng, Wang, Xiaofeng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908588022169600
author Chen, Hongbo
Zhou, Quan
Yang, Sen
Han, Xing
Zhang, Fan
Zhang, Danfeng
Wang, Xiaofeng
author_facet Chen, Hongbo
Zhou, Quan
Yang, Sen
Han, Xing
Zhang, Fan
Zhang, Danfeng
Wang, Xiaofeng
contents Binary verification plays a pivotal role in software security, yet building a verification service that is both open and trustworthy poses a formidable challenge. In this paper, we introduce a novel binary verification service, AGORA, scrupulously designed to overcome the challenge. At the heart of this approach lies a strategic insight: certain tasks can be delegated to untrusted entities, while the corresponding validators are securely housed within the trusted computing base (TCB). AGORA can validate untrusted assertions generated for versatile policies. Through a novel blockchain-based bounty task manager, it also utilizes crowdsourcing to remove trust in theorem provers. These synergistic techniques successfully ameliorate the TCB size burden associated with two procedures: binary analysis and theorem proving. The design of AGORA allows untrusted parties to participate in these complex processes. Moreover, based on running the optimized TCB within trusted execution environments and recording the verification process on a blockchain, the public can audit the correctness of verification results. By implementing verification workflows for software-based fault isolation policy and side-channel mitigation, our evaluation demonstrates the efficacy of AGORA.
format Preprint
id arxiv_https___arxiv_org_abs_2407_15062
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Agora: Trust Less and Open More in Verification for Confidential Computing
Chen, Hongbo
Zhou, Quan
Yang, Sen
Han, Xing
Zhang, Fan
Zhang, Danfeng
Wang, Xiaofeng
Cryptography and Security
Binary verification plays a pivotal role in software security, yet building a verification service that is both open and trustworthy poses a formidable challenge. In this paper, we introduce a novel binary verification service, AGORA, scrupulously designed to overcome the challenge. At the heart of this approach lies a strategic insight: certain tasks can be delegated to untrusted entities, while the corresponding validators are securely housed within the trusted computing base (TCB). AGORA can validate untrusted assertions generated for versatile policies. Through a novel blockchain-based bounty task manager, it also utilizes crowdsourcing to remove trust in theorem provers. These synergistic techniques successfully ameliorate the TCB size burden associated with two procedures: binary analysis and theorem proving. The design of AGORA allows untrusted parties to participate in these complex processes. Moreover, based on running the optimized TCB within trusted execution environments and recording the verification process on a blockchain, the public can audit the correctness of verification results. By implementing verification workflows for software-based fault isolation policy and side-channel mitigation, our evaluation demonstrates the efficacy of AGORA.
title Agora: Trust Less and Open More in Verification for Confidential Computing
topic Cryptography and Security
url https://arxiv.org/abs/2407.15062