Devlore: Device Interrupt Protection for Confidential VMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bertschi, Andrin, Sridhara, Supraja, Kuhne, Mark, Schlüter, Benedict, Groschupp, Friederike, Thorens, Clément, Dutly, Nicolas, Capkun, Srdjan, Shinde, Shweta
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914400466632704
author Bertschi, Andrin
Sridhara, Supraja
Kuhne, Mark
Schlüter, Benedict
Groschupp, Friederike
Thorens, Clément
Dutly, Nicolas
Capkun, Srdjan
Shinde, Shweta
author_facet Bertschi, Andrin
Sridhara, Supraja
Kuhne, Mark
Schlüter, Benedict
Groschupp, Friederike
Thorens, Clément
Dutly, Nicolas
Capkun, Srdjan
Shinde, Shweta
contents Modern confidential computing executes sensitive computation in an abstraction called confidential VMs and protects from the hypervisor, host OS, and other co-resident VMs. It has been shown that an attacker can inject malicious interrupts to break the confidentiality and integrity of confidential VMs. We present Devlore, a device interrupt isolation mechanism that protects confidential VMs from interrupt manipulation attacks. Our design employs a delegate-but-check strategy by offloading interrupt management to the hypervisor, but adds correctness checks in the trusted software. We prototype our design on Arm Confidential Computing Architecture (CCA). We evaluate it on Arm FVP to demonstrate four diverse devices attached to confidential VMs and report costs on a Rock5b board. Our case studies show the feasibility of real-world use cases and that Devlore incurs minimal overheads of 0.06% for typical integrated GPU applications.
format Preprint
id arxiv_https___arxiv_org_abs_2408_05835
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Devlore: Device Interrupt Protection for Confidential VMs
Bertschi, Andrin
Sridhara, Supraja
Kuhne, Mark
Schlüter, Benedict
Groschupp, Friederike
Thorens, Clément
Dutly, Nicolas
Capkun, Srdjan
Shinde, Shweta
Cryptography and Security
Modern confidential computing executes sensitive computation in an abstraction called confidential VMs and protects from the hypervisor, host OS, and other co-resident VMs. It has been shown that an attacker can inject malicious interrupts to break the confidentiality and integrity of confidential VMs. We present Devlore, a device interrupt isolation mechanism that protects confidential VMs from interrupt manipulation attacks. Our design employs a delegate-but-check strategy by offloading interrupt management to the hypervisor, but adds correctness checks in the trusted software. We prototype our design on Arm Confidential Computing Architecture (CCA). We evaluate it on Arm FVP to demonstrate four diverse devices attached to confidential VMs and report costs on a Rock5b board. Our case studies show the feasibility of real-world use cases and that Devlore incurs minimal overheads of 0.06% for typical integrated GPU applications.
title Devlore: Device Interrupt Protection for Confidential VMs
topic Cryptography and Security
url https://arxiv.org/abs/2408.05835