Guardado en:
Detalles Bibliográficos
Autores principales: Kuhne, Mark, Volos, Stavros, Shinde, Shweta
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:https://arxiv.org/abs/2410.03653
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913532225781760
author Kuhne, Mark
Volos, Stavros
Shinde, Shweta
author_facet Kuhne, Mark
Volos, Stavros
Shinde, Shweta
contents TEE implementations on RISC-V offer an enclave abstraction by introducing a trusted component called the security monitor (SM). The SM performs critical tasks such as isolating enclaves from each other as well as from the OS by using privileged ISA instructions that enforce the physical memory protection. However, the SM executes at the highest privilege layer on the platform (machine-mode) along side firmware that is not only large in size but also includes third-party vendor code specific to the platform. In this paper, we present Dorami - a privilege separation approach that isolates the SM from the firmware thus reducing the attack surface on TEEs. Dorami re-purposes existing ISA features to enforce its isolation and achieves its goals without large overheads.
format Preprint
id arxiv_https___arxiv_org_abs_2410_03653
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Dorami: Privilege Separating Security Monitor on RISC-V TEEs
Kuhne, Mark
Volos, Stavros
Shinde, Shweta
Cryptography and Security
TEE implementations on RISC-V offer an enclave abstraction by introducing a trusted component called the security monitor (SM). The SM performs critical tasks such as isolating enclaves from each other as well as from the OS by using privileged ISA instructions that enforce the physical memory protection. However, the SM executes at the highest privilege layer on the platform (machine-mode) along side firmware that is not only large in size but also includes third-party vendor code specific to the platform. In this paper, we present Dorami - a privilege separation approach that isolates the SM from the firmware thus reducing the attack surface on TEEs. Dorami re-purposes existing ISA features to enforce its isolation and achieves its goals without large overheads.
title Dorami: Privilege Separating Security Monitor on RISC-V TEEs
topic Cryptography and Security
url https://arxiv.org/abs/2410.03653