计算机科学
软件部署
操作系统
嵌入式系统
个性化
服务器
钥匙(锁)
小贩
集合(抽象数据类型)
云计算
威胁模型
分布式计算
计算机安全
万维网
程序设计语言
营销
业务
作者
Dayeol Lee,David Kohlbrenner,Shweta Shinde,Krste Asanović,Dawn Song
标识
DOI:10.1145/3342195.3387532
摘要
Trusted execution environments (TEEs) see rising use in devices from embedded sensors to cloud servers and encompass a range of cost, power constraints, and security threat model choices. On the other hand, each of the current vendor-specific TEEs makes a fixed set of trade-offs with little room for customization. We present Keystone---the first open-source framework for building customized TEEs. Keystone uses simple abstractions provided by the hardware such as memory isolation and a programmable layer underneath untrusted components (e.g., OS). We build reusable TEE core primitives from these abstractions while allowing platform-specific modifications and flexible feature choices. We showcase how Keystone-based TEEs run on unmodified RISC-V hardware and demonstrate the strengths of our design in terms of security, TCB size, execution of a range of benchmarks, applications, kernels, and deployment models.
科研通智能强力驱动
Strongly Powered by AbleSci AI