-
17
pages
-
English
-
Documents
Description
Implementing an Untrusted Operating System on Trusted HardwareDavid LieChandramohan A. Thekkath Mark HorowitzUniversity of Toronto, Microsoft Research, and Stanford University1Protection in Systems: Hardware Approach• Many platforms exist where trust is placed in hardware:– Trust Computing Platform Alliance (TCPA)– Microsoft’s Palladium (NGSCB)– Intel LaGrande Architecture• Advantages of hardware approach– Better tamper-resistance– Less dependent on OS correctness for security• Trust in hardware means less trust (or no) in OS– We need to rethink operating system designDavid Lie Implementing an Untrusted Operating System on Trusted Hardware SOSP 2003 2Rethinking the Role of the OS• A traditional OS performs both resource management and protection for applications– But now applications and OS are mutually suspicious– But applications don’t trust OS to access their code and data– OS must be able to interrupt applications • Use XOM (eXecute Only Memory) as an example platform– New operating system is called XOMOS• XOMOS is UNIX-like, port of IRIX 6.5– Should support most standard UNIX applicationsDavid Lie Implementing an Untrusted Operating System on Trusted Hardware SOSP 2003 3XOM Hardware Architecture• XOM is implemented as a set of ISA extensions• XOM Processor implements compartments for protection– Each compartment has a unique XOM ID– Architectural tags to control access to data on-chip– Cryptographic mechanisms protect data ...
-
Publié par
-
Langue
English