서브메뉴
검색
Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260202103650
- ISBN
- 9798314875681
- DDC
- 004
- 서명/저자
- Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
- 발행사항
- [Sl] : University of Michigan, 2025
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2025
- 형태사항
- 192 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 86-11, Section: A.
- 주기사항
- Advisor: Genkin, Daniel;Halderman, Alex.
- 학위논문주기
- Thesis (Ph.D.)--University of Michigan, 2025.
- 초록/해제
- 요약In pursuit for better performance, contemporary processor implementations have incorporated a number of optimization techniques, including both speculative and out-of-order execution. Unfortunately, it turns out that these implementations are riddled with micro-architectural flaws that are detrimental to the security boundaries imposed by the processor to isolate different execution environments from one another. In this dissertation we do not only explore the micro-architectural attacks that are consequently possible on these processors, but we also present various techniques that allow attackers to siphon out potentially sensitive information from numerous micro-architectural buffers. We call this class of attacks Micro-architectural Data Sampling (MDS) attacks. In response, vendors have attempted to mitigate them in a whack-a-mole fashion, addressing them one-by-one as they are reported, rather than mitigating them using a more fundamental and systematic approach to address them all at once.The thesis of this dissertation argues that, in a world where such attacks are becoming more and more pervasive, the incremental approach of "spot" mitigations, currently practiced by both operating system vendors and CPU designers alike, is ineffective at adequately mitigating both current and future speculative- and transient-execution vulnerabilities, and that consequently these vulnerabilities jeopardize security-critical environments, such as TEEs and confidential cloud computing platforms. In order to address the limitations of this approach, this dissertation argues that such security-critical environments should employ remote attestation to guarantee a trusted status, as well as a seamless TCB recovery mechanism, without expecting any involvement from end users of such environments, to maintain that trusted status. Furthermore, users of these environments should expect future discoveries and disclosures of speculative- and transient-execution vulnerabilities. As such, they not only require a thorough understanding of what information can potentially be compromised, but they should also prepare a TCB recovery plan as well as push vendors to timely release mitigations to limit the impact of such vulnerabilities.
- 일반주제명
- Computer science
- 일반주제명
- Computer engineering
- 일반주제명
- Information science
- 기타저자
- University of Michigan Computer Science & Engineering
- 기본자료저록
- Dissertations Abstracts International. 86-11A.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260126s2025 us c eng d■001000017358142
■00520260202103650
■006m o d
■007cr#unu||||||||
■020 ▼a9798314875681
■035 ▼a(MiAaPQ)AAI32092680
■035 ▼a(MiAaPQ)umichrackham006156
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼avan Schaik, Stephan.
■24510▼aFuture-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
■260 ▼a[Sl]▼bUniversity of Michigan▼c2025
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2025
■300 ▼a192 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 86-11, Section: A.
■500 ▼aAdvisor: Genkin, Daniel;Halderman, Alex.
■5021 ▼aThesis (Ph.D.)--University of Michigan, 2025.
■520 ▼aIn pursuit for better performance, contemporary processor implementations have incorporated a number of optimization techniques, including both speculative and out-of-order execution. Unfortunately, it turns out that these implementations are riddled with micro-architectural flaws that are detrimental to the security boundaries imposed by the processor to isolate different execution environments from one another. In this dissertation we do not only explore the micro-architectural attacks that are consequently possible on these processors, but we also present various techniques that allow attackers to siphon out potentially sensitive information from numerous micro-architectural buffers. We call this class of attacks Micro-architectural Data Sampling (MDS) attacks. In response, vendors have attempted to mitigate them in a whack-a-mole fashion, addressing them one-by-one as they are reported, rather than mitigating them using a more fundamental and systematic approach to address them all at once.The thesis of this dissertation argues that, in a world where such attacks are becoming more and more pervasive, the incremental approach of "spot" mitigations, currently practiced by both operating system vendors and CPU designers alike, is ineffective at adequately mitigating both current and future speculative- and transient-execution vulnerabilities, and that consequently these vulnerabilities jeopardize security-critical environments, such as TEEs and confidential cloud computing platforms. In order to address the limitations of this approach, this dissertation argues that such security-critical environments should employ remote attestation to guarantee a trusted status, as well as a seamless TCB recovery mechanism, without expecting any involvement from end users of such environments, to maintain that trusted status. Furthermore, users of these environments should expect future discoveries and disclosures of speculative- and transient-execution vulnerabilities. As such, they not only require a thorough understanding of what information can potentially be compromised, but they should also prepare a TCB recovery plan as well as push vendors to timely release mitigations to limit the impact of such vulnerabilities.
■590 ▼aSchool code: 0127.
■650 4▼aComputer science
■650 4▼aComputer engineering
■650 4▼aInformation science
■653 ▼aTrusted execution environment
■653 ▼aSide channel attack
■653 ▼aSpeculative execution
■653 ▼aTransient execution
■690 ▼a0984
■690 ▼a0464
■690 ▼a0723
■71020▼aUniversity of Michigan▼bComputer Science & Engineering.
■7730 ▼tDissertations Abstracts International▼g86-11A.
■790 ▼a0127
■791 ▼aPh.D.
■792 ▼a2025
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17358142▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


