본문

서브메뉴

Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative...
Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20260202103650
ISBN  
9798314875681
DDC  
004
저자명  
van Schaik, Stephan.
서명/저자  
Future-Proofing Trusted Execution Environments Against the Emerging Threats of Speculative Execution
발행사항  
[Sl] : University of Michigan, 2025
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2025
형태사항  
192 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-11, Section: A.
주기사항  
Advisor: Genkin, Daniel;Halderman, Alex.
학위논문주기  
Thesis (Ph.D.)--University of Michigan, 2025.
초록/해제  
요약In pursuit for better performance, contemporary processor implementations have incorporated a number of optimization techniques, including both speculative and out-of-order execution. Unfortunately, it turns out that these implementations are riddled with micro-architectural flaws that are detrimental to the security boundaries imposed by the processor to isolate different execution environments from one another. In this dissertation we do not only explore the micro-architectural attacks that are consequently possible on these processors, but we also present various techniques that allow attackers to siphon out potentially sensitive information from numerous micro-architectural buffers. We call this class of attacks Micro-architectural Data Sampling (MDS) attacks. In response, vendors have attempted to mitigate them in a whack-a-mole fashion, addressing them one-by-one as they are reported, rather than mitigating them using a more fundamental and systematic approach to address them all at once.The thesis of this dissertation argues that, in a world where such attacks are becoming more and more pervasive, the incremental approach of "spot" mitigations, currently practiced by both operating system vendors and CPU designers alike, is ineffective at adequately mitigating both current and future speculative- and transient-execution vulnerabilities, and that consequently these vulnerabilities jeopardize security-critical environments, such as TEEs and confidential cloud computing platforms. In order to address the limitations of this approach, this dissertation argues that such security-critical environments should employ remote attestation to guarantee a trusted status, as well as a seamless TCB recovery mechanism, without expecting any involvement from end users of such environments, to maintain that trusted status. Furthermore, users of these environments should expect future discoveries and disclosures of speculative- and transient-execution vulnerabilities. As such, they not only require a thorough understanding of what information can potentially be compromised, but they should also prepare a TCB recovery plan as well as push vendors to timely release mitigations to limit the impact of such vulnerabilities.
일반주제명  
Computer science
일반주제명  
Computer engineering
일반주제명  
Information science
키워드  
Trusted execution environment
키워드  
Side channel attack
키워드  
Speculative execution
키워드  
Transient execution
기타저자  
University of Michigan Computer Science & Engineering
기본자료저록  
Dissertations Abstracts International. 86-11A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008260126s2025        us                              c    eng  d
■001000017358142
■00520260202103650
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798314875681
■035    ▼a(MiAaPQ)AAI32092680
■035    ▼a(MiAaPQ)umichrackham006156
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼avan  Schaik,  Stephan.
■24510▼aFuture-Proofing  Trusted  Execution  Environments  Against  the  Emerging  Threats  of  Speculative  Execution
■260    ▼a[Sl]▼bUniversity  of  Michigan▼c2025
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2025
■300    ▼a192  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-11,  Section:  A.
■500    ▼aAdvisor:  Genkin,  Daniel;Halderman,  Alex.
■5021  ▼aThesis  (Ph.D.)--University  of  Michigan,  2025.
■520    ▼aIn  pursuit  for  better  performance,  contemporary  processor  implementations  have  incorporated  a  number  of  optimization  techniques,  including  both  speculative  and  out-of-order  execution.  Unfortunately,  it  turns  out  that  these  implementations  are  riddled  with  micro-architectural  flaws  that  are  detrimental  to  the  security  boundaries  imposed  by  the  processor  to  isolate  different  execution  environments  from  one  another.  In  this  dissertation  we  do  not  only  explore  the  micro-architectural  attacks  that  are  consequently  possible  on  these  processors,  but  we  also  present  various  techniques  that  allow  attackers  to  siphon  out  potentially  sensitive  information  from  numerous  micro-architectural  buffers.  We  call  this  class  of  attacks  Micro-architectural  Data  Sampling  (MDS)  attacks.  In  response,  vendors  have  attempted  to  mitigate  them  in  a  whack-a-mole  fashion,  addressing  them  one-by-one  as  they  are  reported,  rather  than  mitigating  them  using  a  more  fundamental  and  systematic  approach  to  address  them  all  at  once.The  thesis  of  this  dissertation  argues  that,  in  a  world  where  such  attacks  are  becoming  more  and  more  pervasive,  the  incremental  approach  of  "spot"  mitigations,  currently  practiced  by  both  operating  system  vendors  and  CPU  designers  alike,  is  ineffective  at  adequately  mitigating  both  current  and  future  speculative-  and  transient-execution  vulnerabilities,  and  that  consequently  these  vulnerabilities  jeopardize  security-critical  environments,  such  as  TEEs  and  confidential  cloud  computing  platforms.  In  order  to  address  the  limitations  of  this  approach,  this  dissertation  argues  that  such  security-critical  environments  should  employ  remote  attestation  to  guarantee  a  trusted  status,  as  well  as  a  seamless  TCB  recovery  mechanism,  without  expecting  any  involvement  from  end  users  of  such  environments,  to  maintain  that  trusted  status.  Furthermore,  users  of  these  environments  should  expect  future  discoveries  and  disclosures  of  speculative-  and  transient-execution  vulnerabilities.  As  such,  they  not  only  require  a  thorough  understanding  of  what  information  can  potentially  be  compromised,  but  they  should  also  prepare  a  TCB  recovery  plan  as  well  as  push  vendors  to  timely  release  mitigations  to  limit  the  impact  of  such  vulnerabilities.
■590    ▼aSchool  code:  0127.
■650  4▼aComputer  science
■650  4▼aComputer  engineering
■650  4▼aInformation  science
■653    ▼aTrusted  execution  environment
■653    ▼aSide  channel  attack
■653    ▼aSpeculative  execution
■653    ▼aTransient  execution
■690    ▼a0984
■690    ▼a0464
■690    ▼a0723
■71020▼aUniversity  of  Michigan▼bComputer  Science  &  Engineering.
■7730  ▼tDissertations  Abstracts  International▼g86-11A.
■790    ▼a0127
■791    ▼aPh.D.
■792    ▼a2025
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17358142▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF16022 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.