Protecting Enclaves from Intra-Core Side-Channel Attacks through Physical Isolation
View / Open Files
Authors
Van Der Maas, M
Moore, SW
Publication Date
2020-11-13Journal Title
CYSARM 2020 - Proceedings of the 2nd Workshop on Cyber-Security Arms Race
Conference Name
CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security
ISBN
9781450380911
Publisher
ACM
Pages
1-12
Type
Conference Object
This Version
VoR
Metadata
Show full item recordCitation
Van Der Maas, M., & Moore, S. (2020). Protecting Enclaves from Intra-Core Side-Channel Attacks through Physical Isolation. CYSARM 2020 - Proceedings of the 2nd Workshop on Cyber-Security Arms Race, 1-12. https://doi.org/10.1145/3411505.3418437
Abstract
Systems that protect enclaves from privileged software must consider software-based side-channel attacks. Our system isolates enclaves on separate secure cores to stop attackers from running on the same core as the victim, which mitigates intra-core side-channel attacks. Redesigning the memory hierarchy based on enclave ownership protects enclaves against inter-core side-channel attacks. We implement this system and evaluate it in terms of communication performance, memory overhead and hardware area. Combining physical isolation and a redesigned memory hierarchy protects enclaves against all known software-based side-channel attacks.
Keywords
Clinical Research
Sponsorship
Engineering and Physical Sciences Research Council (EP/N509620/1)
EPSRC (via Queen's University Of Belfast) (R1098ECI)
EPSRC (1940704)
Identifiers
External DOI: https://doi.org/10.1145/3411505.3418437
This record's URL: https://www.repository.cam.ac.uk/handle/1810/337408
Statistics
Total file downloads (since January 2020). For more information on metrics see the
IRUS guide.
Recommended or similar items
The current recommendation prototype on the Apollo Repository will be turned off on 03 February 2023. Although the pilot has been fruitful for both parties, the service provider IKVA is focusing on horizon scanning products and so the recommender service can no longer be supported. We recognise the importance of recommender services in supporting research discovery and are evaluating offerings from other service providers. If you would like to offer feedback on this decision please contact us on: support@repository.cam.ac.uk