Iso-X: A Flexible Architecture for Hardware-Managed Isolated Execution

Dmitry Evtyushkin, J. Elwell, Meltem Ozsoy, D. Ponomarev, N. Abu-Ghazaleh, Ryan D. Riley
{"title":"Iso-X: A Flexible Architecture for Hardware-Managed Isolated Execution","authors":"Dmitry Evtyushkin, J. Elwell, Meltem Ozsoy, D. Ponomarev, N. Abu-Ghazaleh, Ryan D. Riley","doi":"10.1109/MICRO.2014.25","DOIUrl":null,"url":null,"abstract":"We consider the problem of how to provide an execution environment where the application's secrets are safe even in the presence of malicious system software layers. We propose Iso-X -- a flexible, fine-grained hardware-supported framework that provides isolation for security-critical pieces of an application such that they can execute securely even in the presence of untrusted system software. Isolation in Iso-X is achieved by creating and dynamically managing compartments to host critical fragments of code and associated data. Iso-X provides fine-grained isolation at the memory-page level, flexible allocation of memory, and a low-complexity, hardware-only trusted computing base. Iso-X requires minimal additional hardware, a small number of new ISA instructions to manage compartments, and minimal changes to the operating system which need not be in the trusted computing base. The run-time performance overhead of Iso-X is negligible and even the overhead of creating and destroying compartments is modest. Iso-X offers higher memory flexibility than the recently proposed SGX design from Intel, allowing both fluid partitioning of the vailable memory space and dynamic growth of compartments. An FPGA implementation of Iso-X runtime mechanisms shows a negligible impact on the processor cycle time.","PeriodicalId":6591,"journal":{"name":"2014 47th Annual IEEE/ACM International Symposium on Microarchitecture","volume":"44 1","pages":"190-202"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"88","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 47th Annual IEEE/ACM International Symposium on Microarchitecture","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MICRO.2014.25","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 88

Abstract

We consider the problem of how to provide an execution environment where the application's secrets are safe even in the presence of malicious system software layers. We propose Iso-X -- a flexible, fine-grained hardware-supported framework that provides isolation for security-critical pieces of an application such that they can execute securely even in the presence of untrusted system software. Isolation in Iso-X is achieved by creating and dynamically managing compartments to host critical fragments of code and associated data. Iso-X provides fine-grained isolation at the memory-page level, flexible allocation of memory, and a low-complexity, hardware-only trusted computing base. Iso-X requires minimal additional hardware, a small number of new ISA instructions to manage compartments, and minimal changes to the operating system which need not be in the trusted computing base. The run-time performance overhead of Iso-X is negligible and even the overhead of creating and destroying compartments is modest. Iso-X offers higher memory flexibility than the recently proposed SGX design from Intel, allowing both fluid partitioning of the vailable memory space and dynamic growth of compartments. An FPGA implementation of Iso-X runtime mechanisms shows a negligible impact on the processor cycle time.
Iso-X:硬件管理隔离执行的灵活架构
我们考虑的问题是如何提供一个执行环境,即使在存在恶意系统软件层的情况下,应用程序的秘密也是安全的。我们提出Iso-X——一个灵活的、细粒度的硬件支持框架,它为应用程序的安全关键部分提供隔离,这样即使在不受信任的系统软件存在的情况下,它们也可以安全地执行。Iso-X中的隔离是通过创建和动态管理存放关键代码片段和相关数据的分区来实现的。Iso-X提供了内存页级别的细粒度隔离、灵活的内存分配和低复杂性、仅依赖硬件的可信计算基础。Iso-X只需要很少的额外硬件,少量新的ISA指令来管理分区,对操作系统的更改也很少,这些更改不需要在可信计算基础中进行。Iso-X的运行时性能开销可以忽略不计,甚至创建和销毁分区的开销也很有限。Iso-X提供了比英特尔最近提出的SGX设计更高的内存灵活性,允许可用内存空间的流体分区和分区的动态增长。Iso-X运行时机制的FPGA实现显示对处理器周期时间的影响可以忽略不计。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信