作者
Dmitry Evtyushkin, Jesse Elwell, Meltem Ozsoy, Dmitry Ponomarev, Nael Abu Ghazaleh, Ryan Riley
发表日期
2014/12/13
研讨会论文
Proceedings of the 47th Annual IEEE/ACM International Symposium on Microarchitecture
页码范围
190-202
出版商
IEEE Computer Society
简介
We consider the problem of how to provide an execution environment where the application's secrets are safe even in the presence of malicious system software layers. We propose Iso-X -- a flexible, fine-grained hardware-supported framework that provides isolation for security-critical pieces of an application such that they can execute securely even in the presence of untrusted system software. Isolation in Iso-X is achieved by creating and dynamically managing compartments to host critical fragments of code and associated data. Iso-X provides fine-grained isolation at the memory-page level, flexible allocation of memory, and a low-complexity, hardware-only trusted computing base. Iso-X requires minimal additional hardware, a small number of new ISA instructions to manage compartments, and minimal changes to the operating system which need not be in the trusted computing base. The run-time …
引用总数
201520162017201820192020202120222023202462123101013316136
学术搜索中的文章
D Evtyushkin, J Elwell, M Ozsoy, D Ponomarev… - 2014 47th Annual IEEE/ACM International Symposium …, 2014