A Simple Protocol for Remote Attestation of System Integrity - Roberto Sassu

  Рет қаралды 3,023

The Linux Foundation

The Linux Foundation

Күн бұрын

A Simple Protocol for Remote Attestation of System Integrity - Roberto Sassu, Huawei Technologies Duesseldorf GmbH
TPM keys can be sealed to the platform state. However, the state cannot include measurements done by Integrity Measurement Architecture (IMA), as file accesses are unpredictable. The proposed IMA Digest Lists extension overcomes this issue by preloading reference measurements from software vendors into the kernel memory and reporting only unknown file accesses. This talk proposes a simple solution for remote attestation that does not require dedicated servers. An endpoint of a TLS channel can implicitly prove to the other endpoint its integrity by performing the handshake, and by providing an X.509 extension from TCG, Subject Key Attestation Evidence (SKAE), certifying that the handshake is done with a TPM key, sealed to a good system state. The talk shows how the feasibility issue of conventional solutions has been addressed and details the tradeoffs made to accomplish the objective.
About Roberto Sassu
Roberto Sassu received a MsC in Information Security in 2008 and worked as a research assistant until 2014. He published and presented papers on Trusted Computing at STC'11 and TrustCom 2014. He also participated to several European projects (OpenTC, TClouds, SECURED and FutureTPM). After working at SUSE Linux from 2015 to 2017, he joined Huawei in 2017 and contributes to the integration of Trusted Computing technologies into products.

Пікірлер
Remote Attestation Procedures Architecture
57:03
Confidential Computing Consortium
Рет қаралды 4,9 М.
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН
Measuring Latency in the UDM Pro MAX Firewall!
30:08
Jeff's CTO Laboratory
Рет қаралды 689
Keylime Demo: Remote Trust for IoT, Edge, and Cloud
12:52
Red Hat Community
Рет қаралды 6 М.
Mastering TPM: Insider Insights for IT Professionals
9:51
TechsavvyProductions
Рет қаралды 118 М.
Inside the V3 Nazi Super Gun
19:52
Blue Paw Print
Рет қаралды 3,2 МЛН
ARM TrustZone - Brandon Adler
18:31
RITSEC
Рет қаралды 15 М.
How Engines Are Made
7:34
Insider Cars
Рет қаралды 145 М.
Simon Sinek's Advice Will Leave You SPEECHLESS 2.0 (MUST WATCH)
20:43
Alpha Leaders
Рет қаралды 2,8 МЛН
What is device attestation and why is it important?
6:06
GlobalPlatform TV
Рет қаралды 1,9 М.
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН