LNCS 8134 - Computer Security – ESORICS 2013

  • Crampton J
  • Jajodia S
  • Mayes K
ISSN: 0302-9743
N/ACitations
Citations of this article
40Readers
Mendeley users who have this article in their library.

Abstract

In this paper we describe a novel approach to securely obtain measurements with respect to the integrity of software running on a low-cost and low-power computing node autonomously or on request. We propose to use these measurements as an indication of the trustwor-thiness of that node. Our approach is based on recent developments in Program Counter Based Access Control. Specifically, we employ San-cus, a light-weight hardware-only Trusted Computing Base and Pro-tected Module Architecture, to integrate trust assessment modules into an untrusted embedded OS without using a hypervisor. Sancus ensures by means of hardware extensions that code and data of a protected module cannot be tampered with, and that the module's data remains confidential. Sancus further provides cryptographic primitives that are employed by our approach to enable the trust management system to verify that the obtained trust metrics are authentic and fresh. Thereby, our trust assessment modules can inspect the OS or application code and securely report reliable trust metrics to an external trust management system. We evaluate a prototypic implementation of our approach that integrates Sancus-protected trust assessment modules with the Contiki OS running on a Sancus-enabled TI MSP430 microcontroller.

Author supplied keywords

Cite

CITATION STYLE

APA

Crampton, J., Jajodia, S., & Mayes, K. (2013). LNCS 8134 - Computer Security – ESORICS 2013. Lecture Notes in Computer Science, 1(September), 69–89. Retrieved from http://link.springer.com/10.1007/978-3-319-24174-6%0Afiles/2227/(Lecture Notes in Computer Science 9326) Günther Pernul, Peter Y A Ryan, Edgar Weippl (eds.)-Computer Security – ESORICS 2015_ 20th European Sy.pdf

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free