Lune

USENIX Security2021Top-tier venue

DICE*: A Formally Verified Implementation of DICE Measured Boot

Zhe Tao, Aseem Rastogi, Naman Gupta, Kapil Vaswani, Aditya V. Thakur

2021Year
25Citations
5Top-tier citations

Abstract

Measured boot is an important class of boot protocols that ensure that each layer of firmware and software in a device's chain of trust is measured, and the measurements are reliably recorded for subsequent verification. This paper presents DICE , a formal specification as well as a formally verified implementation of DICE, an industry standard measured boot protocol. DICE is proved to be functionally correct, memorysafe, and resistant to timing-and cache-based side-channels. A key component of DICE is a verified certificate creation library for a fragment of X.509. We have integrated DICE into the boot firmware of an STM32H753ZI micro-controller. Our evaluation shows that using a fully verified implementation has minimal to no effect on the code size and boot time when compared to an existing unverified implementation.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 065d4c93-983d-4007-ae8c-d60616b5f185

Cited by top-tier papers5

Ask how each one uses it

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines