APRON: Authenticated and Progressive System Image Renovation
Sangho Lee
Abstract
The integrity and availability of an operating system are important to securely use a computing device. Conventional schemes focus on how to prevent adversaries from corrupting the operating system or how to detect such corruption. However, how to recover the device from such corruption securely and efficiently is overlooked, resulting in lengthy system downtime with integrity violation and unavailability.
In this paper, we propose APRON, a novel scheme to renovate a corrupt or outdated operating system image securely and progressively. APRON concurrently and selectively repairs any invalid blocks on demand during and after the system boot, effectively minimizing the system downtime needed for a recovery. APRON verifies whether requested blocks are valid in the kernel using a signed Merkle hash tree computed over the valid, up-to-date system image. If they are invalid, it fetches corresponding blocks from a reliable source, verifies them, and replaces the requested blocks with the fetched ones. Once the system boots up, APRON runs a background thread to eventually renovate any other non-requested invalid blocks. Our evaluation shows that APRON has short downtime: it outperforms conventional recovery mechanisms by up to 28×. It runs real-world applications with an average runtime overhead of 9% during the renovation and with negligible overhead (0.01%) once the renovation is completed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fc00c32c-3b0f-4fa3-b1f7-ed6e806fadadBuilds on3
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England et al.S&P 2019 · 61 citations
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia et al.USENIX Security 2017 · 60 citations
- Virtual machine preserving host updates for zero day patching in public cloudMark Russinovich, Naga K. Govindaraju, Melur Raghuraman, David Hepkin et al.EuroSys 2021 · 8 citations
Related papers
- A Midsummer Night's Tree: Efficient and High Performance Secure SCMSamuel Thomas, Kidus Workneh, Jac McCarty, Joseph Izraelevitz et al.ASPLOS 2024 · 5 citations
- A Write-Friendly and Fast-Recovery Scheme for Security Metadata in Non-Volatile MemoriesJianming Huang, Yu HuaHPCA 2021 · 14 citations
- Root Crash Consistency of SGX-style Integrity Trees in Secure Non-Volatile Memory SystemsJianming Huang, Yu HuaHPCA 2023 · 6 citations
- Fast, Transparent Filesystem Microkernel Recovery with AnankeJing Liu, Yifan Dai, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauFAST 2025 · 6 citations
- On Scalable Integrity Checking for Secure Cloud DisksQuinn Burke, Ryan Sheatsley, Rachel King, Owen Hines et al.FAST 2025 · 5 citations
