Faceted Secure Multi Execution
Thomas Schmitz, Maximilian Algehed, Cormac Flanagan, Alejandro Russo
摘要
To enforce non-interference, both Secure Multi-Execution (SME) and Multiple Facets (MF) rely on the introduction of multi-executions. The attractiveness of these techniques is that they are precise: secure programs running under SME or MF do not change their behavior. Although MF was intended as an optimization for SME, it does provide a weaker security guarantee for termination leaks. This paper presents Faceted Secure Multi Execution (FSME), a novel synthesis of MF and SME that combines the stronger security guarantees of SME with the optimizations of MF. The development of FSME required a unification of the ideas underlying MF and SME into a new multi-execution framework ( ), which can be parameterized to provide MF, SME, or our new approach FSME, thus enabling an apples-to-apples comparison and benchmarking of all three approaches. Unlike the original work on MF and SME, supports arbitrary (and possibly infinite) lattices necessary for decentralized labeling models-a feature needed in order to make possible the writing of applications where each principal can impose confidentiality and integrity requirements on data. We provide some micro-benchmarks for evaluating and write a file hosting service, called ProtectedBox, whose functionality can be securely extended via third-party plugins.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Pave: Information Flow Control for Privacy-preserving Online Data Processing ServicesMinkyung Park, Jaeseung Choi, Hyeonmin Lee, Ted Taekyoung KwonASPLOS 2025 · 被引用 1 次
- Tainted Secure Multi-Execution to Restrict Attacker InfluenceMcKenna McCall, Abhishek Bichhawat, Limin JiaCCS 2023 · 被引用 1 次
它引用的顶会 Paper2
相关 Paper
- Hybrid Trust Multi-party Computation with Trusted Execution EnvironmentPengfei Wu, Jianting Ning, Jiamin Shen, Hongbing Wang 等NDSS 2022
- PRIDWEN: Universally Hardening SGX Programs via Load-Time SynthesisFan Sang, Ming-Wei Shih, Sangho Lee, Xiaokuan Zhang 等USENIX ATC 2022
- MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution PartitioningShiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee 等USENIX Security 2017 · 被引用 136 次
- Generalized Policy-Based Noninterference for Efficient Confidentiality-PreservationShamiek Mangipudi, Pavel Chuprikov, Patrick Eugster, Malte Viering 等PLDI 2023 · 被引用 3 次
- Hardware-Software Contracts for Secure SpeculationMarco Guarnieri, Boris Köpf, Jan Reineke, Pepe VilaS&P 2021 · 被引用 111 次
