Fidelius: Protecting User Secrets from Compromised Browsers
Saba Eskandarian, Jonathan Cogan, Sawyer Birnbaum, Peh Chang Wei Brandon, Dillon Franke, Forest Fraser, Gaspar Garcia Jr., Eric Gong, Hung T. Nguyen, Taresh K. Sethi, Vishal Subbiah, Michael Backes
摘要
Users regularly enter sensitive data, such as passwords, credit card numbers, or tax information, into the browser window. While modern browsers provide powerful client-side privacy measures to protect this data, none of these defenses prevent a browser compromised by malware from stealing it. In this work, we present Fidelius, a new architecture that uses trusted hardware enclaves integrated into the browser to enable protection of user secrets during web browsing sessions, even if the entire underlying browser and OS are fully controlled by a malicious attacker. Fidelius solves many challenges involved in providing protection for browsers in a fully malicious environment, offering support for integrity and privacy for form data, JavaScript execution, XMLHttpRequests, and protected web storage, while minimizing the TCB. Moreover, interactions between the enclave and the browser, the keyboard, and the display all require new protocols, each with their own security considerations. Finally, Fidelius takes into account UI considerations to ensure a consistent and simple interface for both developers and users. As part of this project, we develop the first open source system that provides a trusted path from input and output peripherals to a hardware enclave with no reliance on additional hypervisor security assumptions. These components may be of independent interest and useful to future projects. We implement and evaluate Fidelius to measure its performance overhead, finding that Fidelius imposes acceptable overhead on page load and user interaction for secured pages and has no impact on pages and page components that do not use its enhanced security features.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- BlackMirror: Preventing Wallhacks in 3D Online FPS GamesSeonghyun Park, Adil Ahmad, Byoungyoung LeeCCS 2020 · 被引用 17 次
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 被引用 13 次
- CACTI: Captcha Avoidance via Client-side TEE IntegrationYoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene TsudikUSENIX Security 2021 · 被引用 11 次
- SENG, the SGX-Enforcing Network Gateway: Authorizing Communication from Shielded ClientsFabian Schwarz, Christian RossowUSENIX Security 2020
- The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's PerspectiveAndrea Mengascini, Ryan Aurelio, Giancarlo PellegrinoCCS 2024
它引用的顶会 Paper12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
相关 Paper
- Master of Web Puppets: Abusing Web Browsers for Persistent and Stealthy ComputationPanagiotis Papadopoulos, Panagiotis Ilia, Michalis Polychronakis, Evangelos P. Markatos 等NDSS 2019 · 被引用 36 次
- Peripheral Instinct: How External Devices Breach Browser SandboxesLeon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert 等WWW 2025 · 被引用 2 次
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig 等DAC 2022 · 被引用 11 次
- LightBox: Full-stack Protected Stateful Middlebox at Lightning SpeedHuayi Duan, Cong Wang, Xingliang Yuan, Yajin Zhou 等CCS 2019 · 被引用 88 次
- Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web BrowsersAnuj Gautam, Tarun Kumar Yadav, Garrett Smith, Kent E. Seamons 等CCS 2025
