Presence Attestation: The Missing Link in Dynamic Trust Bootstrapping
Zhangkai Zhang, Xuhua Ding, Gene Tsudik, Jinhua Cui, Zhoujun Li
摘要
Many popular modern processors include an important hardware security feature in the form of a DRTM (Dynamic Root of Trust for Measurement) that helps bootstrap trust and resists software attacks. However, despite substantial body of prior research on trust establishment, security of DRTM was treated without involvement of the human user, who represents a vital missing link. The basic challenge is: how can a human user determine whether an expected DRTM is currently active on her device? In this paper, we define the notion of "presence attestation", which is based on mandatory, though minimal, user participation. We present three concrete presence attestation schemes: sightbased, location-based and scene-based. They vary in terms of security and usability features, and are suitable for different application contexts. After analyzing their security, we assess their usability and performance based on prototype implementations. KEYWORDS trusted computing, attestation, dynamic root of trust, human-inthe-loop, device I/O * The work was mainly done when the author visited SMU as a student intern. 1 We slightly expand the notion of DRTM as TrustZone functions differently from the TXT and SVM.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- CACTI: Captcha Avoidance via Client-side TEE IntegrationYoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene TsudikUSENIX Security 2021 · 被引用 11 次
- Oblivious Digital TokensMihael Liskij, Xuhua Ding, Gene Tsudik, David A. BasinUSENIX Security 2025
- VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer RequestsScott Jordan, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd 等NDSS 2023
它引用的顶会 Paper2
相关 Paper
- Caveat (IoT) Emptor: Towards Transparency of IoT Device PresenceSashidhar Jakkamsetti, Youngil Kim, Gene TsudikCCS 2023 · 被引用 5 次
- TrustWeave: Integrity Measurement and Attestation For Multi-Cloud LLMsJianchang Su, Wenhui Zhang, Yifan Zhang, Kexin Chu 等EuroSys 2026
- PISTIS: Trusted Computing Architecture for Low-end Embedded SystemsMichele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno CrispoUSENIX Security 2022
- A Bad Dream: Subverting Trusted Platform Module While You Are SleepingSeunghun Han, Wook Shin, Jun-Hyeok Park, Hyoung-Chun KimUSENIX Security 2018 · 被引用 34 次
- OPERA: Open Remote Attestation for Intel's Secure EnclavesGuoxing Chen, Yinqian Zhang, Ten-Hwang LaiCCS 2019 · 被引用 67 次
