Trust-V: Toward Secure and Reliable Storage for Trusted Execution Environments
Seung-Kyun Han, Jiyeon Yang, Jinsoo Jang
摘要
Trusted execution environments (TEEs) provide strong isolation for security-critical applications (enclaves) and their runtime data from potentially malicious operating systems. While TEEs also support secure storage by sealing data and storing it persistently on media, they do not ensure the integrity of sealed data, leaving it vulnerable to deletion or manipulation by an untrusted OS. In this work, we present Trusted Storage, a runtime storage isolation mechanism for TEEs that guarantees the integrity of TEE persistent data. The core design partitions storage into trusted and untrusted regions and enforces access control by locking MMIO regions and monitoring block I/O. To ensure portability, Trusted Storage requires no hardware modifications or additional hardware. We implemented a prototype, Trust-V, on the RISC-V platform. In particular, to support secure operation on legacy devices where security features are limited, Trust-V introduces a Virtual-M mode, a sandboxed privileged execution environment in machine mode, for securely hosting the monitor. Our evaluation demonstrates that, although Trust-V incurs up to 3.86× system overhead, it allows TEE software to reliably store and retrieve persistent data.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig 等DAC 2022 · 被引用 11 次
- Dorami: Privilege Separating Security Monitor on RISC-V TEEsMark Kuhne, Stavros Volos, Shweta ShindeUSENIX Security 2025
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution EnvironmentsMoein Ghaniyoun, Kristin Barber, Yuan Xiao, Yinqian Zhang 等ISCA 2023 · 被引用 6 次
- Elasticlave: An Efficient Memory Model for EnclavesJason Zhijingcheng Yu, Shweta Shinde, Trevor E. Carlson, Prateek SaxenaUSENIX Security 2022
