论文标题
基于远程证明和后门检查建立后门网络架构
Towards a Backdoorless Network Architecture Based on Remote Attestation and Backdoor Inspection
论文作者
论文摘要
为了确保系统的安全,系统中的所有设备都需要保持良性。为了避免恶意和/或折衷设备,已经使用了基于信任硬件的凭据和远程证明的网络访问控制,例如身份验证。这些技术确保了设备的真实性和完整性,但不能减轻开发人员嵌入后门的风险。为了解决这个问题,我们提出了一种新颖的体系结构,以整合远程证明和后门检查。具体而言,后门检查结果存储在服务器中,当执行远程证明时,验证器检索并检查后门检查结果。此外,我们讨论了将拟议的体系结构部署到现实世界的问题。
To keep a system secure, all devices in the system need to be benign. To avoid malicious and/or compromised devices, network access control such as authentication using a credential and remote attestation based on trusted hardware has been used. These techniques ensure the authenticity and integrity of the devices, but do not mitigate risks of a backdoor embedded in the devices by the developer. To tackle this problem, we propose a novel architecture that integrates remote attestation and backdoor inspection. Specifically, the backdoor inspection result is stored in a server and the verifier retrieves and checks the backdoor inspection result when the remote attestation is performed. Moreover, we discuss issues to deploy the proposed architecture to the real world.