• DocumentCode
    3516658
  • Title

    Remote attestation to dynamic system properties: Towards providing complete system integrity evidence

  • Author

    Kil, Chongkyung ; Sezer, Emre C. ; Azab, Ahmed M. ; Ning, Peng ; Zhang, Xiaolan

  • Author_Institution
    Dept. of Comput. Sci., NC State Univ., Raleigh, NC, USA
  • fYear
    2009
  • fDate
    June 29 2009-July 2 2009
  • Firstpage
    115
  • Lastpage
    124
  • Abstract
    Remote attestation of system integrity is an essential part of trusted computing. However, current remote attestation techniques only provide integrity proofs of static properties of the system. To address this problem we present a novel remote dynamic attestation system named ReDAS (Remote Dynamic Attestation System) that provides integrity evidence for dynamic system properties. Such dynamic system properties represent the runtime behavior of the attested system, and enable an attester to prove its runtime integrity to a remote party. ReDAS currently provides two types of dynamic system properties for running applications: structural integrity and global data integrity. In this work, we present the challenges of remote dynamic attestation, provide an in-depth security analysis and introduce a first step towards providing a complete runtime dynamic attestation framework. Our prototype implementation and evaluation with real-world applications show that we can improve on current static attestation techniques with an average performance overhead of 8%.
  • Keywords
    data integrity; security of data; ReDAS; Remote Dynamic Attestation System; complete system integrity evidence; dynamic system properties; global data integrity; structural integrity; Computer science; Data security; Drives; Government; Hardware; Information security; Kernel; Open systems; Prototypes; Runtime; Remote attestation; dynamic attestation; runtime integrity; system security; trusted computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
  • Conference_Location
    Lisbon
  • Print_ISBN
    978-1-4244-4422-9
  • Electronic_ISBN
    978-1-4244-4421-2
  • Type

    conf

  • DOI
    10.1109/DSN.2009.5270348
  • Filename
    5270348