4.6 Article

SRX-Secure Data Backup and Recovery for SGX Applications

期刊

IEEE ACCESS
卷 10, 期 -, 页码 35901-35918

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/ACCESS.2022.3162489

关键词

Codes; Passwords; Cryptography; Software; Libraries; Encryption; Seals; Intel SGX; sealing; backup; recovery; TEE

资金

  1. European Commission [870635]
  2. Fundacao para a Ciencia e Tecnologia (FCT) [UIDB/50021/2020]
  3. Instituto Superior Tecnico (IST), Universidade de Lisboa (ULisboa)
  4. Instituto de Engenharia de Sistemas e Computadores-Investigacao e Desenvolvimento (INESC-ID)

向作者/读者索取更多资源

Intel SGX improves application security by shielding code and data in enclaves, but also makes data recovery impossible if the original computer is damaged or lost. To address this issue, SRX is proposed as a solution for sharing sealed data among a restricted set of SGX-enabled computers executing the same enclave code.
Intel SGX improves the security of applications by shielding code and data from untrusted software in enclaves. Since enclaves lose their state when closed, that state has to be sealed, i.e., cryptographically protected with a secret key, and stored outside the enclave boundary. In SGX, the used key is bound to both the enclave and the processor that sealed the data, so it is unfeasible for any enclave in another computer to derive the same secret key to unseal such data. This offers security to the data, but also makes it impossible to recover that data if the original computer is damaged or stolen. In order to support backup and recovery of data sealed by enclaves, we propose SRX, a solution for sharing sealed data amongst a restricted set of SGX-enabled computers executing the same enclave code. Enclaves using SRX have access to common keys to seal and unseal enclave data, allowing the sharing of sealed data among the trusted domain. SRX guarantees that these secret keys are never exposed outside the trusted domain. SRX was implemented and evaluated with two applications: a bitcoin wallet and a password manager.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据