Publication | Open Access
OPERA
60
Citations
31
References
2019
Year
Unknown Venue
EngineeringInformation SecurityConfidential ComputingSoftware AnalysisFormal VerificationHardware SecurityTrusted Execution EnvironmentTrusted Operating SystemOperating System SecurityComputer EngineeringData PrivacyEnclave Remote AttestationComputer ScienceSgx HardwareData SecurityCryptographyTrusted PlatformSoftware TestingEnclave MemorySystem Software
Intel Software Guard Extensions (SGX) remote attestation enables enclaves to authenticate hardware inside which they run, and attest the integrity of their enclave memory to the remote party. To enforce direct control of attestation, Intel mandates attestation to be verified by Intel's attestation service. This Intel-centric attestation model, however, neither protects privacy nor performs efficiently when distributed and frequent attestation is required. This paper presents OPERA, an Open Platform for Enclave Remote Attestation. Without involving Intel's attestation service while conducting attestation, OPERA is unchained from Intel, although it relies on Intel to establish a chain of trust whose anchor point is the secret rooted in SGX hardware. OPERA is open, as the implementation of its attestation service is completely open, allowing any enclave developer to run her own OPERA service, and its execution is publicly verifiable and hence trustworthy; OPERA is privacy-preserving, as the attestation service does not learn which enclave is being attested or when the attestation takes place; OPERA is performant, as it does not rely on a single-point-of-verification and also reduces the latency of verification.
| Year | Citations | |
|---|---|---|
Page 1
Page 1