面向电力边缘智能设备的可信执行环境构建方法

A TRUSTED EXECUTION ENVIRONMENT CONSTRUCTION METHOD FOR POWER EDGE INTELLIGENT DEVICES

  • 摘要: TrustZone在用于嵌入式设备的可信执行环境构建时,现有方案存在安全性较低、响应时间较长等问题。因此,提出一种适用于电力边缘智能设备的基于TrustZone的可信执行环境构建方法,在普通世界内建立安全飞地保护应用的运行时安全,安全世界内只部署一个安全监控模块,由安全监控模块实现完整性度量与执行控制功能。普通世界发生安全相关事件时,会被普通监控模块捕获并转入安全世界进行处理,只有被安全监控模块判定为安全的操作才可以被执行。实验结果表明,该方法可以在较低的开销下有效抵御针对内核、内存和应用的攻击。

     

    Abstract: When TrustZone is used to build a trusted execution environment for embedded devices, existing solutions have problems such as low security and long response time. Therefore, this paper proposes a TrustZone- based trusted execution environment construction method for power edge intelligent devices. In the normal world, a secure enclave was established to safeguard the runtime security of the application. In the secure world, a single security monitoring module was deployed, responsible for the implementation of integrity measurement and execution control functions. When a safety- related event occurs in the normal world, it was captured by the normal monitoring module and subsequently transferred to the secure world for processing. Only operations deemed safe by the security monitoring module were permitted to be executed. The experimental results demonstrate that this method can effectively resist attacks against kernel, memory and application with low overhead.

     

/

返回文章
返回