Devlore는 기밀 VM(confidential VM)을 인터럽트 조작 공격으로부터 보호하는 디바이스 인터럽트 격리 메커니즘이다. 기존 기밀 컴퓨팅은 하이퍼바이저, 호스트 OS, 동거 VM으로부터 보호하지만, 공격자가 악성 인터럽트를 주입해 기밀성과 무결성을 깨뜨릴 수 있다는 취약점이 있었다. Devlore는 인터럽트 관리를 하이퍼바이저에 위임하되 신뢰 소프트웨어에서 정확성을 검증하는 '위임 후 검증' 전략을 사용하며, Arm CCA(Confidential Computing Architecture) 기반으로 프로토타입을 구현했다. Arm FVP에서 4종의 디바이스를 연결해 실현 가능성을 검증했고, Rock5b 보드의 통합 GPU 애플리케이션에서 오버헤드가 0.06%에 불과함을 보였다. 실제 배포 가능한 수준의 낮은 비용으로 기밀 VM 보안을 강화할 수 있음을 시사한다.
- •인터럽트 조작 공격에 대한 기밀 VM 보호를 위해 '위임 후 검증(delegate-but-check)' 전략을 사용
- •Arm CCA(Confidential Computing Architecture) 기반으로 프로토타입 구현
- •Arm FVP에서 4종 디바이스를 연결해 실제 사용 사례 가능성 검증
- •Rock5b 보드의 통합 GPU 응용에서 오버헤드 0.06%로 매우 적은 성능 손실 입증
0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Devlore: Device Interrupt Protection for Confidential VMs
본문 미리보기
arXiv:2408.05835v3 Announce Type: replace Abstract: Modern confidential computing executes sensitive computation in an abstraction called confidential VMs and protects from the hypervisor, host OS, and other co-resident VMs. It has been shown that an attacker can inject malicious interrupts to break the confidentiality and integrity of confidential VMs. We present Devlore, a device interrupt isolation mechanism that protects confidential VMs from interrupt manipulation attacks. Our design emplo
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:23AI 초안



