jVPFS: adding robustness to a secure stacked file system with untrusted local storage components
Carsten Weinhold, Hermann Härtig · 2011
The Virtual Private File System (VPFS) [1] was built to protect confidentiality and integrity of application data against strong attacks. To minimize the trusted com-puting base (i.e., the attack surface) it was built as a stacked file system, where a small isolated component in a microkernel-based system reuses a potentially large and complex untrusted file system; for example, as pro-vided by a more vulnerable guest OS in a separate virtual machine. However, its design ignores robustness issues that come with sudden power loss or crashes of the un-trusted file system. This paper addresses these issues. To minimize dam-age caused by an unclean shutdown, jVPFS carefully splits a journaling mechanism between a trusted core and the untrusted file system. The journaling approach mini-mizes the number of writes needed to maintain consistent information in a Merkle hash tree, which is stored in the untrusted file system to detect attacks on integrity. The commonly very complex and error-prone recovery func-tionality of legacy file systems (in the order of thousands of lines of code) can be reused with little increase of com-plexity in the trusted core: less than 350 lines of code deal with the security-critical aspects of crash recovery. jVPFS shows acceptable performance better than its pre-decessor VPFS, while providing much better protection against data loss. 1