FUsing Hybrid Remote Attestation with a Formally Verified Microkernel: Lessons Learned

Karim Eldefrawy, Norrathep Rattanavipanon, Gene Tsudik · 2017

Remote Attestation (RA) allows a trusted entity (verifier) to securely measure internal state of a remote untrusted device (prover). RA can be used to establish a static or dynamic root of trust in embedded and cyber-physical systems. There are 3 types of RA designs: hardware-based, software-based, and hybrid, each with its own benefits and drawbacks. This paper presents the first hybrid RA design (HYDRA) that builds upon formally verified software components that ensure memory isolation and protection, as well as enforce memory access controls. HYDRA obtains these properties by using the formally verified seL4 microkernel. We instantiate HYDRA on a popular commodity platform and assess its performance via experiments; we show that HYDRA can attest 10MB of memory in less than 500msec. The paper also discusses the challenges facing development of HYDRA and the lessons learned.

Read the paper · More papers on PaperTik