Non-repudiable disk I/O in untrusted kernels
Nikilesh Balakrishnan, Lucian Carata, Thomas Bytheway, Ripduman Sohan, Andy Hopper · 2017
It is currently impossible for an application to verify that the data it passes to the kernel for storage is actually submitted to an underlying device or that the data returned to an application by the kernel has actually originated from an underlying device. A compromised or malicious OS can silently discard data written by the application or return fabricated data during a read operation. This is a serious data integrity issue for use-cases where verifiable storage and retrieval of data is a necessary precondition for ensuring correct operation, for example with secure logging, APT monitoring and compliance.