ProximiTEE: Hardened SGX Attestation and Trusted Path through Proximity Verification

Aritra Dhar, Ivan Puddu, Kostianen, Kari, Srđjan Čapkun · Repository for Publications and Research Data (ETH Zurich) · 2018

Intel's Software Guard Extensions (SGX) enables isolated execution environments, called enclaves, on untrusted operating systems (OS), and thus it can improve the security for various applications and online services. However, SGX has also well-known limitations. First, its remote attestation mechanism is vulnerable to relay attacks that allow the attacker to redirect attestation and the following provisioning of secrets to an unintended platform. Second, attestation keys have been shown to leak thus enabling attackers to fake the secure attested environment by emulating it. Third, there exists no secure way to let enclaves communicate with the I/O devices and as a consequence the user. To address these shortcomings, we propose a hardened variant of SGX attestation using proximity verification. We design and implement a system called ProximiTEE, where a simple embedded device with a low TCB is attached to the target platform. The embedded device verifies the proximity of the attested enclave by using distance bounding and secure boot-time initialization, thus allowing secure attestation regardless of a compromised OS or leaked attestation keys. Our boot-time initialization can be seen as a novel variant of ``trust on first use'' (TOFU) that makes deployment of secure attestation easier, reduces the system's attack surface and enables secure revocation. We further leverage the embedded device to build a trusted I/O path between peripherals (e.g., keyboards, displays) and enclaves, by letting it securely mediate every I/O communication between them. Our prototype implementation shows that such proximity verification is reliable in practice. --> Intel SGX enables protected enclaves on untrusted computing platforms. An important part of SGX is its remote attestation mechanism that allows a remote verifier to check that an enclave was correctly constructed before provisioning secrets to it. However, SGX attestation is vulnerable to relay attacks where the attacker, such as malicious OS, redirects the attestation and therefore the provisioning of confidential data to a platform that he physically controls. Given this redirection, the attacker has unlimited time to mount side-channel, micro-architectural and physical attacks to compromise the enclave. In this paper, we propose ProximiTEE, a novel solution to prevent relay attacks. Our solution is based on a simple embedded device, and it is best suited to deployments where the deployment cost of such a device is minor compared to its security benefit. During attestation, the embedded device, attached to the target platform, verifies the proximity of the attested enclave using distance bounding, thus allowing secure attestation regardless of a compromised OS. The device also performs periodic proximity verification which enables secure enclave revocation by simply detaching the device. Our evaluation shows that proximity verification is secure and reliable for SGX, even using a slow prototype device and assuming very fast adversaries. Additionally, we consider a stronger adversary that has a leaked, but not yet revoked, SGX attestation key and emulates an enclave on the target platform. To address such emulation attacks, we propose a solution where the target platform is securely initialized by booting it from the attached embedded device. Finally, we show how our hardened attestation mechanisms can be used to build a trusted path solution for SGX. To address these shortcomings, we propose a hardened variant of SGX attestation using proximity verification. We design and implement a system called ProximiTEE, where a simple embedded device with a low TCB is attached to the target platform. The embedded device verifies the proximity of the attested enclave by using distance bounding and secure boot-time initialization, thus allowing secure attestation regardless of a compromised OS or leaked attestation keys. Our boot-time initialization can be seen as a novel variant of ``trust on first use'' (TOFU) that makes deployment of secure attestation easier, reduces the system's attack surface and enables secure revocation. We further leverage the embedded.

Read the paper · More papers on PaperTik