vTSE:A Solution of SGX-based vTPM Secure Enhancement

Fei Yan, Yu Mei Zhao, Liqiang Zhang, Bo Zhao · DOAJ (DOAJ: Directory of Open Access Journals) · 2017

Abstract:In order to solve the problem that there is no enough security assurance of virtual trusted platform module (vTPM) in virtualized trusted platform architecture,a vTPM security enhancement (vTSE) method based on Intel SGX (software guard extension) was proposed.The characteristic of physical memory isolation of SGX was utilized firstly.Then the code and data of vTPM instances was isolated and protected in safety isolation region created by SGX.At the same time,the sealing features based on trusted area identity of enclave was used to confidentially store the nonvolatile data in safety isolation region.The experimental results showed that this method could not only dynamically protect the confidentiality and integrity of code and date during the operation of vTPM instances,but also realized the secure storage of vTPM instances data.Finally,the security and performance evaluation of the system was done.The results showed that while the proper functioning and secure storage of vTPM instances were ensured,the performance overhead added was less than 1 ms.

Read the paper · More papers on PaperTik