Securing 5G: Trusted Execution Environments for Centrally Controlled IPsec Integrity

Grazia D’Onghia, Flavio Ciravegna, Giacomo Bruno, Mattin Antartiko Elorza Forcada, Antonio Pastor, Antonio Lioy · 2024

This demo introduces a novel method to enhance IoT communication security using a Trusted Execution Environment (TEE). Secure IPsec channels between two devices with x86 and RISC-V platforms are established by employing a platform equipped with a dedicated hardware Root of Trust. Enarx on x86 (equipped with Intel SGX) and Keystone on RISC-V machines serve as TEEs, ensuring integrity and confidentiality. This demo exhibits a workflow where the IPsec configuration is received from a centralized controller and is securely stored and managed within the TEE. By providing a comprehensive solution for securing IoT communications, the demonstration highlights the importance of TEEs in ensuring the integrity and confidentiality of interconnected devices in modern network infrastructures.

Read the paper · More papers on PaperTik