Flexible remote attestation of pre-SNP SEV VMs using SGX enclaves

05/16/2023
by   Pedro Antonino, et al.
0

We propose a protocol that explores a synergy between two TEE implementations: it brings SGX-like remote attestation to SEV VMs. We use the notion of a trusted guest owner, implemented as an SGX enclave, to deploy, attest, and provision a SEV VM. This machine can, in turn, rely on the trusted owner to generate SGX-like attestation proofs on its behalf. Our protocol combines the application portability of SEV with the flexible remote attestation of SGX. We formalise our protocol and prove that it achieves the intended guarantees using the Tamarin prover. Moreover, we develop an implementation for our trusted guest owner together with example SEV machines, and put those together to demonstrate how our protocol can be used in practice; we use this implementation to evaluate our protocol in the context of creating accountable machine-learning models. We also discuss how our protocol can be extended to provide a simple remote attestation mechanism for a heterogeneous infrastructure of trusted components.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/01/2020

Gimme That Model!: A Trusted ML Model Trading Protocol

We propose a HE-based protocol for trading ML models and describe possib...
research
11/25/2017

Modular Remote Communication Protocol Interpreters

We present "endpoints", a library that provides consistent client implem...
research
12/31/2020

Flexible model composition in machine learning and its implementation in MLJ

A graph-based protocol called `learning networks' which combine assorted...
research
12/01/2021

Trusted And Confidential Program Analysis

We develop the concept of Trusted and Confidential Program Analysis (TCP...
research
04/04/2020

Building secure distributed applications the DECENT way

Remote attestation (RA) enables distributed applications that deploy tru...
research
05/24/2017

SNMP for Common Lisp

Simple Network Management Protocol (SNMP) is widely used for management ...
research
08/13/2017

Monadic Remote Invocation

In order to achieve Separation of Concerns in the domain of remote metho...

Please sign up or login with your details

Forgot password? Click here to reset