Advanced Search
CS Search Google Search
Subscribers, please login

Published Articles >> Table of Contents >> Abstract

Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007)   pp. 19-29
Establishing and Sustaining System Integrity via Root of Trust Installation

Full Article Text: Download PDF of full textBuy this article

DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ACSAC.2007.25
Send link to a friend

Abstract
Integrity measurements provide a means by which dis- tributed systems can assess the trustability of potentially compromised remote hosts. However, current measurement techniques simply assert the identity of software, but pro- vide no indication of the ongoing status of the system or its data. As a result, a number of significant vulnerabilities can result if the system is not configured and managed care- fully. To improve the management of a system's integrity, we propose a Root of Trust Installation (ROTI) as a foun- dation for high integrity systems. A ROTI is a trusted sys- tem installer that also asserts the integrity of the trusted computing base software and data that it installs to en- able straightforward, comprehensive integrity verification for a system. The ROTI addresses a historically limiting problem in integrity measurement: determining what con- stitutes a trusted system state in a heterogeneous, evolv- ing environment. Using the ROTI, a high integrity system state is defined by its installer, thus enabling a remote party to verify integrity guarantees that approximate classical in- tegrity models (e.g., Biba). In this paper, we examine what is necessary to prove the integrity of the trusted computing base (sCore) of a distributed security architecture, called the Shamon. We describe the design and implementation of our custom ROTI sCore installer and study the costs and ef- fectiveness of binding system integrity to installation in the distributed Shamon. This demonstration shows that strong integrity guarantees can be efficiently achieved in large, di- verse environments with limited administrative overhead.
Additional Information

Citation:  Luke St. Clair, Joshua Schiffman, Trent Jaeger, Patrick McDaniel, "Establishing and Sustaining System Integrity via Root of Trust Installation," acsac, pp. 19-29,  Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007),  2007

Similar Articles

Abstract Contents
Abstract
Citation




Free access to

  • Abstracts
  • Selected PDFs

Electronic subscribers login to:

  • Access HTML/PDFs of full text articles

Subscription information

Get a Web account

Peer Review Notice

Give us Feedback