Supporting Heterogeneous TEE for Critical Infrastructure Protection

DOI arXiv PDF
BibTeX Citation
@inproceedings{karanjai2023decentralized,
  title={Decentralized translator of trust: Supporting heterogeneous tee for critical infrastructure protection},
  author={Karanjai, Rabimba and Collier, Rowan and Gao, Zhimin and Chen, Lin and Fan, Xinxin and Suh, Taeweon and Shi, Weidong and Xu, Lei},
  booktitle={Proceedings of the 5th ACM International Symposium on Blockchain and Secure Critical Infrastructure},
  pages={85--94},
  year={2023}
}
Copied to clipboard
Read Paper Download PDF

Abstract

Trusted execution environment (TEE) technology has found many applications in mitigating various security risks in an efficient manner, which is attractive for critical infrastructure protection. First, the natural of critical infrastructure requires it to be well protected from various cyber attacks. Second, performance is usually important for critical infrastructure and it cannot afford an expensive protection mechanism. While a large number of TEE-based critical infrastructure protection systems have been proposed to address various security challenges (e.g., secure sensing and reliable control), most existing works ignore one important feature, i.e., devices comprised the critical infrastructure may be equipped with multiple incompatible TEE technologies and belongs to different owners. This feature makes it hard for these devices to establish mutual trust and form a unified TEE environment. To address these challenges and fully unleash the potential of TEE technology for critical infrastructure protection, we propose DHTee, a decentralized coordination mechanism. DHTee uses blockchain technology to support key TEE functions in a heterogeneous TEE environment, especially the attestation service. A Device equipped with one TEE can interact securely with the blockchain to verify whether another potential collaborating device claiming to have a different TEE meets the security requirements. DHTee is also flexible and can support new TEE schemes without affecting devices using existing TEEs that have been supported by the system.

Type Conference Paper
Venue ACM AsiaCCS 2023
Date May 2023
Citations 12
Security TEE Hardware Security First Author