Integrating Remote Attestation with Transport Layer Security
arXiv:1801.05863
Abstract
Intel(R) Software Guard Extensions (Intel(R) SGX) is a promising technology to securely process information in otherwise untrusted environments. An important aspect of Intel SGX is the ability to perform remote attestation to assess the endpoint's trustworthiness. Ultimately, remote attestation will result in an attested secure channel to provision secrets to the enclave. We seamlessly combine Intel SGX remote attestation with the establishment of a standard Transport Layer Security (TLS) connection. Remote attestation is performed during the connection setup. To achieve this, we neither change the TLS protocol, nor do we modify existing protocol implementations. We have prototype implementations for three widely used open-source TLS libraries: OpenSSL, wolfSSL and mbedTLS. We describe the requirements, design and implementation details to seamlessly bind attested TLS endpoints to Intel SGX enclaves.
Cited by in corpus (13)
- PPFL: Privacy-preserving Federated Learning with Trusted Execution Environments
- Privado: Practical and Secure DNN Inference with Enclaves
- Securing the Storage Data Path with SGX Enclaves
- MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties
- PDoT: Private DNS-over-TLS with TEE Support
- Perun: Secure Multi-Stakeholder Machine Learning Framework with GPU Support
- Building and Maintaining a Third-Party Library Supply Chain for Productive and Secure SGX Enclave Development
- Privacy-Preserving Machine Learning in Untrusted Clouds Made Simple
- It Takes Two to #MeToo - Using Enclaves to Build Autonomous Trusted Systems
- Building secure distributed applications the DECENT way
- HTTPA: HTTPS Attestable Protocol
- WELES: Policy-driven Runtime Integrity Enforcement of Virtual Machines
- P2FAAS: Toward Privacy-Preserving Fuzzing as a Service