Unternehmen jeder Größe und Einrichtungen des öffentlichen Sektors verlagern immer mehr Anwendungen von eigenen Rechenzentren in die Public Cloud. Hierbei rücken auch personenbezogene Daten und Anwendungen der kritischen Infrastruktur in den Fokus. Der Beitrag zeigt, ob und wie Confidential Computing die mit dieser besonderen Verarbeitungssituation verbundenen Risiken wirksam reduzieren kann.
We present CCF, a framework to build permissioned confidential blockchains. CCF provides a simple programming model of a highly-available data store and a universally-verifiable log that implements a ledger abstraction. CCF leverages trust in a consortium of governing members and in a network of replicated hardware-protected execution environments to achieve high throughput, low latency, strong integrity and strong confidentiality for application data and code executing on the ledger. CCF embeds consensus protocols with Byzantine and crash faulttolerant configurations. All configurations support strong service integrity based on the ledger contents. Even if some replicas are corrupt or their keys are compromised, they can be blamed based on their signed evidence of malicious activity recorded in the ledger. CCF supports transparent, programmable governance where the power of the consortium members is tunable and their activity is similarly recorded in the ledger for full auditability. We are developing an open-source implementation of CCF based on SGX-enabled Azure Confidential Compute, built on top of the Open Enclave SDK. Experimental results show that this implementation achieves throughput/latency tradeoffs up to 3 orders of magnitude better than previous confidential blockchain designs. Its code and documentation are available at https: //github.com/Microsoft/CCF.
The development of fast and precise measurement techniques for process analytical technology is important to operate chemical processes safely and efficiently. For quantitative measurements of multiple components at a trace level, often gas chromatographic methods are used which have a response time of several minutes or of up to one hour. For fast changing processes, this can be too slow for efficient control. For reducing the dead time of a control loop by increasing the measurement frequency, a multiplexing gas chromatography (mpGC) technique for a chromatographic system exhibiting a systematic non-linear response has been developed. For mpGC, superimposed chromatograms are measured by injecting consecutive samples before all components of previous samples have eluted from the column. The deconvolution of a superimposed chromatogram yields a computed chromatogram which is an average over the single chromatograms forming the superimposed chromatogram. Such a computed chromatogram typically shows so called correlation noise depending on the degree by which the single chromatograms forming the superimposed chromatogram will differ from each other (non-linear response). A technique is presented to calibrate the convolution matrix in order to suppress correlation noise introduced by systematic errors of the chromatographic system. The remaining correlation noise in the computed chromatogram is then exclusively caused by changing concentrations in the sample stream. For the method presented here, the sample is injected five times during the run time of a single chromatogram. The computed chromatogram is obtained three times within this timespan while representing each time an averaged chromatogram over the last five injections. Therefore, the sample throughput is increased by a factor of three compared to conventional GC.
Modern processors, e.g., Intel SGX, allow applications to isolate secret code and data in encrypted memory regions called enclaves. While encryption effectively hides the contents of memory, the sequence of address references issued by the secret code leaks information. This is a serious problem because these leaks can easily break the confidentiality guarantees of enclaves. In this paper, we explore Oblivious RAM (ORAM) designs that prevent these information leaks under the constraints of modern SGX processors. Most ORAMs are a poor fit for these processors because they have high constant overhead factors or require large private memories, which are not available in these processors. We address these limitations with a new hierarchical ORAM construction, the Pyramid ORAM, that is optimized towards online bandwidth cost and small blocks. It uses a new hashing scheme that circumvents the complexity of previous hierarchical schemes. We present an efficient x64-optimized implementation of Pyramid ORAM that uses only the processor's registers as private memory. We compare Pyramid ORAM with Circuit ORAM, a state-of-the-art tree-based ORAM scheme that also uses constant private memory. Pyramid ORAM has better online asymptotical complexity than Circuit ORAM. Our implementation of Pyramid ORAM and Circuit ORAM validates this: as all hierarchical schemes, Pyramid ORAM has high variance of access latencies; although latency can be high for some accesses, for typical configurations Pyramid ORAM provides access latencies that are 8X better than Circuit ORAM for 99% of accesses. Although the best known hierarchical ORAM has better asymptotical complexity, Pyramid ORAM has significantly lower constant overhead factors, making it the preferred choice in practice.
A multi-party privacy-preserving machine learning system is described which has a trusted execution environment comprising at least one protected memory region. An code loader at the system loads machine learning code, received from at least one of the parties, into the protected memory region. A data uploader uploads confidential data, received from at least one of the parties, to the protected memory region. The trusted execution environment executes the machine learning code using at least one data-oblivious procedure to process the confidential data and returns the result to at least one of the parties, where a data-oblivious procedure is a process where any patterns of memory accesses, patterns of disk accesses and patterns of network accesses are such that the confidential data cannot be predicted from the patterns.
La presente invention concerne un systeme d'apprentissage automatique de respect de la vie privee de plusieurs parties qui presente un environnement d'execution de confiance comprenant au moins une region de memoire protegee. Un chargeur de code au niveau du systeme charge le code d'apprentissage automatique, recu en provenance d'au moins une des parties, dans la region de memoire protegee. Un dispositif de telechargement de donnees telecharge des donnees confidentielles, recues en provenance d'au moins une des parties, vers la region de memoire protegee. L'environnement d'execution de confiance execute le code d'apprentissage automatique a l'aide d'au moins une procedure insensible aux donnees permettant de traiter les donnees confidentielles et renvoie le resultat a au moins l'une des parties, une procedure insensible aux donnees etant un processus dans lequel un modele d'acces a la memoire, un modele d'acces au disque, un modele d'acces au reseau est tel que les donnees confidentielles ne peuvent pas etre predites a partir des modeles.
Cache-based side-channel attacks are a serious problem in multi-tenant environments, for example, modern cloud data centers. We address this problem with Cloak, a new technique that uses hardware transactional memory to prevent adversarial observation of cache misses on sensitive code and data. We show that Cloak provides strong protection against all known cache-based side-channel attacks with low performance overhead. We demonstrate the efficacy of our approach by retrofitting vulnerable code with Cloak and experimentally confirming immunity against state-of-the-art attacks. We also show that by applying Cloak to code running inside Intel SGX enclaves we can effectively block information leakage through cache side channels from enclaves, thus addressing one of the main weaknesses of SGX.
The lower layers in the modern computing infrastructure are written in languages threatened by exploitation of memory management errors. Recently deployed exploit mitigations such as control-flow integrity (CFI) can prevent traditional return-oriented programming (ROP) exploits but are much less effective against newer techniques such as Counterfeit Object-Oriented Programming (COOP) that execute a chain of C++ virtual methods. Since these methods are valid control-flow targets, COOP attacks are hard to distinguish from benign computations. Code randomization is likewise ineffective against COOP. Until now, however, COOP attacks have been limited to vulnerable C++ applications which makes it unclear whether COOP is as general and portable a threat as ROP. This paper demonstrates the first COOP-style exploit for Objective-C, the predominant programming language on Apple's OS X and iOS platforms. We also retrofit the Objective-C runtime with the first practical and efficient defense against our novel attack. Our defense is able to protect complex, real-world software such as iTunes without recompilation. Our performance experiments show that the overhead of our defense is low in practice.
The human mandible is said to arise from desmal ossification, which, however, is not true for the entire body of the mandible: Meckel’s cartilage itself is prone to ossification, at least its anterior part in the canine and incisor region. Also, within the coronoid and in the condylar processes there are cartilaginous cores, which eventually undergo ossification. Furthermore, there are a number of additional single cartilaginous islets arising in fetuses of 95 mm CRL and more. They are located predominantly within the bone at the buccal sides of the brims of the dental compartments, mostly in the gussets between the dental primordia. They become wedge-shaped or elongated with a diameter of around 150–500 μm and were also found in older stages up to 225 mm CRL, which was the oldest specimen used in this study. This report is intended to visualize these single cartilaginous islets histologically and in 3-D reconstructions in stereoscopic images. Although some singular cartilaginous tissue within the mandible may be remains of the decaying Meckel’s cartilage, our 3-D reconstructions clearly show that the aforementioned cartilaginous islets are independent thereof, as can be derived from their separate locations within the mandibular bone. The reasons that lead to these cartilaginous formations have remained unknown so far.
Privacy-preserving multi-party machine learning allows multiple organizations to perform collaborative data analytics while guaranteeing the privacy of their individual datasets. Using trusted SGX-processors for this task yields high performance, but requires a careful selection, adaptation, and implementation of machine-learning algorithms to provably prevent the exploitation of any side channels induced by data-dependent access patterns. We propose data-oblivious machine learning algorithms for support vector machines, matrix factorization, neural networks, decision trees, and k-means clustering. We show that our efficient implementation based on Intel Skylake processors scales up to large, realistic datasets, with overheads several orders of magnitude lower than with previous approaches based on advanced cryptographic multi-party computation schemes.
Code-reuse attacks continue to evolve and remain a severe threat to modern software. Recent research has proposed a variety of defenses with differing security, efficiency, and practicality characteristics. Whereas the majority of these solutions focus on specific code-reuse attack variants such as return-oriented programming (ROP), other attack variants that reuse whole functions, such as the classic return-into-libc, have received much less attention. Mitigating function-level code reuse is highly challenging because one needs to distinguish a legitimate call to a function from an illegitimate one. In fact, the recent counterfeit object-oriented programming (COOP) attack demonstrated that the majority of code-reuse defenses can be bypassed by reusing dynamically bound functions, i.e., functions that are accessed through global offset tables and virtual function tables, respectively. In this paper, we first significantly improve and simplify the COOP attack. Based on a strong adversarial model, we then present the design and implementation of a comprehensive code-reuse defense which is resilient against reuse of dynamically-bound functions. In particular, we introduce two novel defense techniques: (i) a practical technique to randomize the layout of tables containing code pointers resilient to memory disclosure and (ii) booby trap insertion to mitigate the threat of brute-force attacks iterating over the randomized tables. Booby traps serve the dual purpose of preventing fault-analysis side channels and ensuring that each table has sufficiently many possible permutations. Our detailed evaluation demonstrates that our approach is secure, effective, and practical. We prevent realistic, COOP-style attacks against the Chromium web browser and report an average overhead of 1.1% on the SPEC CPU2006 benchmarks.
Code reuse attacks such as return-oriented programming (ROP) have become prevalent techniques to exploit memory corruption vulnerabilities in software programs. A variety of corresponding defenses has been proposed, of which some have already been successfully bypassed -- and the arms race continues. In this paper, we perform a systematic assessment of recently proposed CFI solutions and other defenses against code reuse attacks in the context of C++. We demonstrate that many of these defenses that do not consider object-oriented C++ semantics precisely can be generically bypassed in practice. Our novel attack technique, denoted as counterfeit object-oriented programming (COOP), induces malicious program behavior by only invoking chains of existing C++ virtual functions in a program through corresponding existing call sites. COOP is Turing complete in realistic attack scenarios and we show its viability by developing sophisticated, real-world exploits for Internet Explorer 10 on Windows and Fire fox 36 on Linux. Moreover, we show that even recently proposed defenses (CPS, T-VIP, vfGuard, and VTint) that specifically target C++ are vulnerable to COOP. We observe that constructing defenses resilient to COOP that do not require access to source code seems to be challenging. We believe that our investigation and results are helpful contributions to the design and implementation of future defenses against control flow hijacking attacks.
We present VC3, the first system that allows users to run distributed MapReduce computations in the cloud while keeping their code and data secret, and ensuring the correctness and completeness of their results. VC3 runs on unmodified Hadoop, but crucially keeps Hadoop, the operating system and the hyper visor out of the TCB, thus, confidentiality and integrity are preserved even if these large components are compromised. VC3 relies on SGX processors to isolate memory regions on individual computers, and to deploy new protocols that secure distributed MapReduce computations. VC3 optionally enforces region self-integrity invariants for all MapReduce code running within isolated regions, to prevent attacks due to unsafe memory reads and writes. Experimental results on common benchmarks show that VC3 performs well compared with unprotected Hadoop: VC3's average runtime overhead is negligible for its base security guarantees, 4.5% with write integrity and 8% with read/write integrity.
Bjorn De Sutter合作论文数Electronics and Information Systems Department2