Searcharxiv⌕ Search

arXiv subjects

Guerney D. H. Hunt

Publications and source records attributed to Guerney D. H. Hunt.

3 recordsLinked to original sources

ACE: Towards A High-Assurance Isolated Virtualization Environment for RISC-V

Confidential computing has proven its value in cloud environments, but its potential for securing edge and high-end embedded systems (e.g., automotive controllers, cryptographic accelerators, telco infrastructure) remains largely unexplored. We present ACE, an open-source, royalty-free virtualization-based confidential computing system for RISC-V targeting these environments. ACE isolates software into confidential virtual machines with narrow, well-defined interfaces, building exclusively on commodity RISC-V hardware without specialized hardware extensions or licensing fees. Our prototype evaluation on the first commercially available RISC-V hardware supporting virtualization shows that ACE is a viable candidate for our target systems.

cs.CR↗

Automatic ISA analysis for Secure Context Switching

Instruction set architectures are complex, with hundreds of registers and instructions that can modify dozens of them during execution, variably on each instance. Prose-style ISA specifications struggle to capture these intricacies of the ISAs, where often the important details about a single register are spread out across hundreds of pages of documentation. Ensuring that all ISA-state is swapped in context switch implementations of privileged software requires meticulous examination of these pages. This manual process is tedious and error-prone. We propose a tool called Sailor that leverages machine-readable ISA specifications written in Sail to automate this task. Sailor determines the ISA-state necessary to swap during the context switch using the data collected from Sail and a novel algorithm to classify ISA-state as security-sensitive. Using Sailor's output, we identify three different classes of mishandled ISA-state across four open-source confidential computing systems. We further reveal five distinct security vulnerabilities that can be exploited using the mishandled ISA-state. This research exposes an often overlooked attack surface that stems from mishandled ISA-state, enabling unprivileged adversaries to exploit system vulnerabilities.

cs.OS↗

Towards a Formally Verified Security Monitor for VM-based Confidential Computing

Confidential computing is a key technology for isolating high-assurance applications from the large amounts of untrusted code typical in modern systems. Existing confidential computing systems cannot be certified for use in critical applications, like systems controlling critical infrastructure, hardware security modules, or aircraft, as they lack formal verification. This paper presents an approach to formally modeling and proving a security monitor. It introduces a canonical architecture for virtual machine (VM)-based confidential computing systems. It abstracts processor-specific components and identifies a minimal set of hardware primitives required by a trusted security monitor to enforce security guarantees. We demonstrate our methodology and proposed approach with an example from our Rust implementation of the security monitor for RISC-V.

cs.CR↗