ABSTRACT

    Proceedings of the Eleventh SIGOPS European Workshop, ACM SIGOPS, Leuven, Belgium, September 2004.

    Secure Bootstrap is Not Enough: Shoring up the Trusted Computing Base

    James Hendricks, Leendert van Doorn*

    Dept. Electrical and Computer Engineering
    Carnegie Mellon University

    *IBM T.J. Watson Research Center

    http:\\www..pdl.cmu.edu

    We propose augmenting secure boot with a mechanism to protect against compromises to field-upgradeable devices. In particular, secure boot standards should verify the firmware of all devices in the computer, not just devices that are accessible by the host CPU. Modern computers contain many autonomous processing elements, such as disk controllers, disks, network adapters, and coprocessors, that all have field-upgradeable firmware and are an essential component of the computer system’s trust model. Ignoring these devices opens the system to attacks similar to those secure boot was engineered to defeat.

    FULL PAPER: pdf


    PDL Home Publications Home

    © 2008.
    Last updated 10 November, 2004