Hardware Mechanisms for Memory Integrity Checking
Name
MIT-LCS-TR-872.pdf
Size
334.95 KB
Format
Adobe PDF
Checksum (MD5)
5c43f0b412d975cf10935b4d32323bf7
Author(s) • • • •
Suh, G. Edward
Clarke, Dwaine
Gassend, Blaise
van Dijk, Marten
Devadas, Srinivas
Date Issued
November 2002
Series/Report no.
MIT-LCS-TR-872
Abstract
Memory integrity verification is a useful primitive when implementing secure processors that are resistant to attacks on hardware components. This paper proposes new hardware schemes to verify the integrity of untrusted external memory using a very small amount of trusted on-chip storage. Our schemes maintain incremental multiset hashes of all memory reads and writes at run-time, and can verify a {\\em sequence} of memory operations at a later time. We study the advantages and disadvantages of the two new schemes and two existing integrity checking schemes, MACs and hash trees, when implemented in hardware in a microprocessor. Simulations show that the new schemes outperform existing schemes of equivalent functionality when integrity verification is infrequent.
Persistent DSpace Link