Online Proposers Day TWO DIFFERENT PROJECT IDEA CONTRIBUTIONS - - PowerPoint PPT Presentation

online proposers day
SMART_READER_LITE
LIVE PREVIEW

Online Proposers Day TWO DIFFERENT PROJECT IDEA CONTRIBUTIONS - - PowerPoint PPT Presentation

CELTIC-NEXT Online Proposers Day TWO DIFFERENT PROJECT IDEA CONTRIBUTIONS SYSTEMIC SW Universal Trusted PROTECTION Execution for cloud and endpoint SW for cloud and endpoint SW security enhancement total security SOLIDSHIELD


slide-1
SLIDE 1

SYSTEMIC SW PROTECTION

for cloud and endpoint SW security enhancement

CELTIC-NEXT Online Proposers Day

TWO DIFFERENT PROJECT IDEA CONTRIBUTIONS

SOLIDSHIELD vincent@solidshield.com

Universal Trusted Execution

for cloud and endpoint SW total security

slide-2
SLIDE 2

Project CONTRIBUTION proposal

SYSTEMIC SW PROTECTION

for cloud and endpoint SW security enhancement

CELTIC-NEXT Online Proposers Day

29th November 2018, via WebEx

SOLIDSHIELD vincent@solidshield.com

slide-3
SLIDE 3

PROBLEM STATEMENT

SOFTWARE SECURITY IS FIRST PRIORITY FOR FUTURE IOT BASED SYSTEM SECURITY TODAY 'S PAINPOINTS FOR SW PROTECTION):

  • IMPEDING ATTACKS SLOW DOWN THE SOFTWARE
  • COMPLEX WORKFLOW (SOURCE CODE CHANGE, NEW COMPILATION, ...

www.celticplus.eu SYSTEMIC SW ONE CLICK SECURITY, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

IOT SoTA SOFTWARE ARE AT THE BEST AUTHENTICATED CAN BE REVERSED CAN BE DECOMPILED CAN BE TAMPERED TO TAMPER DATA

slide-4
SLIDE 4

SYSTEMIC

www.celticplus.eu SYSTEMIC SW ONE CLICK SECURITY, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

SYSTEMIC SW PROTECTIONS: ATTESTATION ENCRYPTION ANTI DUMP ANTI TAMPERING ALL THESE FOUR PROTECTION SET AT ONE CLICK COST ON BINARIES NO PERFORMANCE DEGRADATION AT RUNTIME UNIVERSAL SOLUTION

slide-5
SLIDE 5

ORGANISATION PROFILE

5

SOLIDSHIELD WORKS IN SW PROTECTION FOR A DECADE (DEFENSE AND TELECOM) SYSTEMIC (FOR INTEL) IS DERIVED FROM OUR CONTRIBUTION IN SENDATE TANDEM. WORKFLOW IS KEY FOR SUCCESS. WE NEED USE CASES AND MARKET INNER VIEWS OUR PLAN IS TO EXPAND SYSTEMIC TO IOT MARKETS (ARM, JAVA) AND DESIGN AD HOC SOLUTIONS TO MEET SPECIFIC MARKETS CONSTRAINTS. SPECIFICATIONS SHALL COME FROM POTENTIAL USERS. (CONSORTIUM MEMBERS TYPICALLY). TESTS SHALL BE DONE BY THEM TOO.

www.celticplus.eu SYSTEMIC SW ONE CLICK SECURITY, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

slide-6
SLIDE 6

Pitch of a project contribution proposal

Universal Trusted Execution

for cloud and endpoint SW total security

CELTIC-NEXT Online Proposers Day

29th November 2018, via WebEx

SOLIDSHIELD vincent@solidshield.com

slide-7
SLIDE 7

TEASER ONE SOLUTION FOR ALL TEE

7

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

UNIVERSAL TRUSTED EXECUTION DELIVERS HIGHEST SW SECURITY WHATEVER HARDWARE (TEE ENABLED) AT NO EFFORT TO DEVELOPERS

slide-8
SLIDE 8

PROBLEM STATEMENT

8

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

TEE IS A SUPER STRONG BUT POORLY-USED IDEA PROS: IT BREAKS THE CHAIN OF PERFORMANCE<>EFFICIENCY PRO: CODE AND DATA INTEGRITY AND CONFIDIENTIALITY ARE MET CONS: REQUIRE A SECURITY ARCHITECT... VENDOR-SPECIFIC , NO COMPATIBILITY

Limited TCB Complete VM

slide-9
SLIDE 9

UNIV IVERSAL TEE

9

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

ONE SETUP WORKFLOW FOR BOTH TECHNOLOGIES NO CHANGE ON SOURCE CODE REQUIRED ONE SINGLE PROTECTED EXECUTABLE ENABLED FOR BOTH TECHNOLOGIES NO EFFORT FROM DEVELOPER. USE CODE INTERPRETATION AND ASYLO APIS FOR HARDWARE INDEPENDANCE + AUTOMATIC BINARY WRAPPING

slide-10
SLIDE 10

UNIV IVERSAL TEE OUTCOME

10

CLOUD COMPUTING MAKES USE OF TEE... NO MORE INTROSPECTION ATTACKS AT SERVER FARMS... A REAL BOOSTER IN TODAY'S CLOUD COMPUTING USE (5G, SDN, ...) WE OFFER A READY-TO-USE DISRUPTIVE SOLUTION ON BOTH WORKFLOW AND DEPLOYMENT ASPECTS (TODAY'S BLOCKER)

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

"TEE ARE NESCANT AND WILL EVOLVE ATTACKS ON TEES JUST REFLECT HOW MUCH THEY THREAT CYBER ACTIVISTS..."

slide-11
SLIDE 11

FAU 'S 'S EXPERTISE

11

FAU takes part of a long track of collaborative research program including SENDATE

  • TANDEM. Its research focus are trusted execution environments, including the following

publications:

  • Isolating Operating System Components with Intel SGX, SysTex ’16
  • Hardware-Based Trusted Computing Architectures for Isolation and Attestation, IEEE

Transactions on Computers ’17

  • Cache Attacks on Intel SGX, EuroSec ‘17
  • Secure Remote Computation using Intel SGX, GI Sicherheit ’18
  • Universal TEE for Securing SDN/NFV Operations, ARES ‘18
  • TEEshift: Protecting Code Confidentiality by Selectively Shifting Functions into TEEs,

SysTex ‘18

  • Protecting Regular User-Mode Processes with AMD SEV (to be published 2019)

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

slide-12
SLIDE 12

12

PUBLICATIONS REFLECTING THE CONTRIBUTION IDEA: ARES ‘18 CONFERENCE, HAMBOURG, AUGUST 2018: UNIVERSAL TEE FOR SECURING SDN/NFV OPERATIONS HTTPS://DL.ACM.ORG/CITATION.CFM?DOID=3230833.3233256 SYSTEX ‘18 WORKSHOP, CO-LOCATED TO CCS CONFERENCE, TORONTO, OCTOBER 2018: TEESHIFT: PROTECTING CODE BY SELECTIVELY SELECTING FUNCTIONS INTO TEES (BEST-PAPER AWARD ) HTTPS://WWW.RESEARCHGATE.NET/PUBLICATION/328326614_TEESHIFT_PROTE CTING_CODE_CONFIDENTIALITY_BY_SELECTIVELY_SHIFTING_FUNCTIONS_INT O_TEES

www.celticplus.eu Universal Trusted Execution Environment, Vincent Lefebvre, SOLIDSHIELD, vincent@solidshield.com

slide-13
SLIDE 13

CONTACT IN INFO

13

SOLIDSHIELD:

Name: Vincent Lefebvre E-Mail: vincent@solidshield.com Telephone +33 0663579190 83 Bd Sadi Carnot, 06110 Le Cannet, France www.solidshield.com

Presentation available via:

www.tiny.cc/projectidea

FAU:

Name: Tilo Müller E-Mail: tilo.mueller@cs.fau.de Telephone +49 9131 85 69904

  • Martensstr. 3, 91058 Erlangen, Germany

www1.cs.fau.de

slide-14
SLIDE 14

Join the follow-up Telco

14

www.celticplus.eu office@celticplus.eu

Join Webex meeting Meeting number (access code): 956 667 108 Meeting password: Z5jiAfeH Join by phone +49-6925511-4400 Germany toll Global call-in numbers

7th December 14-15 CET