See this document in CiteSeerX!

Secure Bootstrap is Not Enough: Shoring up the Trusted Computing Base  (Make Corrections)  
James Hendricks Carnegie Mellon University 5000 Forbes Ave Pittsburgh, PA...



  Home/Search   Context   Related

 
View or download:
cmu.edu/PDLFTP/st...ps04bootstrap.pdf
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  cmu.edu/Publications/pubsdate (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: We propose augmenting secure boot with a mechanism to protect against compromises to field-upgradeable devices. In particular, secure boot standards should verify the firmware of all devices in the computer, not just devices that are accessible by the host CPU. Modern computers contain many autonomous processing elements, such as disk controllers, disks, network adapters, and coprocessors, that all have field-upgradeable firmware and are an essential component of the computer system's trust... (Update)

Active bibliography (related documents):   More   All
0.5:   Trusted Computing: Providing Security for Peer-to-Peer Networks - Shane Balfe Amit (2005)   (Correct)
0.2:   Code Inection in C and CPP: A Survey of Vulnerabilities.. - Younan, Joosen, Piessens (2004)   (Correct)
0.2:   An Overview of Common Programming Security Vulnerabilities and.. - Younan (2003)   (Correct)

Similar documents based on text:   More   All
0.2:   Web Accessibility: A Broader View - Richards, Hanson (2004)   (Correct)
0.1:   Using Software-based Attestation for Verifying.. - Seshadri, Perrig..   (Correct)
0.1:   Diamond High Assurance Security Program: Trusted Computing.. - Irvine, Levin, Dinolt (2002)   (Correct)

BibTeX entry:   (Update)

@misc{ carnegie-secure,
  author = "James Hendricks Carnegie",
  title = "Secure Bootstrap is Not Enough: Shoring up the Trusted Computing Base",
  url = "citeseer.ist.psu.edu/694655.html" }
Citations (may not include all citations):
63   A secure and reliable bootstrap architecture - Arbaugh, Farber et al. - 1997
29   Aegis: Architecture for tamper-evident and tamperresistant p.. - Suh, Clarke et al. - 2003
24   Metadata efficiency in versioning file systems - Soules, Goodson et al. - 2003
14   Design and implementation of a TCG-based integrity measureme.. (context) - Sailer, Zhang et al. - 2004
11   Security Requirements for Cryptographic Modules (context) - Institute, Standards - 1994
9   EMpowering side-channel attacks - Rao, Rohatgi - 2001
6   A trusted open platform (context) - England, Lampson et al. - 2003
4   Defeating solar designer's non-executable stack patch (context) - Wojtczuk - 1998
2   TPM Main: Part 1 Design Principles (context) - Computing - 2003
1   Warner attempts to out-hack DVD hackers (context) - Smith - 2000
1   TCG PC Specific Implementation Specification (context) - Gomputing - 2003
1   Chips to crack Xbox released on internet (context) - Davidson - 2003
1   Architectural support for copy and tamper resistant software (context) - Thekkath, Mitchell et al. - 2000
http://www.myrinet.com
http://www.arm.com/markets/armpp/462.html
http://www.linuxbios.org
http://www.trustedcomputinggroup.org

Documents on the same site (http://www.pdl.cmu.edu/Publications/pubs-date.html):   More
Capturing the Spatio-Temporal Behavior of Real Traffic Data - Wang, Ailamaki, Faloutsos (2002)   (Correct)
Design and Implementation of a Self-Securing Storage.. - Strunk, Goodson.. (2000)   (Correct)
Automatic Compiler-Inserted I/O Prefetching for.. - Mowry, Demke, Krieger (1996)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC