• Documents
  • Authors
  • Tables
  • Other Seers ▼
    RefSeer AckSeer CollabSeer SeerSeer
  • Log in
  • Sign up
  • MetaCart

CiteSeerX logo

Advanced Search Include Citations
Advanced Search Include Citations | Disambiguate

Terra: a virtual machine-based platform for trusted computing (2003)

Cached

  • Download as a PDF

Download Links

  • [www.cis.upenn.edu]
  • [cs.unomaha.edu]
  • [flint.cs.yale.edu]
  • [www.stanford.edu]
  • [www.cs.rochester.edu]
  • [www.cs.princeton.edu]
  • [suif.stanford.edu]
  • [www.stanford.edu]
  • [www.eecg.toronto.edu]
  • [www.cs.cmu.edu]
  • [www.cs.binghamton.edu]
  • [www.cs.cmu.edu]
  • [www.stanford.edu]

  • Other Repositories/Bibliography

  • DBLP
  • Save to List
  • Add to Collection
  • Correct Errors
  • Monitor Changes
by Tal Garfinkel , Ben Pfaff , Jim Chow , Mendel Rosenblum , Dan Boneh
Citations:257 - 6 self
  • Summary
  • Active Bibliography
  • Co-citation
  • Clustered Documents
  • Version History

BibTeX

@INPROCEEDINGS{Garfinkel03terra:a,
    author = {Tal Garfinkel and Ben Pfaff and Jim Chow and Mendel Rosenblum and Dan Boneh},
    title = {Terra: a virtual machine-based platform for trusted computing},
    booktitle = {},
    year = {2003},
    pages = {193--206},
    publisher = {ACM Press}
}

Years of Citing Articles

Bookmark

citeulike Connotea Bibsonomy Del.icio.us Digg Reddit

OpenURL

 

Abstract

We present a flexible architecture for trusted computing, called Terra, that allows applications with a wide range of security requirements to run simultaneously on commodity hardware. Applications on Terra enjoy the semantics of running on a separate, dedicated, tamper-resistant hardware platform, while retaining the ability to run side-by-side with normal applications on a generalpurpose computing platform. Terra achieves this synthesis by use of a trusted virtual machine monitor (TVMM) that partitions a tamper-resistant hardware platform into multiple, isolated virtual machines (VM), providing the appearance of multiple boxes on a single, general-purpose platform. To each VM, the TVMM provides the semantics of either an “open box, ” i.e. a general-purpose hardware platform like today’s PCs and workstations, or a “closed box, ” an opaque special-purpose platform that protects the privacy and integrity of its contents like today’s game consoles and cellular phones. The software stack in each VM can be tailored from the hardware interface up to meet the security requirements of its application(s). The hardware and TVMM can act as a trusted party to allow closed-box VMs to cryptographically identify the software they run, i.e. what is in the box, to remote parties. We explore the strengths and limitations of this architecture by describing our prototype implementation and several applications that we developed for it.

Citations

561 Exokernel: An operating system architecture for application-level resource management - Engler, Kaashoek, et al. - 1995
432 Group Signatures - Chaum, Heijst - 1991
403 Authentication in distributed systems: Theory and practice - Lampson, Abadi, et al. - 1992
392 safety and performance in the SPIN operating system - BERSHAD, SAVAGE, et al. - 1995
309 On µ-kernel construction - Liedtke - 1995
277 ReVirt: Enabling Intrusion Analysis through Virtual-Machine Logging and Replay - Dunlap, King, et al. - 2002
233 Protocols for public key cryptosystems - Merkle - 1980
232 Memory resource management in VMware ESX server - WALDSPURGER
209 A Secure and Reliable Bootstrap Architecture - Arbaugh, Farber, et al. - 1997
209 A practical and provably secure coalition-resistant group signature scheme - Ateniese, Camenisch, et al. - 2000
202 Integrating Flexible Support for Security Policies into the Linux Operating System - LOSCOCCO, SMALLEY
199 An Empirical Study of Operating Systems Errors - Chou, Yang, et al. - 2001
198 A virtual machine introspection based architecture for intrusion detection - Garfinkel, Rosenblum - 2003
196 Scale and performance in the Denali isolation kernel - Whitaker, Shaw, et al. - 2002
192 Improving the Reliability of Commodity Operating Systems - Swift, Bershad, et al. - 2003
182 Survey of Virtual Machine Research - Goldberg - 1974
180 Architectural Support for Copy and Tamper Resistant Software - Lie, Thekkath, et al. - 2000
172 Virtualizing I/O Devices on VMware Workstation’s Hosted Virtual Machine Monitor - Sugerman, Venkitachalam, et al.
164 Disco: running commodity operating systems on scalable multiprocessors - Bugnion, Devine, et al. - 1997
163 Authentication in the Taos operating system - Wobber, Abadi, et al. - 1994
151 EROS: A fast capability system - Shapiro, Smith, et al.
139 Using programmer-written compiler extensions to catch security holes - Ashcraft, Engler - 2002
97 When virtual is better than real - Chen, Noble - 2001
88 The origin of the VM/370 time-sharing system - Creasy - 1981
81 The Digital distributed system security architecture - Gasser, Goldstein, et al. - 1989
78 Dyad: A System for Using Physically Secure Coprocessors - Tygar, Yee - 1991
69 The Inevitability of Failure: The flawed assumption of security in modern computing environments - LOSCOCCO, SMALLEY, et al. - 1998
64 A trusted open platform - England, Lampson, et al. - 2003
57 Secure coprocessors in electronic commerce applications - Yee, Tygar - 1995
50 Building the IBM 4758 Secure Coprocessor - Dyer, Lindemann, et al.
49 A retrospective on the VAX VMM security kernel - KARGER, ZURKO, et al. - 1991
48 Outbound Authentication for Programmable Secure Coprocessors - Smith - 2004
43 Tamper resistance-a cautionary note - Anderson, Kuhn - 1996
41 Architectural Principles for Virtual Computer Systems - Goldberg - 1972
36 Cryptography and Competition Policy - Issues with ‘Trusted Computing - Anderson - 2004
29 Nettop: Commercial technology in high assurance applications. VMware Tech Trend Notes - Meushaw, Simard
21 al “Mach: a new kernel foundation for Unix development - Accetta, et - 1986
19 Microsoft “Palladium”: A Business Overview - Carroll, Juarez, et al. - 2002
17 A security retrofit of VM/370 - Gold - 1979
17 Authenticated operation of open computing devices - England, Peinado - 2002
16 Practical Server Privacy with Secure Coprocessors - Smith, Safford
15 Program confinement in KVM/370 - Schaefer, Gold, et al. - 1977
14 A flexible and secure auction architecture using trusted hardware - SAM - 1991
13 G.: Towards untrusted device drivers - Leslie, Heiser - 2003
11 KVM/370 in retrospect - Gold, Linde, et al. - 1984
6 Message authentication using Hash Functions-The HMAC - Bellare, Krawczyk
6 Hierarchical approach to computer system integrity - Donovan, Madnick - 1975
5 Prototyping an armored data vault: Rights management on big brother’s computer - Iliev, Smith - 2003
5 Security kernels: A solution or a problem - Ames - 1981
5 Trusted computer systems - Tasker - 1981
The National Science Foundation
  • About CiteSeerX
  • Submit Documents
  • Privacy Policy
  • Help
  • Data
  • Source
  • Contact Us

Developed at and hosted by The College of Information Sciences and Technology

© 2007-2010 The Pennsylvania State University