Freeze and Crypt: Linux kernel support for main memory encryption. Issue 86 (September 2019)
- Record Type:
- Journal Article
- Title:
- Freeze and Crypt: Linux kernel support for main memory encryption. Issue 86 (September 2019)
- Main Title:
- Freeze and Crypt: Linux kernel support for main memory encryption
- Authors:
- Huber, Manuel
Horsch, Julian
Ali, Junaid
Wessel, Sascha - Abstract:
- Highlights: A generic concept for efficient main memory en- and decryption in OS kernels. The development of a prototype for main memory encryption for the Linux kernel. The integration of the prototype onto mobile devices running Android containers. The real-life application of the prototype on productively used smartphones. A thorough security and performance evaluation to demonstrate the practical usability. Abstract: We present Freeze & Crypt, a framework for main memory encryption. Our goal is to protect sensitive main memory on modern devices against memory attacks, such as via coldboot, DMA, or JTAG. This goal is of special significance when it comes to protect unattended or stolen devices, such as smartphones, tablets or laptops, against physical attackers. We describe the design of Freeze & Crypt for the Linux kernel where we build on a process suspension infrastructure called freezer. When suspended with the freezer, processes enter a state in kernel space rendering them unable to access any user space data. Instead of using the freezer for full system suspension, we extend it to make arbitrary process groups transparently and dynamically encrypt their full memory space while suspending. When resuming a process group, we make all contained processes decrypt their memory space before resuming normal execution. The encryption key needs to be present on the system only during en- and decryption, allowing for flexible key management specific to the use case. WeHighlights: A generic concept for efficient main memory en- and decryption in OS kernels. The development of a prototype for main memory encryption for the Linux kernel. The integration of the prototype onto mobile devices running Android containers. The real-life application of the prototype on productively used smartphones. A thorough security and performance evaluation to demonstrate the practical usability. Abstract: We present Freeze & Crypt, a framework for main memory encryption. Our goal is to protect sensitive main memory on modern devices against memory attacks, such as via coldboot, DMA, or JTAG. This goal is of special significance when it comes to protect unattended or stolen devices, such as smartphones, tablets or laptops, against physical attackers. We describe the design of Freeze & Crypt for the Linux kernel where we build on a process suspension infrastructure called freezer. When suspended with the freezer, processes enter a state in kernel space rendering them unable to access any user space data. Instead of using the freezer for full system suspension, we extend it to make arbitrary process groups transparently and dynamically encrypt their full memory space while suspending. When resuming a process group, we make all contained processes decrypt their memory space before resuming normal execution. The encryption key needs to be present on the system only during en- and decryption, allowing for flexible key management specific to the use case. We implement a prototype and apply it on productively used mobile devices running a virtualization platform. This platform allows for the concurrent operation of multiple Android containers on a single device. We use Freeze & Crypt to protect the sensitive data in RAM when the device or a container is not in active use. We create ephemeral keys for each container encryption cycle and protect the keys with a Secure Element while containers are encrypted. In our security and performance evaluations, we demonstrate Freeze & Crypt's practical usability on smartphones, efficiently protecting sensitive memory. … (more)
- Is Part Of:
- Computers & security. Issue 86(2019)
- Journal:
- Computers & security
- Issue:
- Issue 86(2019)
- Issue Display:
- Volume 86, Issue 86 (2019)
- Year:
- 2019
- Volume:
- 86
- Issue:
- 86
- Issue Sort Value:
- 2019-0086-0086-0000
- Page Start:
- 420
- Page End:
- 436
- Publication Date:
- 2019-09
- Subjects:
- Main memory encryption -- Mobile device security -- Process group encryption -- Data confidentiality -- Operating systems security
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2018.08.011 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16503.xml