Publication:
Secure enclave for TLS web server on untrusted environment

dc.contributor.authorChiraphat Chaipheten_US
dc.contributor.authorSudsanguan Ngamsuriyarojen_US
dc.contributor.authorAhmed Awaden_US
dc.contributor.authorBetran Jacoben_US
dc.contributor.authorLoannis Gakosen_US
dc.contributor.authorWiktor Grajkowskien_US
dc.contributor.otherMahidol Universityen_US
dc.contributor.otherUCLen_US
dc.date.accessioned2018-12-21T07:17:28Z
dc.date.accessioned2019-03-14T08:03:18Z
dc.date.available2018-12-21T07:17:28Z
dc.date.available2019-03-14T08:03:18Z
dc.date.issued2017-11-24en_US
dc.description.abstract© 2017 Copyright is held by the owner/author(s). Web servers use SSL/TLS to establish secure communication between clients and servers. The mechanism of SSL/TLS relies on a key pair to validate the server and to protect the confidentiality of the data. However, many websites are running on third-party servers or on cloud environments where website owners have no control over the physical servers or the software including the operating systems but still need to trust and store the private key on the servers. While it is common to store the encrypted key on the disk, the web server still need a decrypted key inside the memory during the operation. Thus, an adversary could obtain the private key residing on the web server's memory. In this paper, we propose a secure enclave for a web server running the high privilege code that handles the secret keys inside an encrypted memory area by utilizing Intel Software Guard Extension (SGX) whereas other components of the web server outside the trusted computing base are left intact. The experimental results show 19% to 38% implementation overhead depending on which cipher suite is used and how a session key is handled.en_US
dc.identifier.citationACM International Conference Proceeding Series. (2017), 27-31en_US
dc.identifier.doi10.1145/3163058.3163063en_US
dc.identifier.other2-s2.0-85041836056en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/42264
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85041836056&origin=inwarden_US
dc.subjectComputer Scienceen_US
dc.titleSecure enclave for TLS web server on untrusted environmenten_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85041836056&origin=inwarden_US

Files

Collections