• DocumentCode
    3209741
  • Title

    A secure and reliable bootstrap architecture

  • Author

    Arbaugh, William A. ; Farber, D.J. ; Smith, Jonathan M.

  • Author_Institution
    Distributed Syst. Lab., Pennsylvania Univ., Philadelphia, PA, USA
  • fYear
    1997
  • fDate
    4-7 May 1997
  • Firstpage
    65
  • Lastpage
    71
  • Abstract
    In a computer system, the integrity of lower layers is typically treated as axiomatic by higher layers. Under the presumption that the hardware comprising the machine (the lowest layer) is valid, the integrity of a layer can be guaranteed if and only if: (1) the integrity of the lower layers is checked and (2) transitions to higher layers occur only after integrity checks on them are complete. The resulting integrity “chain” inductively guarantees system integrity. When these conditions are not met, as they typically are not in the bootstrapping (initialization) of a computer system, no integrity guarantees can be made, yet these guarantees are increasingly important to diverse applications such as Internet commerce, security systems and “active networks”. In this paper, we describe the AEGIS architecture for initializing a computer system. It validates integrity at each layer transition in the bootstrap process. AEGIS also includes a recovery process for integrity check failures, and we show how this results in robust systems
  • Keywords
    Internet; computer bootstrapping; data integrity; security of data; software reliability; system recovery; AEGIS architecture; Internet commerce; active networks; bootstrap architecture; hardware validity; initialization; integrity chain; integrity check failures; lower-layer integrity; recovery process; reliability; robust systems; security; system integrity guarantees; transitions; Computer architecture; Distributed computing; Hardware; IP networks; Laboratories; Microprogramming; Operating systems; Robustness; Security; Virtual machining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1997. Proceedings., 1997 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-8186-7828-3
  • Type

    conf

  • DOI
    10.1109/SECPRI.1997.601317
  • Filename
    601317