KIT | KIT-Bibliothek | Impressum | Datenschutz

DDS Security+: Enhancing the Data Distribution Service With TPM-based Remote Attestation

Wagner, Paul Georg ORCID iD icon 1,2; Birnstill, Pascal 1,2; Beyerer, Jürgen 1,3
1 Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL), Karlsruher Institut für Technologie (KIT)
2 Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung (IOSB)
3 Institut für Anthropomatik und Robotik (IAR), Karlsruher Institut für Technologie (KIT)

Abstract:

The Data Distribution Service (DDS) is a widely accepted industry standard for reliably exchanging data over the network using a publish-subscribe model. While DDS already includes basic security features such as participant authentication and access control, the possibilities of leveraging Trusted Platform Modules (TPMs) to increase the security and trustworthiness of DDS-based applications have not been sufficiently researched yet. In this work, we show how TPM-based remote attestation can be effectively integrated into the existing DDS security architecture. This enables application developers to verify the code integrity of remote DDS participants during the operation of the distributed system. Our solution transparently extends the DDS secure channel handshake, while cryptographically binding the established communication channels to the attested software stacks. We show the security properties of our proposal by formally verifying the resulting remote attestation protocol using the Tamarin theorem prover. We also implement our solution as a fork of the popular eProsima FastDDS library and evaluate the resulting performance impact when conducting TPM-based remote attestations of DDS applications.


Verlagsausgabe §
DOI: 10.5445/IR/1000173126
Veröffentlicht am 05.08.2024
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Anthropomatik und Robotik (IAR)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 30.07.2024
Sprache Englisch
Identifikator ISBN: 979-8-4007-1718-5
KITopen-ID: 1000173126
HGF-Programm 46.23.04 (POF IV, LK 01) Engineering Security for Production Systems
Erschienen in Proceedings of the 19th International Conference on Availability, Reliability and Security
Veranstaltung International Conference on Availability, Reliability and Security (ARES 2024), Wien, Österreich, 30.07.2024 – 02.08.2024
Verlag Association for Computing Machinery (ACM)
Seiten Art.-Nr.: 159
Schlagwörter Data Distribution Service, DDS Security, Remote Attestation, Trusted Platform Modules, TPM, Integrity Measurement
Nachgewiesen in Dimensions
Scopus
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page