David Cerdeira

dblp:255/2388 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
3since 2021 · last 2022
0000-0002-1348-0272ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Hardware security and side channels · 60% Authentication and access control · 17% Systems and software security · 13%
Databases, data mining, and information retrieval
1 paper
Query processing and optimization · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Storage systems · 50% Memory systems · 50%

Topics — the 9 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › trusted execution environments
ARM TrustZone
1.022022
ReZone: Disarming TrustZone with TEE Privilege Reduction · USENIX Security Symposium 2022
SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE Systems · SP 2020
Hardware security and side channels
trusted execution environments
1.022022
ReZone: Disarming TrustZone with TEE Privilege Reduction · USENIX Security Symposium 2022
SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE Systems · SP 2020
Query processing and optimization
secure query processing
0.612022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Authentication and access control › access control
least privilege
0.612022
ReZone: Disarming TrustZone with TEE Privilege Reduction · USENIX Security Symposium 2022
Systems and software security
vulnerability analysis
0.412020
SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE Systems · SP 2020
Privacy and data protection › privacy compliance
GDPR compliance
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Privacy and data protection
policy compliance
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Storage systems
computational storage
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Memory systems › processing-in-memory
near-data processing
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022

Methods — techniques the papers use, named apart from their topics

trusted execution environment · 1.7Intel SGX · 1.7ARM TrustZone · 1.7security analysis · 0.4reverse engineering · 0.4
YearPublicationVenuePosition
2022 Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures
abstract
Computation Storage Architectures (CSA) are increasingly adopted in the cloud for near data processing, where the underlying storage devices/servers are now equipped with heterogeneous cores which enable computation offloading near to the data. While CSA is a promising high-performance architecture for the cloud, in general data analytics also presents significant data security and policy compliance (e.g., GDPR) challenges in untrusted cloud environments. In this paper, we present IronSafe, a secure and policy-compliant query processing system for heterogeneous computational storage architectures, while preserving the performance advantages of CSA in untrusted cloud environments. To achieve these design properties in a computing environment with heterogeneous host (x86) and storage system (ARM), we design and implement the entire hardware and software system stack from the ground-up leveraging hardware-assisted Trusted Execution Environments (TEEs): namely, Intel SGX and ARM TrustZone. More specifically, IronSafe builds on three core contributions: (1) a heterogeneous confidential computing framework for shielded execution with x86 and ARM TEEs and associated secure storage system for the untrusted storage medium; (2) a policy compliance monitor to provide a unified service for attestation and policy compliance; and (3) a declarative policy language and associated interpreter for concisely specifying and efficiently evaluating a rich set of polices. Our evaluation using the TPC-H SQL benchmark queries and GDPR anti-pattern use-cases shows that IronSafe is faster, on average by 2.3x than a host-only secure system, while providing strong security and policy-compliance properties.
Harshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos 0001, Pramod Bhatotia
SIGMOD Conference2
2022 ReZone: Disarming TrustZone with TEE Privilege Reduction
David Cerdeira, José Martins 0004, Nuno Santos 0001, Sandro Pinto 0001
USENIX Security Symposium1
2021 Self-secured devices: High performance and secure I/O access in TrustZone-based systems
abstract
Arm TrustZone is a hardware technology that adds significant value to the ongoing security picture. TrustZone-based systems typically consolidate multiple environments into the same platform, requiring resources to be shared among them. Currently, hardware devices on TrustZone-enabled system-on-chip (SoC) solutions can only be configured as secure or non-secure, which means the dual-world concept of TrustZone is not spread to the inner logic of the devices. The traditional passthrough model dictates that both worlds cannot use the same device concurrently. Furthermore, existing shared device access methods have been proven to cause a negative impact on the overall system in terms of security and performance. This work introduces the concept of self-secured devices, a novel approach for shared device access in TrustZone-based architectures. This concept extends the TrustZone dual-world model to the device itself, providing a secure and non-secure logical interface in a single device instance. The solution was deployed and evaluated on the LTZVisor, an open-source and lightweight TrustZone-assisted hypervisor . The obtained results are encouraging, demonstrating that our solution requires only a few additional hardware resources when compared with the native device implementation, while providing a secure solution for device sharing.
Sandro Pinto 0001, Daniel Oliveira 0003, David Cerdeira, Tiago Gomes 0001
J. Syst. Archit.4
2020 SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE Systems
abstract
Hundreds of millions of mobile devices worldwide rely on Trusted Execution Environments (TEEs) built with Arm TrustZone for the protection of security-critical applications (e.g., DRM) and operating system (OS) components (e.g., Android keystore). TEEs are often assumed to be highly secure; however, over the past years, TEEs have been successfully attacked multiple times, with highly damaging impact across various platforms. Unfortunately, these attacks have been possible by the presence of security flaws in TEE systems. In this paper, we aim to understand which types of vulnerabilities and limitations affect existing TrustZone-assisted TEE systems, what are the main challenges to build them correctly, and what contributions can be borrowed from the research community to overcome them. To this end, we present a security analysis of popular TrustZone-assisted TEE systems (targeting Cortex-A processors) developed by Qualcomm, Trustonic, Huawei, Nvidia, and Linaro. By studying publicly documented exploits and vulnerabilities as well as by reverse engineering the TEE firmware, we identified several critical vulnerabilities across existing systems which makes it legitimate to raise reasonable concerns about the security of commercial TEE implementations.
David Cerdeira, Nuno Santos 0001, Pedro Fonseca 0001, Sandro Pinto 0001
SP1
2019 Operating Systems for Internet of Things Low-End Devices: Analysis and Benchmarking
abstract
In the era of the Internet of Things (IoT), billions of wirelessly connected embedded devices rapidly became part of our daily lives. As a key tool for each Internet-enabled object, embedded operating systems (OSes) provide a set of services and abstractions which eases the development and speedups the deployment of IoT solutions at scale. This article starts by discussing the requirements of an IoT-enabled OS, taking into consideration the major concerns when developing solutions at the network edge, followed by a deep comparative analysis and benchmarking on Contiki-NG, RIOT, and Zephyr. Such OSes were considered as the best representative of their class considering the main key-points that best define an OS for resource-constrained IoT devices: low-power consumption, real-time capabilities, security awareness, interoperability, and connectivity. While evaluating each OS under different network conditions, the gathered results revealed distinct behaviors for each OS feature, mainly due to differences in kernel and network stack implementations.
David Cerdeira, Sandro Pinto 0001, Tiago Gomes 0001
IEEE Internet Things J.2