Jeffrey S. Dwoskin

dblp:58/5604 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
0since 2021 · last 2010
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2Security and privacy · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Hardware security and side channels · 40% Systems and software security · 33% Cryptographic protocols and secure computation · 15%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Memory systems · 100%

Topics — the 8 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
trusted execution environments
0.122007
Hardware-rooted trust for secure key management and transient trust · CCS 2007
Architecture for Protecting Critical Secrets in Microprocessors · ISCA 2005
Systems and software security
operating system security
0.112008
Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems · ASPLOS 2008
Systems and software security › virtualization security
virtualization-based security
0.112008
Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems · ASPLOS 2008
Cryptographic protocols and secure computation
key management
0.122007
Architecture for Protecting Critical Secrets in Microprocessors · ISCA 2005
Hardware-rooted trust for secure key management and transient trust · CCS 2007
Hardware security and side channels › hardware security primitives
hardware root of trust
0.112007
Hardware-rooted trust for secure key management and transient trust · CCS 2007
Cryptographic primitives and cryptanalysis › cryptographic implementation
key protection
0.112005
Architecture for Protecting Critical Secrets in Microprocessors · ISCA 2005
Operating systems
commodity operating systems
0.012008
Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems · ASPLOS 2008
Memory systems › memory management
virtual memory
0.012008
Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems · ASPLOS 2008

Methods — techniques the papers use, named apart from their topics

virtual machine based isolation · 0.2multi-shadowing · 0.2trusted software module · 0.1architectural features · 0.1storage root hash · 0.1hardware additions · 0.1device root key · 0.1
YearPublicationVenuePosition
2010 A framework for testing hardware-software security architectures
abstract
New security architectures are difficult to prototype and test at the design stage. Fine-grained monitoring of the interactions between hardware, the operating system and applications is required. We have designed and prototyped a testing framework, using virtualization, that can emulate the behavior of new hardware mechanisms in the virtual CPU and can perform a wide range of hardware and software attacks on the system under test.
Jeffrey S. Dwoskin, Mahadevan Gomathisankaran, Yu-Yuan Chen, Ruby B. Lee
ACSAC1
2008 Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems
abstract
Commodity operating systems entrusted with securing sensitive data are remarkably large and complex, and consequently, frequently prone to compromise. To address this limitation, we introduce a virtual-machine-based system called Overshadow that protects the privacy and integrity of application data, even in the event of a total OScompromise. Overshadow presents an application with a normal view of its resources, but the OS with an encrypted view. This allows the operating system to carry out the complex task of managing an application's resources, without allowing it to read or modify them. Thus, Overshadow offers a last line of defense for application data.Overshadow builds on multi-shadowing, a novel mechanism that presents different views of physical memory, depending on the context performing the access. This primitive offers an additional dimension of protection beyond the hierarchical protection domains implemented by traditional operating systems and processor architectures.We present the design and implementation of Overshadow and show how its new protection semantics can be integrated with existing systems. Our design has been fully implemented and used to protect a wide range of unmodified legacy applications running on an unmodified Linux operating system. We evaluate the performance of our implementation, demonstrating that this approach is practical.
Tal Garfinkel, E. Christopher Lewis, Pratap Subrahmanyam, Carl A. Waldspurger, Dan Boneh, Jeffrey S. Dwoskin, Dan R. K. Ports
ASPLOS7
2007 Hardware-rooted trust for secure key management and transient trust
abstract
We propose minimalist new hardware additions to a microprocessor chip that protect cryptographic keys in portable computing devices which are used in the field but owned by a central authority. Our authority-mode architecture has trust rooted in two critical secrets: a Device Root Key and a Storage Root Hash, initialized in the device by the trusted authority. Our architecture protects trusted software, bound to the device, which can use the root secrets to protect other sensitive information for many different usage scenarios. We describe a detailed usage scenario for crisis response, where first responders are given transient access to third-party sensitive information which can be securely accessed during a crisis and reliably revoked after the crisis is over.
Jeffrey S. Dwoskin, Ruby B. Lee
CCS1
2007 Secure Key Management Architecture Against Sensor-Node Fabrication Attacks
abstract
In lightweight mobile ad hoc networks, both probabilistic and deterministic key management schemes are fragile to node fabrication attacks. Our simulation results show that the Successful Attack Probability (SAP) can be as high as 42.6% with the fabrication of only 6 copies from captured nodes comprising only 3% of all nodes. In this paper, we propose two low-cost secure-architecture-based techniques to improve the security against such node fabrication attacks. Our new architectures, specifically targeted at the sensor-node platform, protect long-term keys using a root of trust embedded in the hardware System-on-a-Chip (SoC). This prevents an adversary from extracting these protected long-term keys from a captured node to fabricate new nodes. The extensive simulation results show that the proposed architecture can significantly decrease the SAP and increase the security level of key management for mobile ad hoc networks.
Jeffrey S. Dwoskin, Dahai Xu, Jianwei Huang 0001, Mung Chiang, Ruby B. Lee
GLOBECOM1
2007 Re-examining Probabilistic Versus Deterministic Key Management
abstract
It is widely believed that although being more complex, a probabilistic key predistribution scheme is much more resilient against node capture than a deterministic one in lightweight wireless ad hoc networks. Backed up by the surprisingly large successful attack probabilities computed in this paper, we show that the probabilistic approaches have only limited performance advantages over deterministic approaches. We first consider a static network scenario as originally considered in the seminal paper by Eschenauer and Gligor [1], where any node capture happens after the establishment of all pairwise links, and show that the deterministic approach can achieve a performance as good as the probabilistic one. Furthermore in a mobile network, the probabilistic key management as described in [1] can lead to a successful attack probability of one order of magnitude larger than the one in a static network.
Dahai Xu, Jianwei Huang 0001, Jeffrey S. Dwoskin, Mung Chiang, Ruby B. Lee
ISIT3
2005 Architecture for Protecting Critical Secrets in Microprocessors
abstract
We propose "secret-protected (SP)" architecture to enable secure and convenient protection of critical secrets for a given user in an on-line environment. Keys are examples of critical secrets, and key protection and management is a fundamental problem - often assumed but not solved /sup n/derlying the use of cryptographic protection of sensitive files, messages, data and programs. SP-processors contain a minimalist set of architectural features that can be built into a general-purpose microprocessor to provide protection of critical secrets and their computations, without expensive or inconvenient auxiliary hardware. SP-architecture also requires a trusted software module, a few modifications to the operating system, a secure I/O path to the user, and a secure installation process. Unique aspects of our architecture include: decoupling of user secrets from the devices, enabling users to securely access their keys from different networked computing devices; the use of symmetric master keys rather than more costly public-private key pairs; and the avoidance of any permanent or factory-installed device secrets.
Ruby B. Lee, Peter C. S. Kwan, John Patrick McGregor, Jeffrey S. Dwoskin, Zhenghong Wang
ISCA4