Uppsats
Protecting Integrity of Security and Audit Trail Events using Trusted Execution Environments
Master-uppsats
Linköpings universitet/Institutionen för datavetenskap
Publicerad: 2025
Språk: Engelska
Sammanfattning
Security and audit trail events play a critical role in intrusion detection, incident response, and damage assessment following security breaches. Attackers target these logs to evade detection or remove evidence. While log protection is well-studied in traditional environments, few studies have specifically addressed the challenge within Cloud Radio Access Network (Cloud RAN) infrastructures, where logs must remain secure despite an adversary potentially having privileged access to the entire platform. This thesis investigates the feasibility of integrating Trusted Execution Environments (TEEs) into Cloud RAN products to protect symmetric keys used for generating Hash-based Message Authentication Codes (HMACs). Based on a STRIDE threat assessment, identified threats are addressed by deriving a hardware-agnostic design, implemented using the Open Enclave SDK and OpenSSL, facilitating compatibility across diverse hardware environments. The resulting proof of concept performs secure key establishment through a protocol involving remote attestation and cryptographic key provisioning. To preserve integrity, security and audit trail events are securely signed within the TEE using HMACs. Subsequently, they are sent to and verified externally by a centralized Security Information and Event Management (SIEM) system. The proof of concept was evaluated in a Kubernetes-based environment with SGX-enabled hardware, assessing its impact on container image footprint, deployment latency, and scalability. Results demonstrate that while TEE integration introduces moderate overhead, it offers significant improvements in protecting critical assets even against infrastructure-level adversaries. These findings offer actionable insights for operators aiming to enhance log integrity in cloud-native deployments exposed to high-privilege threats.
Information
- Författare
- Schölin, Edvin, Strömberg Hooshidar, Felix
- Lärosäte / institution
- Linköpings universitet/Institutionen för datavetenskap
- Publiceringsdatum
- 2025
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Linköpings universitet/Institutionen för datavetenskap
Svensson, Petter, Norberg, Philip
Publicerad: 2025
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Wang, Pengcheng
Publicerad: 2025
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Liang, Tianning
Publicerad: 2025
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Amadoru, Nethmee
Publicerad: 2025
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Bokelund Singh, Alexander Sanjot, Björklund, Jonathan
Publicerad: 2025
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Nan, Zilong
Publicerad: 2025