TrustZone Enhanced Plausibly Deniable Encryption System for Mobile Devices

TrustZone Enhanced Plausibly Deniable Encryption System for Mobile Devices
复制标题

DOI:
10.1145/3453142.3493512
复制
发表时间:
2021-12
期刊:
2021 IEEE/ACM Symposium on Edge Computing (SEC)
影响因子:
--
通讯作者:
Jinghui Liao;Bo Chen;Weisong Shi
Jinghui Liao;Bo Chen;Weisong Shi
中科院分区:
其他
文献类型:
--
作者:
Jinghui Liao;Bo Chen;Weisong Shi

文献摘要

相似文献

现代移动的设备越来越多地用于存储和处理敏感数据。为了防止敏感数据被泄露,保护它们及其所有者的最佳方法之一就是用合理的可否认性隐藏数据。似可否认加密(PDE)就是为此目的而设计的。然而,用于移动的设备的现有PDE系统已经遭受显著的缺点,因为它们或者忽略存在于移动的设备的特殊底层存储介质中的可否认性妥协,或者容易受到诸如侧信道攻击的各种新攻击。在这项工作中,我们提出了一个新的PDE系统设计的移动的设备,它利用了硬件功能配备在主流的移动的设备。我们的初步设计有两个主要组成部分:首先,我们严格隔离闪存层中的隐藏数据和公共数据,以便多快照对手在访问低层时无法识别隐藏敏感数据的存在设备的存储介质。其次,我们将软件和操作系统级别的可否认性纳入ARM TrustZone。有了这个TrustZone增强的隔离,我们的PDE系统在操作系统层对侧信道攻击免疫。
Modern mobile devices are increasingly used to store and process sensitive data. In order to prevent the sensitive data from being leaked, one of the best ways of protecting them and their owner is to hide the data with plausible deniability. Plausibly Deniable Encryption (PDE) has been designed for such purpose. The existing PDE systems for mobile devices however, have suffered from significant drawbacks as they either ignore the deniability compromises present in the special underlying storage media of mobile devices or are vulnerable to various new attacks such as side-channel attacks. In this work, we propose a new PDE system design for mobile devices which takes advantage of the hardware features equipped in the mainstream mobile devices. Our preliminary design has two major component: First, we strictly isolate the hidden and the public data in the flash layer, so that a multi-snapshot adversary is not able to identify the existence of the hidden sensitive data when having access to the low layer storage medium of the device. Second, we incorporate software and operating system level deniability into ARM TrustZone. With this TrustZone-enhanced isolation, our PDE system is immune to side-channel attacks at the operating system layer.