TruZ-Droid: Integrating TrustZone with Mobile Operating System

TruZ-Droid: Integrating TrustZone with Mobile Operating System
复制标题

DOI:
10.1145/3210240.3210338
复制
发表时间:
2018-06
期刊:
Proceedings of the 16th Annual International Conference on Mobile Systems, Applications, and Services
影响因子:
--
通讯作者:
Kailiang Ying;A. Ahlawat;B. Alsharifi;Yuexin Jiang;Priyank Thavai;Wenliang Du
Kailiang Ying;A. Ahlawat;B. Alsharifi;Yuexin Jiang;Priyank Thavai;Wenliang Du
中科院分区:
其他
文献类型:
--
作者:
Kailiang Ying;A. Ahlawat;B. Alsharifi;Yuexin Jiang;Priyank Thavai;Wenliang Du

文献摘要

被引文献

相似文献

今天,移动设备提供了一种称为可信执行环境(TEE)的硬件保护模式,以帮助保护用户免受损害的操作系统和管理程序的侵害。今天,只有供应商应用程序或与供应商合作的开发人员可以利用TEE。由于供应商认为Tee内部不受信任的第三方应用程序代码,以允许应用程序利用TEE,因此应用程序开发人员必须以量身定制的方式编写应用程序代码,以与供应商的SDK合作。我们提出了一种新颖的设计,以将T恤与移动操作系统集成在一起,以允许任何应用程序利用TEE。我们的设计结合了OS级别的TEE支持,允许应用程序在不将应用程序特定代码添加到TEE中,而使用现有接口与移动OS进行交互时,可以利用TEE。我们通过将Trustzone Tee与Android OS集成,实现了称为Truz-Droid的设计。 Truz-Droid允许应用程序利用T恤保护以下内容:(i)用户的秘密输入和确认,以及(ii)将用户的秘密发送到授权服务器。我们使用启用信任的Hikey董事会制造了一个原型,以评估我们的设计。我们通过在现有应用程序中添加新的安全功能来保护用户的敏感信息并证明用户的确认,从而证明了TRUZ-Droid的有效性。 Truz-Droid的现实世界用例评估表明,应用程序可以在使用现有OS API时利用Trustzone。我们的可用性研究证明,用户可以正确地与truz-Droid互动,以保护其安全敏感的活动和数据。
Mobile devices today provide a hardware-protected mode called Trusted Execution Environment (TEE) to help protect users from a compromised OS and hypervisor. Today TEE can only be leveraged either by vendor apps or by developers who work with the vendor. Since vendors consider third-party app code untrusted inside the TEE, to allow an app to leverage TEE, app developers have to write the app code in a tailored way to work with the vendor's SDK. We proposed a novel design to integrate TEE with mobile OS to allow any app to leverage the TEE. Our design incorporates TEE support at the OS level, allowing apps to leverage the TEE without adding app-specific code into the TEE, and while using existing interface to interact with the mobile OS. We implemented our design, called TruZ-Droid, by integrating TrustZone TEE with the Android OS. TruZ-Droid allows apps to leverage the TEE to protect the following: (i) user's secret input and confirmation, and (ii) sending of user's secrets to the authorized server. We built a prototype using the TrustZone-enabled HiKey board to evaluate our design. We demonstrated TruZ-Droid's effectiveness by adding new security features to existing apps to protect user's sensitive information and attest user's confirmation. TruZ-Droid's real-world use case evaluation shows that apps can leverage TrustZone while using existing OS APIs. Our usability study proves that users can correctly interact with TruZ-Droid to protect their security sensitive activities and data.