SoK: Cryptographic Confidentiality of Data on Mobile Devices

SoK: Cryptographic Confidentiality of Data on Mobile Devices
复制标题

DOI:
10.2478/popets-2022-0029
复制
发表时间:
2021-09
影响因子:
--
通讯作者:
Maximilian Zinkus;Tushar M. Jois;M. Green
Maximilian Zinkus;Tushar M. Jois;M. Green
中科院分区:
--
文献类型:
--
作者:
Maximilian Zinkus;Tushar M. Jois;M. Green

文献摘要

被引文献

相似文献

摘要移动的设备已经成为现代生活中不可缺少的组成部分。它们的高存储容量使这些设备能够存储大量敏感的个人数据,这使它们成为高价值的目标:这些设备经常被犯罪分子窃取数据,并且越来越多地被执法机构视为有价值的取证数据来源。在过去的几年里,提供商已经部署了许多高级加密功能,旨在保护移动的设备上的数据,即使在攻击者可以物理访问设备的强大环境中也是如此。这些技术中有许多来自研究文献,但已被改编为这个全新的问题设置。这涉及到一些新的挑战,这些挑战在文献中没有完全解决。在这项工作中,我们概述了这些挑战,并系统化已知的方法来保护用户数据免受提取攻击。我们的工作提出了一种方法,研究人员可以用来分析加密数据的机密性移动的设备。我们评估了现有的文献,以保护设备免受具有强大功能的数据提取对手,包括访问设备和云服务,他们所依赖的。然后,我们分析了现有的移动终端保密措施,以确定尚未得到适当的关注,从社会的研究领域,并代表未来的研究机会。
Abstract Mobile devices have become an indispensable component of modern life. Their high storage capacity gives these devices the capability to store vast amounts of sensitive personal data, which makes them a high-value target: these devices are routinely stolen by criminals for data theft, and are increasingly viewed by law enforcement agencies as a valuable source of forensic data. Over the past several years, providers have deployed a number of advanced cryptographic features intended to protect data on mobile devices, even in the strong setting where an attacker has physical access to a device. Many of these techniques draw from the research literature, but have been adapted to this entirely new problem setting. This involves a number of novel challenges, which are incompletely addressed in the literature. In this work, we outline those challenges, and systematize the known approaches to securing user data against extraction attacks. Our work proposes a methodology that researchers can use to analyze cryptographic data confidentiality for mobile devices. We evaluate the existing literature for securing devices against data extraction adversaries with powerful capabilities including access to devices and to the cloud services they rely on. We then analyze existing mobile device confidentiality measures to identify research areas that have not received proper attention from the community and represent opportunities for future research.