CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices

CRII:SaTC:审查和改进可信执行环境在移动设备中进行身份验证的使用

基本信息

  • 批准号:
    1849803
  • 负责人:
  • 金额:
    $ 17.5万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-06-01 至 2019-10-31
  • 项目状态:
    已结题

项目摘要

In mobile devices, authentication protocols are used to ensure that users' intentions are communicated untampered to the applications' backend servers. Unfortunately, traditional authentication protocols do not defend against "root-attackers," i.e., attackers able to fully compromise the main operating system of a victim's device. Trusted Execution Environments (TEEs), specific hardware components available in modern mobile devices, can be used to mitigate this threat, since they run a separate, smaller codebase than the main operating system. This project explores how it is possible to use TEEs to implement "root-resilient" authentication protocols, i.e., authentication protocols effective against root-attackers.This project is divided into three main tasks. The first task consists in performing a comprehensive study of the existing Application Programming Interfaces (APIs) that developers of mobile apps can use to interact with TEEs. This study will concentrate on understanding if and how these APIs can be used to implement root-resilient authentication protocols. The second task focuses on developing an automated analysis system that will be used to perform a large-scale study assessing the security of TEE-based authentication protocols implemented by existing applications. The third task consists of implementing an authentication framework helping developers in using TEEs for authentication purposes.The project has the potential to improve the security of millions of mobile device users by enabling root-resilient authentication in thousands of mobile application programs. By performing a large-scale analysis of such mobile "apps", this project will identify weaknesses in existing programs. Additionally, the authentication framework developed by this project could potentially allow thousands of developers to implement root-resilient authentication protocols with reduced effort. The developed software, techniques, and findings will be disseminated by releasing the source code of the implemented software, publishing academic articles, and presenting results at academic conferences.In addition, produced software and data will also be shared on a dedicated website (http://homepage.divms.uiowa.edu/~bianch/mobiletees/). After project completion, produced software and data will be available for at least three years.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在移动设备中,身份验证协议用于确保用户的意图不被篡改地传达到应用程序的后端服务器。不幸的是,传统的身份验证协议无法防御“根攻击者”,即能够完全破坏受害者设备的主操作系统的攻击者。可信执行环境 (TEE) 是现代移动设备中可用的特定硬件组件,可用于减轻这种威胁,因为它们运行一个独立的、比主操作系统更小的代码库。该项目探索如何使用 TEE 来实现“root-resilient”身份验证协议,即有效对抗 root 攻击者的身份验证协议。该项目分为三个主要任务。第一项任务包括对移动应用程序开发人员可用来与 TEE 交互的现有应用程序编程接口 (API) 进行全面研究。本研究将集中于了解是否以及如何使用这些 API 来实现 root 弹性身份验证协议。第二项任务重点是开发一个自动分析系统,该系统将用于执行大规模研究,评估现有应用程序实现的基于 TEE 的身份验证协议的安全性。第三项任务包括实现一个身份验证框架,帮助开发人员使用 TEE 进行身份验证。该项目有潜力通过在数千个移动应用程序中启用 root 弹性身份验证来提高数百万移动设备用户的安全性。通过对此类移动“应用程序”进行大规模分析,该项目将识别现有程序中的弱点。此外,该项目开发的身份验证框架可能允许数千名开发人员以更少的工作量实现根弹性身份验证协议。所开发的软件、技术和研究结果将通过发布所实现的软件的源代码、发表学术文章以及在学术会议上展示成果来传播。此外,所开发的软件和数据也将在专门的网站(http://homepage.divms.uiowa.edu/~bianch/mobiletees/)上共享。项目完成后,生成的软件和数据将至少可用三年。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Antonio Bianchi其他文献

Short: Rethinking Secure Pairing in Drone Swarms
简短:重新思考无人机群中的安全配对
MATOQ: a Monte Carlo simulation of electron transport in environmental-friendly gas mixtures for Resistive Plate Chambers
  • DOI:
    10.1140/epjp/s13360-023-04440-0
  • 发表时间:
    2023-09-25
  • 期刊:
  • 影响因子:
    2.900
  • 作者:
    Antonio Bianchi
  • 通讯作者:
    Antonio Bianchi
Lights or shadows, a promising future for positron emission tomography in pituitary tumors: a systematic review
  • DOI:
    10.1007/s11154-025-09978-1
  • 发表时间:
    2025-06-11
  • 期刊:
  • 影响因子:
    8.000
  • 作者:
    Sabrina Chiloiro;Carmelo Caldarella;Alessandra Vicari;Simone Antonio De Sanctis;Antonella Giampietro;Pier Paolo Mattogno;Lauretti Liverana;Rosalinda Calandrelli;Tommaso Tartaglione;Simona Gaudino;Alessandro Olivi;Laura De Marinis;Francesco Doglietto;Antonio Bianchi;Maria Fleseriu;Alfredo Pontecorvi
  • 通讯作者:
    Alfredo Pontecorvi
IGF-I levels during standard Lanreotide dose predicts biochemical outcome of high-frequency regimen in acromegaly
  • DOI:
    10.1007/s11102-024-01479-9
  • 发表时间:
    2024-12-26
  • 期刊:
  • 影响因子:
    3.400
  • 作者:
    Sabrina Chiloiro;Antonella Giampietro;Penelope Giambò;Flavia Costanza;Pier Paolo Mattogno;Liverana Lauretti;Rosalinda Calandrelli;Simona Gaudino;Marco Gessi;Guido Rindi;Alessandro Olivi;Laura De Marinis;Francesco Doglietto;Antonio Bianchi;Alfredo Pontecorvi;Andrea Giustina
  • 通讯作者:
    Andrea Giustina
PatchVerif: Discovering Faulty Patches in Robotic Vehicles
PatchVerif:发现机器人车辆中的故障补丁
  • DOI:
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Hyungsub Kim;Muslum Ozgur Ozmen;Z. Berkay Celik;Antonio Bianchi;Dongyan Xu
  • 通讯作者:
    Dongyan Xu

Antonio Bianchi的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Antonio Bianchi', 18)}}的其他基金

CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
CRII:SaTC:审查和改进可信执行环境在移动设备中进行身份验证的使用
  • 批准号:
    1949632
  • 财政年份:
    2019
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant

相似海外基金

CRII: SaTC: Automated Knowledge Representation for IoT Cybersecurity Regulations
CRII:SaTC:物联网网络安全法规的自动化知识表示
  • 批准号:
    2348147
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Reliable Hardware Architectures Against Side-Channel Attacks for Post-Quantum Cryptographic Algorithms
CRII:SaTC:针对后量子密码算法的侧通道攻击的可靠硬件架构
  • 批准号:
    2348261
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
  • 批准号:
    2348181
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Continuing Grant
CRII: SaTC: Evolving I/O Protocols for Confidential Computing
CRII:SaTC:用于机密计算的不断发展的 I/O 协议
  • 批准号:
    2348130
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Enforcing Expressive Security Policies using Trusted Execution Environments
CRII:SaTC:使用可信执行环境执行表达性安全策略
  • 批准号:
    2348304
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Continuing Grant
CRII: SaTC: The Right to be Forgotten in Follow-ups of Machine Learning: When Privacy Meets Explanation and Efficiency
CRII:SaTC:机器学习后续中被遗忘的权利:当隐私遇到解释和效率时
  • 批准号:
    2348177
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了