CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
批准号:
1949632
负责人:
Antonio Bianchi
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-08-12 至 2021-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
In mobile devices, authentication protocols are used to ensure that users' intentions are communicated untampered to the applications' backend servers. Unfortunately, traditional authentication protocols do not defend against "root-attackers," i.e., attackers able to fully compromise the main operating system of a victim's device. Trusted Execution Environments (TEEs), specific hardware components available in modern mobile devices, can be used to mitigate this threat, since they run a separate, smaller codebase than the main operating system. This project explores how it is possible to use TEEs to implement "root-resilient" authentication protocols, i.e., authentication protocols effective against root-attackers.This project is divided into three main tasks. The first task consists in performing a comprehensive study of the existing Application Programming Interfaces (APIs) that developers of mobile apps can use to interact with TEEs. This study will concentrate on understanding if and how these APIs can be used to implement root-resilient authentication protocols. The second task focuses on developing an automated analysis system that will be used to perform a large-scale study assessing the security of TEE-based authentication protocols implemented by existing applications. The third task consists of implementing an authentication framework helping developers in using TEEs for authentication purposes.The project has the potential to improve the security of millions of mobile device users by enabling root-resilient authentication in thousands of mobile application programs. By performing a large-scale analysis of such mobile "apps", this project will identify weaknesses in existing programs. Additionally, the authentication framework developed by this project could potentially allow thousands of developers to implement root-resilient authentication protocols with reduced effort. The developed software, techniques, and findings will be disseminated by releasing the source code of the implemented software, publishing academic articles, and presenting results at academic conferences.In addition, produced software and data will also be shared on a dedicated website (http://homepage.divms.uiowa.edu/~bianch/mobiletees/). After project completion, produced software and data will be available for at least three years.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3458864.3466627
发表时间:
2021-06
期刊:
Proceedings of the 19th Annual International Conference on Mobile Systems, Applications, and Services
影响因子:
--
作者:
[Muhammad Ibrahim;A. Imran;Antonio Bianchi]
通讯作者:
Muhammad Ibrahim;A. Imran;Antonio Bianchi
DOI:
10.1109/eurosp51992.2021.00038
发表时间:
2021-09
期刊:
2021 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
作者:
[Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele]
通讯作者:
Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele
Exploring Syscall-Based Semantics Reconstruction of Android Applications
探索基于 Syscall 的 Android 应用语义重构
DOI:
--
发表时间:
2019
期刊:
Intrusions and Defenses (RAID 2019
影响因子:
--
作者:
[Nisi, Dario, Bianchi, Antonio, Fratantonio, Yanick]
通讯作者:
Fratantonio, Yanick
On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
DOI:
10.14722/ndss.2021.24212
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos]
通讯作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
-
批准号:1849803
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2019
-
负责人:Antonio Bianchi
-
依托单位:
海外基金