CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
批准号:
1949632
负责人:
Antonio Bianchi
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-08-12 至 2021-12-31
中文摘要
在移动设备中,身份验证协议用于确保将用户的意图不受篡改地传达给应用程序的后端服务器。不幸的是,传统的身份验证协议不能防御“根攻击者”,即能够完全破坏受害者设备的主操作系统的攻击者。可信执行环境(tee)是现代移动设备中可用的特定硬件组件,可以用来减轻这种威胁,因为它们运行的代码库比主操作系统小。本项目探讨了如何使用tee实现“根弹性”身份验证协议,即有效对抗根攻击者的身份验证协议。这个项目分为三个主要任务。第一项任务包括对现有的应用程序编程接口(api)进行全面研究,移动应用程序的开发人员可以使用这些接口与tee进行交互。本研究将重点了解这些api是否以及如何用于实现根弹性身份验证协议。第二项任务侧重于开发一个自动分析系统,该系统将用于执行大规模研究,评估现有应用程序实现的基于tee的身份验证协议的安全性。第三个任务包括实现一个身份验证框架,帮助开发人员使用tee进行身份验证。通过在数千个移动应用程序中启用根弹性身份验证,该项目有可能提高数百万移动设备用户的安全性。通过对此类移动“应用程序”进行大规模分析,该项目将找出现有程序中的弱点。此外,该项目开发的身份验证框架可能允许成千上万的开发人员以更少的努力实现根弹性身份验证协议。开发的软件、技术和发现将通过发布实现软件的源代码、发表学术文章和在学术会议上展示结果来传播。此外,制作的软件和数据也将在一个专门的网站(http://homepage.divms.uiowa.edu/~bianch/mobiletees/)上分享。项目完成后,生产的软件和数据将至少在三年内可用。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In mobile devices, authentication protocols are used to ensure that users' intentions are communicated untampered to the applications' backend servers. Unfortunately, traditional authentication protocols do not defend against "root-attackers," i.e., attackers able to fully compromise the main operating system of a victim's device. Trusted Execution Environments (TEEs), specific hardware components available in modern mobile devices, can be used to mitigate this threat, since they run a separate, smaller codebase than the main operating system. This project explores how it is possible to use TEEs to implement "root-resilient" authentication protocols, i.e., authentication protocols effective against root-attackers.This project is divided into three main tasks. The first task consists in performing a comprehensive study of the existing Application Programming Interfaces (APIs) that developers of mobile apps can use to interact with TEEs. This study will concentrate on understanding if and how these APIs can be used to implement root-resilient authentication protocols. The second task focuses on developing an automated analysis system that will be used to perform a large-scale study assessing the security of TEE-based authentication protocols implemented by existing applications. The third task consists of implementing an authentication framework helping developers in using TEEs for authentication purposes.The project has the potential to improve the security of millions of mobile device users by enabling root-resilient authentication in thousands of mobile application programs. By performing a large-scale analysis of such mobile "apps", this project will identify weaknesses in existing programs. Additionally, the authentication framework developed by this project could potentially allow thousands of developers to implement root-resilient authentication protocols with reduced effort. The developed software, techniques, and findings will be disseminated by releasing the source code of the implemented software, publishing academic articles, and presenting results at academic conferences.In addition, produced software and data will also be shared on a dedicated website (http://homepage.divms.uiowa.edu/~bianch/mobiletees/). After project completion, produced software and data will be available for at least three years.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3458864.3466627
发表时间:
2021-06
期刊:
Proceedings of the 19th Annual International Conference on Mobile Systems, Applications, and Services
影响因子:
--
作者:
[Muhammad Ibrahim;A. Imran;Antonio Bianchi]
通讯作者:
Muhammad Ibrahim;A. Imran;Antonio Bianchi
DOI:
10.1109/eurosp51992.2021.00038
发表时间:
2021-09
期刊:
2021 IEEE European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
作者:
[Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele]
通讯作者:
Onur Zungur;Antonio Bianchi;G. Stringhini;Manuel Egele
Exploring Syscall-Based Semantics Reconstruction of Android Applications
探索基于 Syscall 的 Android 应用语义重构
DOI:
--
发表时间:
2019
期刊:
Intrusions and Defenses (RAID 2019
影响因子:
--
作者:
[Nisi, Dario, Bianchi, Antonio, Fratantonio, Yanick]
通讯作者:
Fratantonio, Yanick
On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
DOI:
10.14722/ndss.2021.24212
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos]
通讯作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
CRII: SaTC: Vetting and Improving the Usage of Trusted Execution Environments for Authentication in Mobile Devices
-
批准号:1849803
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2019
-
负责人:Antonio Bianchi
-
依托单位:
海外基金