I-Corps: A device for defensive charging to augment the security of mobile devices
I-Corps: A device for defensive charging to augment the security of mobile devices
批准号:
2110237
负责人:
Abdul Serwadda
金额:
$5.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-03-01 至 2022-08-31
中文摘要
这个i-Corps项目的更广泛的影响/商业潜力是开发一种智能手机充电技术,保护在公共充电中心为手机充电的用户的隐私。由于是公开的,这类集线器是恶意行为者篡改的主要目标,这些恶意行为者可以嵌入非法仪表,执行电力分析,以收集有关键入的密钥、访问的网站、消费的多媒体内容等信息。拟议的系统缓解了这些攻击,对经常旅行的人可能具有重要价值,因为他们经常发现自己不得不在可能不值得信任的实体管辖的集线器为手机充电。除了个人常客,这项拟议中的技术对寻求缓解员工使用手机连接到公司网络的员工构成的安全威胁的公司也可能有价值。随着智能手机日益成为通信、银行、敏感数据存储等活动的核心,拟议的技术有可能显著增强最终用户的安全性。该i-Corps项目基于开发一种防御性充电方案,旨在缓解充电过程中的电源侧通道攻击。这项拟议技术的硬件形式是充电器或充电器插件,它可以改变手机在充电过程中消耗的电量。它由一个微控制器和金属氧化物半导体场效应晶体管(MOSFET)组成,当手机充电时,MOSFET可以打开和关闭随机的电阻组合。电阻的变化反过来又产生了混淆手机功率消耗的真实足迹所需的效果。该解决方案的软件形式在手机充电时在后台使用虚假操作(例如,随机图像旋转)。这些操作会导致计算机处理单元(CPU)和内存负载中断,而这些内存负载是混淆手机真实功耗所需的。该系统的设计将对充电时间以及软件方法使用的CPU和内存的影响降至最低。由于硬件选件位于电话外部,因此不会消耗电话上的CPU/内存。作为一种软件解决方案,这项技术可能会提供便利,因为它在充电过程中自动运行,并且可以随着威胁和防御机制的发展而轻松更新。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The broader impact/commercial potential of this I-Corps project is the development of a smart phone charging technology that protects the privacy of users who charge their phones at public charging hubs. By virtue of being public, such hubs are a prime target for tampering by malicious actors who could embed illicit meters that perform power analytics to glean information about keys typed, websites visited, multimedia content consumed, etc. The proposed system mitigates these attacks and may be of significant value to frequent travelers given that they often find themselves having to charge their phones at hubs that are within the jurisdiction of entities that might not be trustworthy. Beyond individual frequent travelers, the proposed technology also may be of value to companies seeking to mitigate the security threat posed by employees who connect to the company network using their phones. As smart phones increasingly become central to activities such as communication, banking, storage of sensitive data, etc., the proposed technology has the potential to significantly augment end-user security.This I-Corps project is based on the development of a defensive charging scheme designed to mitigate power side-channel attacks during the charging process. The hardware form of the proposed technology is a charger or charger add-on that morphs the power drawn by the phone during charging. It consists of a micro-controller and metal–oxide–semiconductor field-effect transistors (MOSFETs) that switch on and off random combinations of resistors while the phone is being charged. The variation in resistance, in turn, produces the effect needed to obfuscate the true footprint of the phone’s power draw. The software form of the solution uses bogus operations (e.g., random image rotations) in the background while the phone is being charged. These operations cause disruptions in computer processing unit (CPU) and memory load needed to obfuscate the phone’s true power draw. The system has been designed to minimize the impact on charging time and the CPU and memory used by the software approach. By virtue of being external to the phone, the hardware option does not consume CPU/memory on the phone. As a software solution, this technology may offer convenience given that it runs automatically during charging and could easily be updated as threats and the defense mechanism evolve.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RET Site: Applied Data Science for Cyber Security
-
批准号:1801734
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2018
-
负责人:Abdul Serwadda
-
依托单位:
海外基金