Zur Hauptnavigation wechseln Zur Suche wechseln Zum Hauptinhalt wechseln

A Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices

  • Javier Gonzales
  • , Michael Hölzl
  • , Peter Riedl
  • , Philippe Bonnet
  • , Rene Mayrhofer

Publikation: Beitrag in Buch/Bericht/TagungsbandKapitelBegutachtung

8 Zitate (Scopus)

Abstract

Current efforts to increase the security of the boot sequence for mobile devices fall into two main categories: (i) secure boot: where each stage in the boot sequence is evaluated, aborting the boot process if a non expected component attempts to be loaded; and (ii) trusted boot: where a log is maintained with the components that have been loaded in the boot process for later audit. The first approach is often criticized for locking down devices, thus reducing users’ freedom to choose software. The second lacks the mechanisms to enforce any form of run-time verification. In this paper, we present the architecture for a two-phase boot verification that addresses these shortcomings. In the first phase, at boot-time the integrity of the bootloader and OS images are verified and logged; in the second phase, at run-time applications can check the boot traces and verify that the running software satisfies their security requirements. This is a first step towards supporting usage control primitives for running applications. Our approach relies on off-the-shelf secure hardware that is available in a multitude of mobile devices: ARM TrustZone as a Trusted Execution Environment, and Secure Element as a tamper-resistant unit.
OriginalspracheEnglisch
TitelInformation Security - 17th International Conference, ISC 2014, Proceedings
Redakteure/-innenSherman S.M. Chow, Jan Camenisch, Lucas C.K. Hui, Siu Ming Yiu
Herausgeber (Verlag)Springer
Seiten542-554
Seitenumfang13
ISBN (elektronisch)9783319132563
ISBN (Print)978-3-319-13257-0
DOIs
PublikationsstatusVeröffentlicht - 2014
VeranstaltungInformation Security Conference (ISC) - Hong Kong, China
Dauer: 12 Okt. 201414 Okt. 2014
http://isc14.ie.cuhk.edu.hk/

Publikationsreihe

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Band8783
ISSN (Print)0302-9743
ISSN (elektronisch)1611-3349

Konferenz

KonferenzInformation Security Conference (ISC)
Land/GebietChina
OrtHong Kong
Zeitraum12.10.201414.10.2014
Internetadresse

Fingerprint

Untersuchen Sie die Forschungsthemen von „A Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices“. Zusammen bilden sie einen einzigartigen Fingerprint.

Zitieren