Abstract
Mobile devices such as smart phones have become one of the preferred means of accessing digital services, both for consuming and creating content. Unfortunately, securing such mobile devices is inherently difficult for a number of reasons. In this paper, we systematically analyze the technical issues of securing mobile device platforms against different threats and discuss a resulting and currently unsolved problem: how to create an end-to-end secure channel between the digital service (e.g. a secure wallet application on an embedded smart card or an infrastructure service connected over wireless media) and the user. Although the problem has been known for years and technical approaches start appearing in products, the user interaction aspects have remained unsolved. We discuss the reasons for this difficulty and suggest potential approaches to create human-verifiable secure communication with components or services within partially untrusted devices.
Originalsprache | Englisch |
---|---|
Titel | Proceedings - 2013 IEEE International Conference on High Performance Computing and Communications, HPCC 2013 and 2013 IEEE International Conference on Embedded and Ubiquitous Computing, EUC 2013 |
Herausgeber (Verlag) | IEEE Computer Society Press |
Seiten | 1579-1584 |
Seitenumfang | 6 |
ISBN (Print) | 9780769550886 |
DOIs | |
Publikationsstatus | Veröffentlicht - 2014 |
Veranstaltung | Fourth IEEE International Symposium on Trust, Security, and Privacy - Zhangjiajie, China, China Dauer: 13 Nov. 2013 → 15 Nov. 2013 http://trust.csu.edu.cn/conference/tsp2013/ |
Publikationsreihe
Name | Proceedings - 2013 IEEE International Conference on High Performance Computing and Communications, HPCC 2013 and 2013 IEEE International Conference on Embedded and Ubiquitous Computing, EUC 2013 |
---|
Konferenz
Konferenz | Fourth IEEE International Symposium on Trust, Security, and Privacy |
---|---|
Land/Gebiet | China |
Ort | Zhangjiajie, China |
Zeitraum | 13.11.2013 → 15.11.2013 |
Internetadresse |