• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类
Advanced Search
Zhang Yingjun, Feng Dengguo, Qin Yu, Yang Bo. A TrustZone Based Application Protection Scheme in Highly Open Scenarios[J]. Journal of Computer Research and Development, 2017, 54(10): 2268-2283. DOI: 10.7544/issn1000-1239.2017.20170387
Citation: Zhang Yingjun, Feng Dengguo, Qin Yu, Yang Bo. A TrustZone Based Application Protection Scheme in Highly Open Scenarios[J]. Journal of Computer Research and Development, 2017, 54(10): 2268-2283. DOI: 10.7544/issn1000-1239.2017.20170387

A TrustZone Based Application Protection Scheme in Highly Open Scenarios

More Information
  • Published Date: September 30, 2017
  • We propose a protection scheme for security-sensitive applications on mobile embedded devices, which is focus on the scenarios with both strong security and high openness requirements, such as “bring your own device”, mobile cloud computing. To meet the security requirements, we leverage the trusted execution environment of ARM TrustZone to provide strong isolation guarantees for applications even in the presence of a malicious operating system. To meet the openness requirements, our scheme has two major advantages compared with previous TrustZone-based solutions. Firstly, it moves concrete sensitive applications from TrustZone secure world to the normal world, so that the trusted computing base keeps small and unchanged regardless of the amount of supported security applications. Secondly, it leverages a light-weight kernel monitor in the secure world to enforce the untrusted operating system to serve these security applications legally, so that they could securely use standard system calls, which could provide critical features for the openness requirements, such as dynamic application deployment. We also propose proactive attestation, a novel technique that greatly improves the system efficiency by enforcing the operating system to contribute to its own verification. We implement the prototype system on real TrustZone devices. The experiment results show that our scheme is practical with acceptable performance overhead.

Catalog

    Article views (1734) PDF downloads (558) Cited by()
    Turn off MathJax
    Article Contents

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return