【24h】

When Users Cannot Verify Digital Signatures: On the Difficulties of Securing Mobile Devices

机译:当用户无法验证数字签名时:关于保护移动设备的困难

获取原文
获取原文并翻译 | 示例

摘要

Mobile devices such as smart phones have become one of the preferred means of accessing digital services, both for consuming and creating content. Unfortunately, securing such mobile devices is inherently difficult for a number of reasons. In this paper, we systematically analyze the technical issues of securing mobile device platforms against different threats and discuss a resulting and currently unsolved problem: how to create an end-to-end secure channel between the digital service (e.g. a secure wallet application on an embedded smart card or an infrastructure service connected over wireless media) and the user. Although the problem has been known for years and technical approaches start appearing in products, the user interaction aspects have remained unsolved. We discuss the reasons for this difficulty and suggest potential approaches to create human-verifiable secure communication with components or services within partially untrusted devices.
机译:诸如智能电话之类的移动设备已成为访问数字服务的首选方式之一,以消费和创建内容。不幸的是,出于多种原因,保护这种移动设备固有地困难。在本文中,我们系统地分析了保护移动设备平台免受不同威胁的技术问题,并讨论了由此产生的和当前尚未解决的问题:如何在数字服务之间创建端到端的安全通道(例如,嵌入式智能卡或通过无线媒体连接的基础结构服务)和用户。尽管这个问题已经知道多年,并且技术方法开始出现在产品中,但是用户交互方面仍未解决。我们讨论了造成这种困难的原因,并提出了可能的方法来与部分不受信任的设备中的组件或服务创建可验证的安全人类通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号