首页> 外文会议>International conference on smart card research and advanced applications >seTPM: Towards Flexible Trusted Computing on Mobile Devices Based on GlobalPlatform Secure Elements
【24h】

seTPM: Towards Flexible Trusted Computing on Mobile Devices Based on GlobalPlatform Secure Elements

机译:seTPM:基于GlobalPlatform安全元素的移动设备上的灵活可信计算

获取原文

摘要

Insufficiently protected mobile devices present a ubiquitous threat. Due to severe hardware constraints, such as limited printed circuit board area, hardware-based security as proposed by the Trusted Computing Group is usually not part of mobile devices, yet. We present the design and implementation of seTPM, a secure element based TPM, utilizing Java Card technology. seTPM establishes trust in mobile devices by enabling Trusted Computing based integrity measurement services, such as IMA for Linux. Our prototype emulates TPM functionality on a GlobalPlatform secure element, which allows seamless integration into the Trusted Software Stack of Linux-based mobile operating systems like Android. With our work, we provide a solution to run Trusted Computing based security protocols while supplying a similar security level as provided by hardware TPM chips. In addition, due to the flexible design of the seTPM, we further increase the security level as we are able to selectively replace the outdated SHA-1 hash algorithm of TPM 1.2 specification by the present Keccak algorithm. Further, our architecture comprises hybrid support for the TPM 1.2 and TPM 2.0 specifications to simplify the transition towards the TPM 2.0 standard.
机译:保护不足的移动设备带来了普遍存在的威胁。由于严格的硬件限制,例如有限的印刷电路板面积,Trusted Computing Group提出的基于硬件的安全性通常还不是移动设备的一部分。我们介绍利用Java Card技术的seTPM(基于安全元素的TPM)的设计和实现。 seTPM通过启用基于Trusted Computing的完整性度量服务(例如用于Linux的IMA)来建立对移动设备的信任。我们的原型在GlobalPlatform安全元素上模拟TPM功能,从而可以无缝集成到基于Linux的移动操作系统(如Android)的可信软件堆栈中。通过我们的工作,我们提供了一种运行基于可信计算的安全协议的解决方案,同时提供了与硬件TPM芯片所提供的相似的安全级别。另外,由于seTPM的灵活设计,我们能够通过当前的Keccak算法选择性地替换TPM 1.2规范的过时SHA-1哈希算法,从而进一步提高了安全级别。此外,我们的体系结构包括对TPM 1.2和TPM 2.0规范的混合支持,以简化向TPM 2.0标准的过渡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号