【24h】

Security analysis of Samsung Knox

机译:三星Knox的安全性分析

获取原文

摘要

A Trusted Execution Environment (TEE) has become popular in the mobile industry. Hardware-based security will be employed by default for every mobile device within a few years. In this paper, we explore several potential security issues of the Samsung Knox platform that is one of the advanced hardware based mobile security platforms for Android devices. We describe several attack scenarios to show how the Knox platform can be compromised. We particularly performed experiments for Man in the Middle Attacks with an untrusted certificate. To mitigate such security risks, we also recommend several countermeasures based on fundamental security principles. For example, security-sensitive resources in Knox should be strictly isolated from processes in an insecure operating system.
机译:可信执行环境(TEE)在移动行业中已变得越来越流行。默认情况下,将在几年内为每台移动设备采用基于硬件的安全性。在本文中,我们探讨了三星Knox平台的几个潜在安全问题,该平台是用于Android设备的基于硬件的高级移动安全平台之一。我们描述了几种攻击情形,以展示如何破坏Knox平台。我们特别为带有不可信证书的“中间人攻击”进行了实验。为了减轻此类安全风险,我们还建议基于基本安全原则的几种对策。例如,应严格将Knox中对安全敏感的资源与不安全的操作系统中的进程隔离。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号