DocumentCode
737287
Title
TrustICE: Hardware-Assisted Isolated Computing Environments on Mobile Devices
Author
Sun, He ; Sun, Kun ; Wang, Yuewu ; Jing, Jiwu ; Wang, Haining
fYear
2015
fDate
22-25 June 2015
Firstpage
367
Lastpage
378
Abstract
Mobile devices have been widely used to process sensitive data and perform important transactions. It is a challenge to protect secure code from a malicious mobile OS. ARM TrustZone technology can protect secure code in a secure domain from an untrusted normal domain. However, since the attack surface of the secure domain will increase along with the size of secure code, it becomes arduous to negotiate with OEMs to get new secure code installed. We propose a novel TrustZone-based isolation framework named TrustICE to create isolated computing environments (ICEs) in the normal domain. TrustICE securely isolates the secure code in an ICE from an untrusted Rich OS in the normal domain. The trusted computing base (TCB) of TrustICE remains small and unchanged regardless of the amount of secure code being protected. Our prototype shows that the switching time between an ICE and the Rich OS is less than 12 ms.
Keywords
Ice; Mobile handsets; Program processors; Random access memory; Read only memory; Switches; Watermarking; Computing Environment; Isolation; TrustZone;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks (DSN), 2015 45th Annual IEEE/IFIP International Conference on
Conference_Location
Rio de Janeiro, Brazil
Type
conf
DOI
10.1109/DSN.2015.11
Filename
7266865
Link To Document