• DocumentCode
    737287
  • Title

    TrustICE: Hardware-Assisted Isolated Computing Environments on Mobile Devices

  • Author

    Sun, He ; Sun, Kun ; Wang, Yuewu ; Jing, Jiwu ; Wang, Haining

  • fYear
    2015
  • fDate
    22-25 June 2015
  • Firstpage
    367
  • Lastpage
    378
  • Abstract
    Mobile devices have been widely used to process sensitive data and perform important transactions. It is a challenge to protect secure code from a malicious mobile OS. ARM TrustZone technology can protect secure code in a secure domain from an untrusted normal domain. However, since the attack surface of the secure domain will increase along with the size of secure code, it becomes arduous to negotiate with OEMs to get new secure code installed. We propose a novel TrustZone-based isolation framework named TrustICE to create isolated computing environments (ICEs) in the normal domain. TrustICE securely isolates the secure code in an ICE from an untrusted Rich OS in the normal domain. The trusted computing base (TCB) of TrustICE remains small and unchanged regardless of the amount of secure code being protected. Our prototype shows that the switching time between an ICE and the Rich OS is less than 12 ms.
  • Keywords
    Ice; Mobile handsets; Program processors; Random access memory; Read only memory; Switches; Watermarking; Computing Environment; Isolation; TrustZone;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks (DSN), 2015 45th Annual IEEE/IFIP International Conference on
  • Conference_Location
    Rio de Janeiro, Brazil
  • Type

    conf

  • DOI
    10.1109/DSN.2015.11
  • Filename
    7266865