Skip to search boxSkip to navigationSkip to main content

A Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices

  • Javier Gonzalez
    ,
  • Michael Hölzl
    ,
  • Peter Riedl
    ,
  • Philippe Bonnet
    ,
  • René Mayrhofer
  • ,
  • University of Applied Sciences Upper Austria
Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Open access

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 542-554 (13 pages)

Journal (Volume, Issue Number)

Lecture Notes in Computer Science (Volume 8783)

Publication milestones

  • Published - 2014

Publication status

Published - 2014

ISSN

0302-9743

Publication IDs

  • Scopus: 84921803748

Abstract

Current efforts to increase the security of the boot sequence for mobile devices fall into two main categories: (i) secure boot: where each stage in the boot sequence is evaluated, aborting the boot process if a non expected component attempts to be loaded; and (ii) trusted boot: where a log is maintained with the components that have been loaded in the boot process for later audit. The first approach is often criticized for locking down devices, thus reducing users’ freedom to choose software. The second lacks the mechanisms to enforce any form of run-time verification. In this paper, we present the architecture for a two-phase boot verification that addresses these shortcomings. In the first phase, at boot-time the integrity of the bootloader and OS images are verified and logged; in the second phase, at run-time applications can check the boot traces and verify that the running software satisfies their security requirements. This is a first step towards supporting usage control primitives for running applications. Our approach relies on off-the-shelf secure hardware that is available in a multitude of mobile devices: ARM TrustZone as a Trusted Execution Environment, and Secure Element as a tamper-resistant unit.

Publication metrics

PlumX, opens in new tab

Captures
38
Citations
8

Access to documents