The emergence of mobile applications to execute sensitive operations has brought a myriad of security threats to both enterprises and users. In order to benefit from the large potential in smartphones there is a need to manage the risks arising from threats, while maintaining an easy interface for the users. In this paper we investigate the use of Trusted Platform Model (TPM) 2.0 to develop a secure application for smartphones using Windows Phone 8.1. In particular, we suggest a framework based on remote attestation as a proxy to authenticate remote services, where the device is associated to the user and replaces the users credentials. In addition, we use the TPM 2.0 to enable secured information and data storage within the device itself. We present an implementation and performance evaluation of the suggested architecture that uses our novel attestation and authentication scheme and reveal the caveats of using software TPM in todays mobile devices.
翻译:实施敏感操作的移动应用程序的出现给企业和用户带来了各种各样的安全威胁。为了从智能手机的巨大潜力中获益,有必要管理威胁带来的风险,同时保持用户的简易界面。在本文件中,我们调查了使用信任平台模型(TPM)2.0开发智能手机使用Windows Phone 8.1的安全应用程序的情况。特别是,我们建议建立一个基于远程验证的框架,作为认证远程服务的代理,该设备与用户相关联,并取代用户证书。此外,我们使用TPM 2.0来保证该设备本身的安全信息和数据存储。我们介绍了拟议架构的实施和绩效评估,该架构使用我们的新证明和认证计划,并揭示了当今移动设备使用软件TPM的洞察力。