DocumentCode
3116038
Title
Enhancing the Security of Mobile Applications by Using TEE and (U)SIM
Author
Ahmad, Zainal ; Francis, L. ; Ahmed, Toufik ; Lobodzinski, Christopher ; Audsin, Dev ; Peng Jiang
Author_Institution
Orange Labs. UK, London, UK
fYear
2013
fDate
18-21 Dec. 2013
Firstpage
575
Lastpage
582
Abstract
Mobile phone platforms are increasingly becoming vulnerable to security attacks and is untrusted to host security sensitive applications, content, and services. Open source mobile ecosystems such as Android allow increased flexibility for developing and deploying applications. However, there are industry-led initiatives to increase the security of mobile phone platforms by using virtualisation and hardware abstraction techniques. In this paper, we explore the potential of the recently introduced Trusted Execution Environment (TEE) ecosystem for mobile phones in order to compliment the security-proven (U)SIM based security functions. We present a security architecture and a novel mobile payment and multimedia content playback solution leveraging on the existing post-paid billing method. We integrate TEE with (U)SIM based security techniques to provide enhanced security for user authentication, content purchase, protected storage and secure content viewing.
Keywords
Android (operating system); mobile communication; security of data; smart phones; telecommunication security; virtualisation; (U)SIM; Android; TEE; Trusted Execution Environment ecosystem; content purchase; enhanced security; hardware abstraction techniques; mobile applications; mobile payment; multimedia content playback solution; open source mobile ecosystems; postpaid billing method; protected storage; secure content viewing; security architecture; security attacks; security sensitive applications; user authentication; virtualisation; Authentication; Cryptography; Mobile communication; Mobile handsets; Protocols; Servers; (U)SIM; Architecture; Digital Rights; Proof-of-concept; Secure PIN Entry; Security; Security Framework; TEE; Trusted Computing; Trustlet; UICC;
fLanguage
English
Publisher
ieee
Conference_Titel
Ubiquitous Intelligence and Computing, 2013 IEEE 10th International Conference on and 10th International Conference on Autonomic and Trusted Computing (UIC/ATC)
Conference_Location
Vietri sul Mere
Print_ISBN
978-1-4799-2481-3
Type
conf
DOI
10.1109/UIC-ATC.2013.76
Filename
6726262
Link To Document