Security composition in the real world: squaring the circle of mobile security with contemporary device economics

Jon A. Geater
{"title":"Security composition in the real world: squaring the circle of mobile security with contemporary device economics","authors":"Jon A. Geater","doi":"10.1145/2516760.2516761","DOIUrl":null,"url":null,"abstract":"In a very short space of time consumer mobile devices have changed the way we live and work, resulting in huge amounts of sensitive data -- personal and corporate -- flowing through these tiny devices. As the value of data on these devices grows so do the threats they face, and the unique way the mobile industry works presents many challenges to achieving verifiable security while enabling an open ecosystem. Modern mobile devices are complex composed systems made up of multiple off-the-shelf components in hardware (SoC, GPU, memories), software (OS, drivers, applications) and firmware (boot stack). The devices have a relatively short life and are updated/replaced at a very fast pace, meaning that development, test and maintenance cycles are very short and major components frequently change from generation to generation. Achieving and maintaining whole system security in this scenario is extremely difficult. This keynote introduces some of the past and near future hardware assisted mobile security techniques and highlights some of the key areas of research needed to improve quality and confidence in the security of applications in these fast-evolving composed systems.","PeriodicalId":213305,"journal":{"name":"Security and Privacy in Smartphones and Mobile Devices","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-11-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Security and Privacy in Smartphones and Mobile Devices","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2516760.2516761","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

In a very short space of time consumer mobile devices have changed the way we live and work, resulting in huge amounts of sensitive data -- personal and corporate -- flowing through these tiny devices. As the value of data on these devices grows so do the threats they face, and the unique way the mobile industry works presents many challenges to achieving verifiable security while enabling an open ecosystem. Modern mobile devices are complex composed systems made up of multiple off-the-shelf components in hardware (SoC, GPU, memories), software (OS, drivers, applications) and firmware (boot stack). The devices have a relatively short life and are updated/replaced at a very fast pace, meaning that development, test and maintenance cycles are very short and major components frequently change from generation to generation. Achieving and maintaining whole system security in this scenario is extremely difficult. This keynote introduces some of the past and near future hardware assisted mobile security techniques and highlights some of the key areas of research needed to improve quality and confidence in the security of applications in these fast-evolving composed systems.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
现实世界中的安全构成:用当代设备经济学解决移动安全问题
在很短的时间内,消费者移动设备改变了我们的生活和工作方式,导致大量的敏感数据——个人和企业数据——通过这些微小的设备流动。随着这些设备上的数据价值的增长,它们面临的威胁也在增加,移动行业独特的工作方式为实现可验证的安全性提出了许多挑战,同时实现开放的生态系统。现代移动设备是由硬件(SoC、GPU、内存)、软件(操作系统、驱动程序、应用程序)和固件(引导堆栈)中的多个现成组件组成的复杂系统。这些设备的使用寿命相对较短,更新/更换的速度非常快,这意味着开发、测试和维护周期非常短,主要组件经常代代更迭。在这种情况下实现和维护整个系统的安全性是极其困难的。本主题介绍了一些过去和不久的将来的硬件辅助移动安全技术,并强调了在这些快速发展的组合系统中提高应用程序安全性的质量和信心所需的一些关键研究领域。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Sound and precise malware analysis for android via pushdown reachability and entry-point saturation Deadbolt: locking down android disk encryption Secure enrollment and practical migration for mobile trusted execution environments Passwords and interfaces: towards creating stronger passwords by using mobile phone handsets Please slow down!: the impact on tor performance from mobility
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1