DAA-TZ: An Ecient DAA Scheme for Mobile Devices using ARM TrustZone (Full Version) ?
Bo Yang, Kang Yang, Yu Qin, Zhenfeng Zhang, Dengguo Feng · 2015
Direct Anonymous Attestation (DAA) has been studied for applying to mobile devices based on ARM TrustZone. However, current solutions bring in extra performance overheads and security risks when adapting existing DAA schemes originally designed for PC platform. In this paper, we propose a complete and ecient DAA scheme (DAA-TZ) specically designed for mobile devices using TrustZone. By considering the application scenarios, DAA-TZ extends the interactive model of orig- inal DAA and provides anonymity for a device and its user against remote service providers. The proposed scheme requires only one-time switch of TrustZone for signing phase and elaborately takes pre-computation into account. Consequently, the frequent on-line signing just needs at most three exponentiations on elliptic curve. Moreover, we present the archi- tecture for trusted mobile devices. The issues about key derivation and sensitive data management relying on a root of trust from SRAM Physi- cal Unclonable Function (PUF) are discussed. We implement a prototype system and execute DAA-TZ using MNT and BN curves with dierent security levels. The comparison result and performance evaluation indi- cate that our scheme meets the demanding requirement of mobile users in respects of both security and eciency.