Using asynchronous collaborative attestation to build a trusted computing environment for mobile applications
Lei Zhou, Fengwei Zhang, Guojun Wang · 2017
Nowadays, mobile applications like mobile payments become more popular in public life, but users are eager to acquire a trusted execution system to protect its secrets. This paper presents the design, implementation, and evaluation of the Trusted Computing Environment for the Mobile Application, which protects the integrity and confidentiality of the software from the risk of untrusted mobile platform. The mechanism based on TrustZone and non-interactive verifiable computing provides the Asynchronous Collaborative Attestation Mechanism (ACAM) to runtime attest the active system. TrustZone is a strong hardware-feature based isolated execution technique, but it can not defend against the timing attacking. ACAM can effective prevent this kinds of risk by asynchronous remote attestation and reduces the overhead from real-time protection. The security analysis and evaluation shows that the approach has major potential in mobile trusted computing system and provides a higher secure level environment for mobile users.