SchrodinText: Strong Protection of Sensitive Textual Content of Mobile Applications
Nicholas Wei, Ardalan Amiri Sani · IEEE Transactions on Mobile Computing · 2020
Many mobile applications deliver and showsensitive and private textual contentto users including messages, social network posts, account information, and verification codes. All such textual content must be displayed to users but must be strongly protected from unauthorized access in mobile devices. Unfortunately, this is not the case in mobile devices today: malware that can compromise the OS can easily access textual content of other applications. We present SchrodinText, a system solution for strongly protecting the confidentiality of an application's selected UI textual content from a fully compromised OS. SchrodinText leverages a novel security monitor based on two hardware features on ARM processors: virtualization hardware and TrustZone. Our key contribution is a set of novel techniques that allow the OS to perform text rendering without needing access to the text itself, hence minimizing the trusted computing base (TCB). These techniques, collectively calledoblivious rendering, enable the OS to rasterize and lay out all the characters without access to the text; the monitorresolvesthe right character glyphs onto the framebufferobservedby the user and protects them from the OS. Using our prototypes, we show that SchrodinText incurs noticeable overhead but that its performance is usable.