Published November 11, 2021 | Version v1

Andromeda: Enabling Secure Enclaves For The Android Ecosystem

  • 1. FORTH-ICS
  • 2. Technical University of Crete

Description

The Android OS is currently used in a plethora of devices that play a core part of our everyday life, such as mobile phones, tablets, smart home appliances, entertainment systems and embedded devices. The majority of these devices typically process and store a vast amount of security-critical and privacy-sensitive data, including personal contacts, financial accounts and high-profile enterprise assets. The importance of these data makes these devices valuable attack targets.

In this paper we propose Andromeda, a framework that provides secure enclaves for Android OS to mitigate attacks that target sensitive or critical code, data and communication channels. Andromeda offers the first SGX interface for Android OS (to the best of our knowledge), as well as services that enhance its security and offer protection schemes for several applications that deal with sensitive or secret data. Andromeda is also able to securely execute SGX-enabled code on behalf of external devices that are not equipped with SGX-capable CPUs. Moreover, Andromeda protects cryptographic keys from memory dump attacks with less than 16% overhead on the corresponding cryptographic operations and provides secure, end-to-end encrypted, communication and computation channels for external devices paired with the Android device.

Files

paper.pdf

Files (329.4 kB)

Name Size Download all
md5:0ec5d23004157a41357d61e817ba1f86
329.4 kB Preview Download

Additional details

Funding

European Commission
C4IIoT - Cyber security 4.0: protecting the Industrial Internet Of Things 833828