首页> 外文会议>2015 IEEE/ACM 1st International Workshop on Software Protection >Using Virtual Machine Protections to Enhance Whitebox Cryptography
【24h】

Using Virtual Machine Protections to Enhance Whitebox Cryptography

机译:使用虚拟机保护来增强白盒加密

获取原文
获取原文并翻译 | 示例

摘要

Since attackers can gain full control of the mobile execution environment, they are able to examine the inputs, outputs, and, with the help of a disassembler/debugger the result of every intermediate computation a cryptographic algorithm carries out. Essentially, attackers have total visibility into the cryptographic operation. White box cryptography aims at protecting keys from disclosed in software implementation. With theoretically unbounded resources a determined attacker is able to recover any confidential keys and data. A strong white box cipher implementation as the cornerstone of security is essential for the overall security in mobile environments. Our goal is to provide an increased degree of protection given the constraints of a software-solution and the resource-constrained, hostile-host environments. We seek neither perfect protection nor long-term guarantees, but rather a practical level of protection to balance cost, security and usability. Regular software updates can be applied such that the protection will need to withstand a limited period of time. V-OS operates as a virtual machine (VM) within the native mobile operating system to provide a secure software environment within which to perform critical processes and computations for a mobile app.
机译:由于攻击者可以完全控制移动执行环境,因此他们可以检查输入,输出,并借助反汇编程序/调试器来进行每次中间计算的结果,从而执行加密算法。本质上,攻击者可以完全了解加密操作。白盒密码学旨在保护密钥免于在软件实现中公开。使用理论上不受限制的资源,坚定的攻击者能够恢复任何机密密钥和数据。强大的白盒密码实施作为安全性的基石对于移动环境中的整体安全性至关重要。考虑到软件解决方案和资源受限的敌对主机环境的限制,我们的目标是提供更高程度的保护。我们既不是寻求完美的保护也不是长期的保证,而是寻求一种实用的保护级别来平衡成本,安全性和可用性。可以应用定期的软件更新,以使保护需要承受一段有限的时间。 V-OS在本机移动操作系统中充当虚拟机(VM),以提供一个安全的软件环境,在其中可以为移动应用程序执行关键过程和计算。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号