现实世界中的安全构成:用当代设备经济学解决移动安全问题

Jon A. Geater
{"title":"现实世界中的安全构成:用当代设备经济学解决移动安全问题","authors":"Jon A. Geater","doi":"10.1145/2516760.2516761","DOIUrl":null,"url":null,"abstract":"In a very short space of time consumer mobile devices have changed the way we live and work, resulting in huge amounts of sensitive data -- personal and corporate -- flowing through these tiny devices. As the value of data on these devices grows so do the threats they face, and the unique way the mobile industry works presents many challenges to achieving verifiable security while enabling an open ecosystem. Modern mobile devices are complex composed systems made up of multiple off-the-shelf components in hardware (SoC, GPU, memories), software (OS, drivers, applications) and firmware (boot stack). The devices have a relatively short life and are updated/replaced at a very fast pace, meaning that development, test and maintenance cycles are very short and major components frequently change from generation to generation. Achieving and maintaining whole system security in this scenario is extremely difficult. This keynote introduces some of the past and near future hardware assisted mobile security techniques and highlights some of the key areas of research needed to improve quality and confidence in the security of applications in these fast-evolving composed systems.","PeriodicalId":213305,"journal":{"name":"Security and Privacy in Smartphones and Mobile Devices","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-11-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Security composition in the real world: squaring the circle of mobile security with contemporary device economics\",\"authors\":\"Jon A. Geater\",\"doi\":\"10.1145/2516760.2516761\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In a very short space of time consumer mobile devices have changed the way we live and work, resulting in huge amounts of sensitive data -- personal and corporate -- flowing through these tiny devices. As the value of data on these devices grows so do the threats they face, and the unique way the mobile industry works presents many challenges to achieving verifiable security while enabling an open ecosystem. Modern mobile devices are complex composed systems made up of multiple off-the-shelf components in hardware (SoC, GPU, memories), software (OS, drivers, applications) and firmware (boot stack). The devices have a relatively short life and are updated/replaced at a very fast pace, meaning that development, test and maintenance cycles are very short and major components frequently change from generation to generation. Achieving and maintaining whole system security in this scenario is extremely difficult. This keynote introduces some of the past and near future hardware assisted mobile security techniques and highlights some of the key areas of research needed to improve quality and confidence in the security of applications in these fast-evolving composed systems.\",\"PeriodicalId\":213305,\"journal\":{\"name\":\"Security and Privacy in Smartphones and Mobile Devices\",\"volume\":\"4 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-11-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Security and Privacy in Smartphones and Mobile Devices\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/2516760.2516761\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Security and Privacy in Smartphones and Mobile Devices","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2516760.2516761","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

在很短的时间内,消费者移动设备改变了我们的生活和工作方式,导致大量的敏感数据——个人和企业数据——通过这些微小的设备流动。随着这些设备上的数据价值的增长,它们面临的威胁也在增加,移动行业独特的工作方式为实现可验证的安全性提出了许多挑战,同时实现开放的生态系统。现代移动设备是由硬件(SoC、GPU、内存)、软件(操作系统、驱动程序、应用程序)和固件(引导堆栈)中的多个现成组件组成的复杂系统。这些设备的使用寿命相对较短,更新/更换的速度非常快,这意味着开发、测试和维护周期非常短,主要组件经常代代更迭。在这种情况下实现和维护整个系统的安全性是极其困难的。本主题介绍了一些过去和不久的将来的硬件辅助移动安全技术,并强调了在这些快速发展的组合系统中提高应用程序安全性的质量和信心所需的一些关键研究领域。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Security composition in the real world: squaring the circle of mobile security with contemporary device economics
In a very short space of time consumer mobile devices have changed the way we live and work, resulting in huge amounts of sensitive data -- personal and corporate -- flowing through these tiny devices. As the value of data on these devices grows so do the threats they face, and the unique way the mobile industry works presents many challenges to achieving verifiable security while enabling an open ecosystem. Modern mobile devices are complex composed systems made up of multiple off-the-shelf components in hardware (SoC, GPU, memories), software (OS, drivers, applications) and firmware (boot stack). The devices have a relatively short life and are updated/replaced at a very fast pace, meaning that development, test and maintenance cycles are very short and major components frequently change from generation to generation. Achieving and maintaining whole system security in this scenario is extremely difficult. This keynote introduces some of the past and near future hardware assisted mobile security techniques and highlights some of the key areas of research needed to improve quality and confidence in the security of applications in these fast-evolving composed systems.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信