TrustPAY: Trusted mobile payment on security enhanced ARM TrustZone platforms

2016 
Recent technological advances have accelerated the design and deployment of kinds of secure applications on smartphones. Although users can access and handle their data flexibly and stably with mobile devices, not only computing devices, it poses security challenges of a new dimension that users disclose lots of sensitive data and privacy information over open devices and networks as well. Thus, more and more malwares are emerging to compromise mobile OS and steal sensitive data from these applications. In this paper, we propose a mobile payment framework TrustPAY on TrustZone security enhanced platform, which can ensure payment transactions security and realize privacy friendly payment. We have implemented a prototype system on a simulation environment by using ARM FastModel and Open Virtualization software stack for ARM TrustZone, and presented our implementation on a real development board by using ARM CoreTile Express A9×4. Our experiment evaluation and security analysis prove that our scheme can effectively meet the security requirements of a practical m-payment with acceptable performance. Furthermore, TrustPAY is also flexible to support kinds of secure applications requiring to privacy protection.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    8
    References
    10
    Citations
    NaN
    KQI
    []