198 Software Networks
As we have seen, software security is not costly, but in general it is
not very high level. It is often possible for a very good attacker to
retrieve a copy and be able to find a certain number of keys. For this
reason, it is usual to try and associate a hardware element with the
keys. The other end of the security scale is to always have a hardware
element to contain keys or important security elements, which can
even facilitate the execution of algorithms within the safe box. An
intermediary solution, which requires a certain amount of additional
explanation, is available on the market today: the TEE (Trusted
Execution Environment).
The TEE is a secure zone within the main processor of a
smartphone or tablet or any other mobile device, which ensures that
sensitive data are stored, processed and protected in a confidential
environment. The ability of the TEE to provide safe execution of the
authorized security programs, known as “trusted applications”, means
it can provide end-to-end security by imposing protection,
confidentiality, integrity and access rights on the data.
Smartphone manufacturers and chip manufacturers have developed
versions of this technology and built them into their devices as part of
their proprietary solution. Thus, application developers need to deal
with the complexity of the secure creation and evaluation of the
different versions of each application in order to conform to the
different sets of specifications and security levels established by each
individual proprietary solution.
The first solution to use the TEE is to attach to it a local secure
element such as a smartcard, which is found on numerous mobile
terminals. The smartcard serves to accommodate the secure part of the
applications. The difficulty is in installing several independent
applications and being able to modify them, remove them and add
new ones with a high level of security. For this purpose, the TSM
solution was developed. We shall discuss this solution in the next
section.
www.it-ebooks.info
As we have seen, software security is not costly, but in general it is
not very high level. It is often possible for a very good attacker to
retrieve a copy and be able to find a certain number of keys. For this
reason, it is usual to try and associate a hardware element with the
keys. The other end of the security scale is to always have a hardware
element to contain keys or important security elements, which can
even facilitate the execution of algorithms within the safe box. An
intermediary solution, which requires a certain amount of additional
explanation, is available on the market today: the TEE (Trusted
Execution Environment).
The TEE is a secure zone within the main processor of a
smartphone or tablet or any other mobile device, which ensures that
sensitive data are stored, processed and protected in a confidential
environment. The ability of the TEE to provide safe execution of the
authorized security programs, known as “trusted applications”, means
it can provide end-to-end security by imposing protection,
confidentiality, integrity and access rights on the data.
Smartphone manufacturers and chip manufacturers have developed
versions of this technology and built them into their devices as part of
their proprietary solution. Thus, application developers need to deal
with the complexity of the secure creation and evaluation of the
different versions of each application in order to conform to the
different sets of specifications and security levels established by each
individual proprietary solution.
The first solution to use the TEE is to attach to it a local secure
element such as a smartcard, which is found on numerous mobile
terminals. The smartcard serves to accommodate the secure part of the
applications. The difficulty is in installing several independent
applications and being able to modify them, remove them and add
new ones with a high level of security. For this purpose, the TSM
solution was developed. We shall discuss this solution in the next
section.
www.it-ebooks.info
