News / Events

DFIR Stream 0x7 

"Bringing User Sovereignty to Smartphones

by Dr. Shweta Shinde, ETH Zurich.

Abstract: Modern smartphones are complex systems where control over phone resources is exercised by phone manufacturers, operators, OS vendors, and users. These parties have diverse and often competing interests. Barring some exceptions, users, including developers, entrust their security and privacy to OS vendors (Android and iOS) and need to accept the constraints they impose. The manufacturers protect their firmware and peripherals from the OS by executing in the highest privilege and by leveraging dedicated CPUs and TEEs. OS vendors further try to protect their ecosystems by virtualization but still need to trust the highest privilege code deployed by manufacturers. This division of control over the phone is not ideal for OS vendors but is primarily disadvantageous for the users, who cannot freely install and isolate their applications, or flexibly configure their access to peripherals.

In this talk, Dr. Shinde presents a new smartphone architecture that maintains compatibility with the existing smartphone ecosystem but allows the balancing of the control over the phones. The proposed architecture, named TEEtime implements novel TEE-based mechanisms that allow the users to flexibly choose which resources (including peripherals) to dedicate to different isolated domains to securely execute applications.

About the Speaker

Dr. Shweta Shinde is an assistant professor at the Computer Science Department in ETH Zurich, where she leads the Secure & Trustworthy Systems (SECTRS) group. She is a member of the Institute of Information Security and the ZISC Center.


Her research is broadly at the intersection of trusted computing, system security, and program analysis. Her group focuses on foundational aspects of confidential computing to protect phones, servers, and accelerators as well as practical aspects of building large systems.

Date and Time: Monday, April 22 · 4:00 – 5:00 pm (GMT+00:00) United Kingdom Time

Location:  Online (Pre-Registration is Required to Obtain the Meeting Link)

Event Registration Link:  https://forms.gle/M9wves6fCdRk2NsU7 

Online Registration Ends April 21 at 4:00 PM (GMT+00:00) United Kingdom Time

Recording

Visit Us On Social Media:

Subscribe to our Facebook Group
Follow Us On Twitter
Like our Facebook Page