{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T09:46:39Z","timestamp":1780479999867,"version":"3.54.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319788128","type":"print"},{"value":"9783319788135","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78813-5_30","type":"book-chapter","created":{"date-parts":[[2018,4,10]],"date-time":"2018-04-10T10:03:21Z","timestamp":1523354601000},"page":"585-605","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["An Efficient Trustzone-Based In-application Isolation Schema for\u00a0Mobile Authenticators"],"prefix":"10.1007","author":[{"given":"Yingjun","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Qin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dengguo","family":"Feng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weijin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,4,11]]},"reference":[{"key":"30_CR1","unstructured":"How to root my android device using vroot. \nhttp:\/\/www.androidxda.com\/download-vroot"},{"key":"30_CR2","unstructured":"Poc of private key leakage using heartbleed. \nhttps:\/\/github.com\/einaros\/heartbleed-tools"},{"key":"30_CR3","unstructured":"Tiqr. \nhttp:\/\/www.rcdevs.com\/downloads\/download\/1\/Utils\/rcdevs_libs-1.0.15.tgz"},{"key":"30_CR4","unstructured":"Vmware: Vulnerability statistics. \nhttp:\/\/www.cvedetails.com\/vendor\/252\/Vmware.html"},{"key":"30_CR5","unstructured":"Xen: Vulnerability statistics. \nhttp:\/\/www.cvedetails.com\/vendor\/6276\/XEN.html"},{"key":"30_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1007\/978-3-662-45472-5_24","volume-title":"Financial Cryptography and Data Security","author":"A Dmitrienko","year":"2014","unstructured":"Dmitrienko, A., Liebchen, C., Rossow, C., Sadeghi, A.-R.: On the (in)security of mobile two-factor authentication. In: Christin, N., Safavi-Naini, R. (eds.) FC 2014. LNCS, vol. 8437, pp. 365\u2013383. Springer, Heidelberg (2014). \nhttps:\/\/doi.org\/10.1007\/978-3-662-45472-5_24"},{"key":"30_CR7","unstructured":"ARM: Building a secure system using TrustZone (2009). \nhttp:\/\/www.arm.com"},{"key":"30_CR8","unstructured":"ARM: Securing the Future of Authentication with ARM TrustZone-based Trusted Execution Environment and Fast Identity Online (FIDO) (2015). \nhttps:\/\/www.arm.com\/files\/pdf\/TrustZone-and-FIDO-white-paper.pdf"},{"key":"30_CR9","doi-asserted-by":"crossref","unstructured":"Azab, A., Ning, P., Shah, J., Chen, Q., Bhutkar, R.: Hypervision across worlds: real-time kernel protection from the arm trustzone secure world. In: Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS 2014) (2014)","DOI":"10.1145\/2660267.2660350"},{"key":"30_CR10","unstructured":"Brumley, D., Song, D.: Privtrans: automatically partitioning programs for privilege separation. In: Proceedings of the 13th Conference on USENIX Security Symposium (2004)"},{"key":"30_CR11","doi-asserted-by":"crossref","unstructured":"Checkoway, S., Shacham, H.: Iago attacks: why the system call API is a bad untrusted RPC interface. In: The 18th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 2013) (2013)","DOI":"10.1145\/2451116.2451145"},{"key":"30_CR12","doi-asserted-by":"crossref","unstructured":"Chen, X., et al.: Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems. In: The 13th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 2008) (2008)","DOI":"10.1145\/1346281.1346284"},{"key":"30_CR13","unstructured":"Gonzalez, J.: Open Virtulization for Xilinxs ZC-702. \nhttps:\/\/github.com\/javigon\/OpenVirtulization"},{"key":"30_CR14","unstructured":"Google: Google Authenticator. \nhttps:\/\/github.com\/google\/google-authenticator-libpam"},{"key":"30_CR15","unstructured":"Chen, H., Zhang, F., Chen, C., Yang, Z., Chen, R., Zang, B., Mao, W.: Tamper-resistant execution in an untrusted operating system using a virtual machine monitor. In: Report FDUPPITR-2007-0801, Parallel Processing Institute, Fudan University, August 2007"},{"key":"30_CR16","doi-asserted-by":"crossref","unstructured":"Sun, H., Sun, K., Wang, Y., Jing, J.: TrustICE: hardware-assisted isolated computing environments on mobile devices. In: International Conference on Dependable Systems and Networks (DSN 2015) (2015)","DOI":"10.1109\/DSN.2015.11"},{"key":"30_CR17","doi-asserted-by":"crossref","unstructured":"Sun, H., Sun, K., Wang, Y., Jing, J.: TrustOTP: transforming smartphones into secure one-time password tokens. In: Proceedings of the 22th ACM Conference on Computer and Communications Security (CCS 2015) (2015)","DOI":"10.1145\/2810103.2813692"},{"key":"30_CR18","doi-asserted-by":"crossref","unstructured":"Hofmann, O., Kim, S., Dunn, A., Lee, M., Witchel, E.: InkTag: secure applications on an untrusted operating system. In: the 18th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 2013) (2013)","DOI":"10.1145\/2451116.2451146"},{"key":"30_CR19","doi-asserted-by":"crossref","unstructured":"Mccune, J.M., Parno, B., Perrig, A., et al.: Flicker: an execution infrastructure for TCB minimization. In: EuroSys (2008)","DOI":"10.1145\/1352592.1352625"},{"key":"30_CR20","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Li, Y., Qu, N., et al.: Trustvisor: efficient TCB reduction and attestation. In: Proceedings of the 31st IEEE Symposium on Security and Privacy (2010)","DOI":"10.1109\/SP.2010.17"},{"key":"30_CR21","doi-asserted-by":"crossref","unstructured":"Jang, J., et al.: SeCReT: secure channel between rich execution environment and trusted execution environment. In: Proceedings of the Network and Distributed System Security Symposium (NDSS 2015) (2015)","DOI":"10.14722\/ndss.2015.23189"},{"key":"30_CR22","unstructured":"Keltner, N.: Here be dragons: vulnerabilities in trustzone (2014). \nhttps:\/\/atredispartners.blogspot.com\/2014\/08\/here-be-dragons-vulnerabilities-in.html"},{"key":"30_CR23","doi-asserted-by":"crossref","unstructured":"Kostiainen, K., Ekberg, J., Asokan, N., Rantala, A.: On-board credentials with open provisioning. In: Proceedings of the International Symposium on Information, Computer, and Communications Security (2009)","DOI":"10.1145\/1533057.1533074"},{"key":"30_CR24","doi-asserted-by":"crossref","unstructured":"Guan, L., Liu, P., Xing, X., et al.: TrustShadow: secure execution of unmodified applications with ARM trustZone. In: Proceedings of the 15th ACM International Conference on Mobile Systems, Applications, and Services (MobiSys 2017) (2017)","DOI":"10.1145\/3081333.3081349"},{"key":"30_CR25","unstructured":"Rosculete, L., Rosculete, L., Mitra, T., et al.: Automated partitioning of android applications for trusted execution environments. In: Proceedings of the International Conference on Software Engineering (ICSE 2016) (2016)"},{"key":"30_CR26","unstructured":"laginimaineb: Bits, please! (2016). \nhttps:\/\/bits-please.blogspot.com\/"},{"key":"30_CR27","doi-asserted-by":"crossref","unstructured":"Marforio, C., et al.: Smartphones as practical and secure location verification tokens for payments. In: Proceedings of the Network and Distributed System Security Symposium (NDSS 2014) (2014)","DOI":"10.14722\/ndss.2014.23165"},{"key":"30_CR28","unstructured":"Lindemann, R., Hill, D.B., Tiffany, E.: FIDO UAF Protocol Specification v1.0 (2014). \nhttps:\/\/fidoalliance.org\/specs\/fido-uaf-v1.0-ps-20141208\/fido-uaf-protocol-v1.0-ps-20141208.html"},{"key":"30_CR29","unstructured":"Roland, M.: Applying recent secure element relay attack scenarios to the real world: Google Wallet Relay Attack (2013)"},{"key":"30_CR30","unstructured":"Rosenberg, D.: Reflections on trusting trustzone. In: BlackHat USA (2014)"},{"key":"30_CR31","unstructured":"Rosenberg, D.: QSEE trustzone kernel integer over flow vulnerability. In: Black Hat Conference (2014)"},{"key":"30_CR32","doi-asserted-by":"crossref","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS 2007) (2007)","DOI":"10.1145\/1315245.1315313"},{"key":"30_CR33","unstructured":"Shen, D.: Attacking your trusted core, exploiting trustzone on android. In: BlackHat USA (2015)"},{"key":"30_CR34","unstructured":"Xilinx: Zynq-7000 all programmable SOC ZC702 evaluation kit. \nhttp:\/\/www.xilinx.com\/products\/boards-and-kits\/EK-Z7-ZC702-G.htm"},{"key":"30_CR35","doi-asserted-by":"crossref","unstructured":"Liu, Y., Zhou, T., Chen, K., et al.: Thwarting memory disclosure with efficient hypervisor-enforced intra-domain isolation. In: Proceedings of the 22th ACM Conference on Computer and Communications Security (CCS 2015) (2015)","DOI":"10.1145\/2810103.2813690"},{"key":"30_CR36","doi-asserted-by":"crossref","unstructured":"Wu, Y., Sun, J., Liu, Y., Dong, J.S.: Automatically partition software into least privilege components using dynamic data dependency analysis. In: Proceedings of the 28th International Conference on Automated Software Engineering (ASE 2013) (2013)","DOI":"10.1109\/ASE.2013.6693091"},{"key":"30_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Zhao, S., Qin, Y., et al.: TrustTokenF: a generic security framework for mobile two-factor authentication using trustzone. In: Proceedings of the 14th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2015) (2015)","DOI":"10.1109\/Trustcom.2015.355"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78813-5_30","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,4,10]],"date-time":"2018-04-10T10:20:56Z","timestamp":1523355656000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78813-5_30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788128","9783319788135"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78813-5_30","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}