How to Secure Mobile IDs on Any Smartphone

420 views
•
April 15, 2014
by
RSAC Cybersecurity
YouTube video player
How to Secure Mobile IDs on Any Smartphone

TL;DR

A mobile identity strategy should establish a trusted path between each device and its back-end cloud services while protecting credentials and cryptographic keys with standardized secure technologies. GlobalPlatform specifications give applications common interfaces to trusted execution environments and hardware secure elements, helping service providers deploy, support, and manage sensitive applications across different handsets and secure-element form factors.

Transcript

Thank you and good afternoon. My name is Kevin Gillick, and I'm the executive director of an industry specification development body known as GlobalPlatform. How many people here have any knowledge of GlobalPlatform as an organization? Ah, very few. Okay. So hopefully you'll walk away from this twenty minutes that we share with a little bit of unde... Read More

Key Insights

  • Higher-value mobile applications require stronger trust because payment, authentication, and identity information must be protected for both users and service providers. Applications with lower security requirements do not demand the same safeguards as services that hold valuable credentials or authorize consequential transactions.
  • Security and convenience are competing forces in mobile deployment because adding protective layers can reduce ease of use and make a service less desirable. A sound strategy must manage this trade-off while recognizing that richer mobile applications create more incentives for malware and other malicious behavior.
  • A trusted path is the protected space between a user’s device and the service provider’s back-room cloud systems. GlobalPlatform presents this end-to-end path as an essential foundation for deploying mobile services securely across any handset included in an organization’s strategy.
  • A rich operating system provides flexibility, storage, and extensive user-interface capabilities, but it is comparatively porous and weak at preventing attacks. Passing critical information through that environment alone is risky, so sensitive services benefit from protected components operating alongside or beneath it.
  • A trusted execution environment is a secure processor area that stores, processes, and protects data alongside but independently of the rich operating system. It offers less functionality than the open operating system but provides greater protection for sensitive activity and communication with a secure element.
  • A secure element is tamper-resistant hardware, typically implemented as a secure chip microcontroller. It offers limited functionality but highly hardened protection for credentials and cryptographic keys. Calling cloud functionality a secure element misuses the term because the definition presented here specifically refers to hardware.
  • GlobalPlatform specifications make secure elements functionally consistent across embedded chips, removable UICC or SIM implementations, and smart microSD cards. Applications built against the standardized APIs can therefore behave consistently regardless of which supported hardware form factor is installed in a handset.
  • Standardized secure platforms reduce device-specific dependencies because a service provider can create and manage one application without advance knowledge of the handset manufacturer or underlying secure chipset. This uniformity supports interoperability, future-proofing, lower market-entry costs, and access to a broader potential device market.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations secure mobile identity services?

Organizations can secure mobile identity services by establishing a trusted path between the user’s handset and the service provider’s back-room cloud systems. Sensitive processing and storage should use protected device technologies rather than relying exclusively on the porous rich operating system. Standardized trusted execution environments and hardware secure elements can protect identity data, credentials, and cryptographic keys while supporting consistent application deployment and lifecycle management.

Q: What is a trusted path in a mobile strategy?

A trusted path covers everything between the device held by the user and the services operating in the back room or cloud. It provides the security foundation for information and operations traveling between those endpoints. GlobalPlatform treats this protected path as an underpinning of a sound mobile strategy, including strategies intended to work across different handset manufacturers and underlying secure hardware implementations.

Q: Why is a rich mobile operating system insufficient for sensitive applications?

A rich mobile operating system offers flexibility, substantial memory and storage, and strong user-interface capabilities, but it is also a porous operational environment that is not very effective at preventing attacks. Sending critical information through that layer alone creates risk. Payment, identity, and authentication applications therefore need stronger protection from components such as trusted execution environments and secure elements.

Q: What is a trusted execution environment on a smartphone?

A trusted execution environment, or TEE, is a secure area of a processor within a mobile handset. It stores, processes, and protects data in a trusted environment that operates alongside but independently of the rich operating system. It provides less general functionality than the open operating system but offers greater protection for sensitive handset operations and communication with a secure element.

Q: What is a secure element in a mobile device?

A secure element is a tamper-resistant hardware platform, typically a secure chip microcontroller. It has limited functionality but provides highly hardened security for assets such as credentials and cryptographic keys. It may appear as an embedded chipset, a removable UICC or SIM, or a smart microSD card. The term does not properly describe cloud functionality because a secure element is hardware.

Q: How do standards support applications across different smartphones?

Standards provide common APIs, interfaces, and functionality for protected device technologies. An outside service provider can build a payment, identity, or authentication application against GlobalPlatform specifications and expect it to behave consistently across supported secure-element implementations. The provider does not need advance knowledge of whether the handset comes from Samsung, Huawei, Motorola, or uses embedded, removable, or microSD-based secure hardware.

Q: Why must mobile security balance protection and convenience?

Stronger security can add steps or constraints that reduce convenience for the end user, potentially making a product or service less desirable. At the same time, payment, authentication, and identity applications require greater protection because they carry more value and invite more malicious behavior. A mobile strategy must therefore raise trust and security while managing the effect those safeguards have on usability.

Q: What benefits does GlobalPlatform offer mobile service providers?

GlobalPlatform standardizes the management of applications on trusted execution environments and secure elements. Its specifications help providers create, provision, support, and lifecycle-manage a protected application in a common way across different handsets and hardware form factors. This approach can reduce market-entry costs, improve interoperability, support future-proofing, and make a broader device market addressable without requiring separate implementations for every platform.

Summary & Key Takeaways

  • Mobile applications are expanding from relatively low-risk conveniences into payment, authentication, and identity services that carry greater value. This shift attracts more malicious activity and requires stronger safeguards. A successful mobile strategy must therefore increase trust without making services so inconvenient that users find the resulting products less desirable.

  • Smartphones provide three relevant technology layers: a flexible but porous rich operating system, a more protected trusted execution environment, and a highly hardened hardware secure element. The TEE can protect stored and processed data independently of the rich operating system, while the secure element protects credentials, cryptographic keys, and similarly sensitive assets.

  • GlobalPlatform standardizes application management for trusted execution environments and secure elements rather than the rich operating system. Its specifications give different hardware implementations common interfaces and functionality. Consequently, service providers can develop, provision, support, and manage a protected application consistently without knowing the handset manufacturer or secure-element form factor in advance.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚