论文标题

Mobigyges:一种移动式隐藏卷,用于防止数据丢失,改善存储使用情况并避免重新启动设备

MobiGyges: A mobile hidden volume for preventing data loss, improving storage utilization, and avoiding device reboot

论文作者

Feng, Wendi, Liu, Chuanchang, Guo, Zehua, Baker, Thar, Wang, Gang, Wang, Meng, Cheng, Bo, Chen, Junliang

论文摘要

敏感的数据保护对于移动用户至关重要。合理的拒绝加密(PDE)系统提供了一种有效的方式来通过将敏感数据隐藏在设备上来保护敏感数据。但是,由于用于避免数据丢失的保留区域,现有的PDE系统可能会丢失数据,因此浪费物理存储,并且在使用隐藏卷时需要重新启动设备。本文介绍了基于隐藏的基于卷的移动PDE系统Mobigyges,以填补空白。 Mobigyges通过限制仅由一个卷使用的每个存储块来解决数据丢失的问题,并通过消除保留区域来改善存储利用率。 Mobigyges还可以通过动态安装服务动态安装隐藏的卷来避免重新启动设备。此外,我们确定了两次新颖的PDE攻击,容量比较攻击和填充攻击。 Mobigyges可以通过共同利用缩减的U-Disk方法和多级可否认性来捍卫它们。我们在真实的手机Google Nexus 6P上实现了Mobigyges的概念验证系统。实验结果表明,Mobigyges可以防止数据丢失,避免重新启动设备,将存储使用率提高了30%以上,并且与当前工程相比,可接受的性能遮盖了费用。

Sensitive data protection is essential for mobile users. Plausibly Deniable Encryption (PDE) systems provide an effective manner to protect sensitive data by hiding them on the device. However, existing PDE systems can lose data due to overriding the hidden volume, waste physical storage because of the reserved area used for avoiding data loss, and require device reboot when using the hidden volume. This paper presents MobiGyges, a hidden volume-based mobile PDE system, to fill the gap. MobiGyges addresses the problem of data loss by restricting each storage block used only by one volume, and it improves storage utilization by eliminating the reserved area. MobiGyges can also avoid device reboot by mounting the hidden volume dynamically on-demand with the Dynamic Mounting service. Moreover, we identify two novel PDE oriented attacks, the capacity comparison attack and the fill-to-full attack. MobiGyges can defend them by jointly leveraging the Shrunk U-disk method and multi-level deniability. We implement the MobiGyges proof-of-concept system on a real mobile phone Google Nexus 6P with LineageOS 13. Experimental results show that MobiGyges prevents data loss, avoids device reboot, improves storage utilization by over 30% with acceptable performance overhead compared with current works.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源