The Experts below are selected from a list of 327 Experts worldwide ranked by ideXlab platform
Sascha Wessel - One of the best experts on this subject based on the ideXlab platform.
-
Inscrypt - A Secure Architecture for Operating System-Level Virtualization on Mobile Devices
Information Security and Cryptology, 2016Co-Authors: Manuel Huber, Julian Horsch, Michael Velten, Michael Weiss, Sascha WesselAbstract:In this paper, we present a novel secure architecture for OS-Level virtualization on mobile devices. OS-Level virtualization allows to simultaneously operate multiple userland OS instances on one physical device. Compared to previous approaches, our main objective is the confidentiality of sensitive user data stored on the device. We isolate the OS instances by restricting them to a set of minimal, controlled functionality and allow communication between components exclusively through well-defined channels. With our secure architecture, we therefore go beyond the common deployment of Linux kernel mechanisms, such as namespaces or cgroups. We develop a specially tailored, stacked LSM concept using SELinux and a custom LSM, leverage Linux capabilities and the cgroups devices subSystem. Based on the architecture, we present secure device virtualization concepts allowing to dynamically assign device functionalities to different OS instances. Furthermore, we develop a mechanism for secure switching between the instances. We realize the architecture with a fully functional and performant implementation on the Samsung Galaxy S4 and Nexus 5 mobile devices, running Android 4.4.4 and 5.1.1, respectively. With a Systematic security evaluation, we demonstrate that the secure isolation of OS instances provides confidentiality even when large parts of the System are compromised.
-
a secure architecture for Operating System Level virtualization on mobile devices
International Conference on Information Security and Cryptology, 2015Co-Authors: Manuel Huber, Julian Horsch, Michael Velten, Michael Weiss, Sascha WesselAbstract:In this paper, we present a novel secure architecture for OS-Level virtualization on mobile devices. OS-Level virtualization allows to simultaneously operate multiple userland OS instances on one physical device. Compared to previous approaches, our main objective is the confidentiality of sensitive user data stored on the device. We isolate the OS instances by restricting them to a set of minimal, controlled functionality and allow communication between components exclusively through well-defined channels. With our secure architecture, we therefore go beyond the common deployment of Linux kernel mechanisms, such as namespaces or cgroups. We develop a specially tailored, stacked LSM concept using SELinux and a custom LSM, leverage Linux capabilities and the cgroups devices subSystem. Based on the architecture, we present secure device virtualization concepts allowing to dynamically assign device functionalities to different OS instances. Furthermore, we develop a mechanism for secure switching between the instances. We realize the architecture with a fully functional and performant implementation on the Samsung Galaxy S4 and Nexus 5 mobile devices, running Android 4.4.4 and 5.1.1, respectively. With a Systematic security evaluation, we demonstrate that the secure isolation of OS instances provides confidentiality even when large parts of the System are compromised.
-
Improving mobile device security with Operating System-Level virtualization
Computers & Security, 2015Co-Authors: Sascha Wessel, Frederic Stumpf, Manuel Huber, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. We provide an administrative solution for dynamically modifying, removing or adding multiple Android instances remotely and locally. Furthermore, we present a secure device provisioning and enrollment solution for our System. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen of mobile devices. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
-
Improving Mobile Device Security with Operating System-Level Virtualization
2013Co-Authors: Sascha Wessel, Ilja Herdt, Frederic Stumpf, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
-
SEC - Improving Mobile Device Security with Operating System-Level Virtualization
Security and Privacy Protection in Information Processing Systems, 2013Co-Authors: Sascha Wessel, Ilja Herdt, Frederic Stumpf, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
Manuel Huber - One of the best experts on this subject based on the ideXlab platform.
-
Inscrypt - A Secure Architecture for Operating System-Level Virtualization on Mobile Devices
Information Security and Cryptology, 2016Co-Authors: Manuel Huber, Julian Horsch, Michael Velten, Michael Weiss, Sascha WesselAbstract:In this paper, we present a novel secure architecture for OS-Level virtualization on mobile devices. OS-Level virtualization allows to simultaneously operate multiple userland OS instances on one physical device. Compared to previous approaches, our main objective is the confidentiality of sensitive user data stored on the device. We isolate the OS instances by restricting them to a set of minimal, controlled functionality and allow communication between components exclusively through well-defined channels. With our secure architecture, we therefore go beyond the common deployment of Linux kernel mechanisms, such as namespaces or cgroups. We develop a specially tailored, stacked LSM concept using SELinux and a custom LSM, leverage Linux capabilities and the cgroups devices subSystem. Based on the architecture, we present secure device virtualization concepts allowing to dynamically assign device functionalities to different OS instances. Furthermore, we develop a mechanism for secure switching between the instances. We realize the architecture with a fully functional and performant implementation on the Samsung Galaxy S4 and Nexus 5 mobile devices, running Android 4.4.4 and 5.1.1, respectively. With a Systematic security evaluation, we demonstrate that the secure isolation of OS instances provides confidentiality even when large parts of the System are compromised.
-
a secure architecture for Operating System Level virtualization on mobile devices
International Conference on Information Security and Cryptology, 2015Co-Authors: Manuel Huber, Julian Horsch, Michael Velten, Michael Weiss, Sascha WesselAbstract:In this paper, we present a novel secure architecture for OS-Level virtualization on mobile devices. OS-Level virtualization allows to simultaneously operate multiple userland OS instances on one physical device. Compared to previous approaches, our main objective is the confidentiality of sensitive user data stored on the device. We isolate the OS instances by restricting them to a set of minimal, controlled functionality and allow communication between components exclusively through well-defined channels. With our secure architecture, we therefore go beyond the common deployment of Linux kernel mechanisms, such as namespaces or cgroups. We develop a specially tailored, stacked LSM concept using SELinux and a custom LSM, leverage Linux capabilities and the cgroups devices subSystem. Based on the architecture, we present secure device virtualization concepts allowing to dynamically assign device functionalities to different OS instances. Furthermore, we develop a mechanism for secure switching between the instances. We realize the architecture with a fully functional and performant implementation on the Samsung Galaxy S4 and Nexus 5 mobile devices, running Android 4.4.4 and 5.1.1, respectively. With a Systematic security evaluation, we demonstrate that the secure isolation of OS instances provides confidentiality even when large parts of the System are compromised.
-
Improving mobile device security with Operating System-Level virtualization
Computers & Security, 2015Co-Authors: Sascha Wessel, Frederic Stumpf, Manuel Huber, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. We provide an administrative solution for dynamically modifying, removing or adding multiple Android instances remotely and locally. Furthermore, we present a secure device provisioning and enrollment solution for our System. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen of mobile devices. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
Claudia Eckert - One of the best experts on this subject based on the ideXlab platform.
-
Improving mobile device security with Operating System-Level virtualization
Computers & Security, 2015Co-Authors: Sascha Wessel, Frederic Stumpf, Manuel Huber, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. We provide an administrative solution for dynamically modifying, removing or adding multiple Android instances remotely and locally. Furthermore, we present a secure device provisioning and enrollment solution for our System. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen of mobile devices. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
-
Improving Mobile Device Security with Operating System-Level Virtualization
2013Co-Authors: Sascha Wessel, Ilja Herdt, Frederic Stumpf, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
-
SEC - Improving Mobile Device Security with Operating System-Level Virtualization
Security and Privacy Protection in Information Processing Systems, 2013Co-Authors: Sascha Wessel, Ilja Herdt, Frederic Stumpf, Claudia EckertAbstract:In this paper, we propose a lightweight mechanism to isolate one or more Android userland instances from a trustworthy and secure entity. This entity controls and manages the Android instances and provides an interface for remote administration and management of the device and its software. Our approach includes several security extensions for secure network access, integrity protection of data on storage devices, and secure access to the touchscreen. Our implementation requires only minimal modification to the software stack of a typical Android-based smartphone, which allows easy porting to other devices when compared to other virtualization techniques. Practical tests show the feasibility of our approach regarding runtime overhead and battery lifetime impact.
Tarek Al-bagikni - One of the best experts on this subject based on the ideXlab platform.
-
Developing an Autonomic System Engineering Testbed: Virtualization of Operating Systems
2012Co-Authors: Tarek Al-bagikniAbstract:Revision with unchanged content. This thesis is on developing an Autonomic System Engineering testbed using Operating-System-Level virtualization technologies. The ASE testbed is a basis on which autonomic applications are to be developed, experimented with, and demonstrated. The thesis identifies and examines different virtualization concepts and technologies. Various solutions are compared, measured and benchmarked in order to find out, which product can be adapted best to and deployed for the ASE testbed. Finally, based on the virtualization measurements taken, the realization of the ASE testbed is described.
-
Developing an Autonomic System Engineering Testbed
2012Co-Authors: Tarek Al-bagikniAbstract:Revision with unchanged content. This thesis is on developing an Autonomic System Engineering testbed using Operating-System-Level virtualization technologies. The ASE testbed is a basis on which autonomic applications are to be developed, experimented with, and demonstrated. The thesis identifies and examines different virtualization concepts and technologies. Various solutions are compared, measured and benchmarked in order to find out, which product can be adapted best to and deployed for the ASE testbed. Finally, based on the virtualization measurements taken, the realization of the ASE testbed is described.
Marco D. Santambrogio - One of the best experts on this subject based on the ideXlab platform.
-
Metronome: Operating System Level performance management via self-adaptive computing
DAC Design Automation Conference 2012, 2012Co-Authors: Filippo Sironi, Davide B. Bartolini, Simone Campanoni, Fabio Cancare, Henry Hoffmann, Donatella Sciuto, Marco D. SantambrogioAbstract:In this paper, we present Metronome: a framework to enhance commodity Operating Systems with self-adaptive capabilities. The Metronome framework features two distinct components: Heart Rate Monitor (HRM) and Performance - Aware Fair Scheduler (PAFS). HRM is an active monitoring infrastructure implementing the observe phase of a self - adaptive computing System Observe - Decide - Act (ODA) control loop, while PAFS is an adaptation policy implementing the decide and act phases of the control loop. Metronome was designed and developed looking towards multi - core processors; therefore, its experimental evaluation has been carried on with the PARSEC 2.1 benchmark suite.
-
DAC - Metronome: Operating System Level performance management via self-adaptive computing
Proceedings of the 49th Annual Design Automation Conference on - DAC '12, 2012Co-Authors: Filippo Sironi, Davide B. Bartolini, Simone Campanoni, Fabio Cancare, Henry Hoffmann, Donatella Sciuto, Marco D. SantambrogioAbstract:In this paper, we present Metronome: a framework to enhance commodity Operating Systems with self-adaptive capabilities. The Metronome framework features two distinct components: Heart Rate Monitor (HRM) and Performance--Aware Fair Scheduler (PAFS). HRM is an active monitoring infrastructure implementing the observe phase of a self--adaptive computing System Observe--Decide--Act (ODA) control loop, while PAFS is an adaptation policy implementing the decide and act phases of the control loop. Metronome was designed and developed looking towards multi--core processors; therefore, its experimental evaluation has been carried on with the PARSEC 2.1 benchmark suite.