JCSE, vol. 5, no. 4, pp.331-337, 2011
DOI: http://dx.doi.org/10.5626/JCSE.2011.5.4.331
Data Firewall: A TPM-based Security Framework for Protecting Data in Thick Client Mobile Environment
Wooram Park, Chanik Park
Department of Computer Science and Engineering, Pohang University of Science and Technology (POSTECH), Pohang, Korea
Abstract: Recently, Virtual Desktop Infrastructure (VDI) has been widely adopted to ensure secure protection of enterprise data and provide
users with a centrally managed execution environment. However, user experiences may be restricted due to the limited functionalities
of thin clients in VDI. If thick client devices like laptops are used, then data leakage may be possible due to malicious software
installed in thick client mobile devices. In this paper, we present Data Firewall, a security framework to manage and protect securitysensitive
data in thick client mobile devices. Data Firewall consists of three components: Virtual Machine (VM) image management,
client VM integrity attestation, and key management for Protected Storage. There are two types of execution VMs managed by Data
Firewall: Normal VM and Secure VM. In Normal VM, a user can execute any applications installed in the laptop in the same manner
as before. A user can access security-sensitive data only in the Secure VM, for which the integrity should be checked prior to access
being granted. All the security-sensitive data are stored in the space called Protected Storage for which the access keys are managed by
Data Firewall. Key management and exchange between client and server are handled via Trusted Platform Module (TPM) in the
framework. We have analyzed the security characteristics and built a prototype to show the performance overhead of the proposed
framework.
Keyword:
Trusted platform module; Data firewall; Virtual desktop infrastructure; Virtualization
Full Paper: 132 Downloads, 2642 View
|