Open Access
Peer-Reviewed
Original Research
A Formally Verified Digital Signature Device for Smartphones
Abstract
Attacks on Internet banking using a malware called “Hig h Roller” triggered the EU cyber security agency to issue a warning and call for action. With the proliferation of smartphones, customers want to do online banking on their phone, too. But a smartphone could also be compromised and so the customer cannot trust what is shown in the display and PINs could be sent to the attacker. We assume an attacker motivated by financial gain through diverting manipulated bank transactions to an account under his control. Based on that assumption, we propose signed transac tion summaries where the signature is created in a separate security device after the summary has been shown to the user and the user has approved it. Keeping the requirements to the absolute minimum, we derive a hardware implementation for the Jolla smartphone and, based on that hardware, a secure software implementation. We use commercial off-the-shelf components and, by keeping the protocols simple, reduce the trusted computing base as much as possible. We then demonstrate how the program in the micro c ontroller avoids common software flaws and show fragments of a formal verification of the correctness of the microcontroller program.
Keywords
Secure digital signing unit
Internet banking
transaction summaries
chip cards
formal verification.
Declarations & Ethics
Funding:
This research received academic dissemination support through ESCAP / JournalsHub publishing programs.
Conflicts of Interest:
The authors declare no competing financial or institutional interests.
Peer Review:
Double-blind peer reviewed by international subject specialists.
License:
Creative Commons Attribution 4.0 International (CC BY 4.0).
How to Cite This Article
APA / MLA / BibTeX
Safe, et al. (2015). A Formally Verified Digital Signature Device for Smartphones. IADIS International Journal on Computer Science and Information Systems, 10(2). https://doi.org/10.33965/ijcsis_2015_v10i2_02
Safe, et al. "A Formally Verified Digital Signature Device for Smartphones." IADIS International Journal on Computer Science and Information Systems, vol. 10, no. 2, 2015. https://doi.org/10.33965/ijcsis_2015_v10i2_02
Safe, et al. "A Formally Verified Digital Signature Device for Smartphones." IADIS International Journal on Computer Science and Information Systems 10, no. 2 (2015). https://doi.org/10.33965/ijcsis_2015_v10i2_02