On the (In)Security of Manufacturer-Provided Remote Attestation Frameworks in Android


연구 분야: Analysis



학회: European Symposium on Research in Computer Security


초록

To provide a tamper-proof mechanism for mobile apps to check the integrity of the device and their own code/data, Android phone manufacturers have introduced Manufacturer-provided Android Remote Attestation (MARA) frameworks. The MARA framework helps an app conduct a series of integrity checks, signs the check results, and sends them to remote servers for a remote attestation. Nonetheless, we observe that real-world MARA frameworks often adopt two implementations of integrity check (hardware-based and software-based) for compatibility consideration, and this allows an attacker to easily conduct a downgrade attack to force the app to utilize the software-based integrity check and forge checking results, even if the Android device is able to employ hardware-supported remote attestation securely. We demonstrate our MARA bypass approach against MARA frameworks (i.e., Google SafetyNet and Huawei SafetyDetect) on real Android devices, and design an automated measurement pipeline to analyze 35,245 popular Android apps, successfully attacking all 104 apps that use these MARA services, including well-known apps and games such as TikTok Lite, Huawei Wallet, and Pokémon GO. Our study reveals the significant risks against MARA frameworks in use.


Author Profile
Yikun Hu

Shanghai Jiao Tong University Shanghai China

China
Author Profile
Dawu Gu

Shanghai Jiao Tong University Shanghai China

China
Author Profile
Ziyi Zhou

Shanghai Jiao Tong University Shanghai China

China

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 China
사이트 Springer
좋아요 수 0

연관 논문 목록 (102건)