Google Details the Tamper-Resistant Hardware Security Module on the Pixel 2...

 
 
 
Google Details the Tamper-Resistant Hardware Security Module on the Pixel 2...

 
xda-developers
Nov 15, 2017 11:30 PM • by Idrees Patel
Google Details the Tamper-Resistant Hardware Security Module on the Pixel 2

With each new version of Android, Google has increased its focus on security. Android 5.1 Lollipop added Factory Reset Protection as an anti-theft measure. Then, the company made encryption mandatory for high-performing devices since Android 6.0 Marshmallow. In Nougat, Google made the switch over to File-Based Encryption. Now, Google has detailed the Pixel 2's tamper-resistant hardware security module, which delivers "enterprise-grade security", according to the company.

The Pixel 2 and the Pixel 2 XL's hardware security module is a first for an Android device. It reinforces the lock screen against malware and hardware attacks. This is done in order to better safeguard the data stored on a user's device, which includes contacts, emails, photos, app data, etc. Google hopes that the Pixel 2 is the first of many Android devices that feature dedicated security modules.

We know that the lock screen is the first line of defence when it comes to protecting a user's data from attacks, as it is the point of vulnerability for brute force attacks. Google states that devices that ship with Android 7.0+ already verify a user's lock screen passcode in a secure environment, such as the Trusted Execution Environment (TEE).

This limits how often a malicious attacker can repeatedly try to guess it by brute-force. The key step is when the secure environment has successfully verified the user's passcode. Then, and only then it reveals a device and user-specific secret which is used to derive the disk encryption key, according to Google. The company states that without the disk encryption key, a user's data cannot be decrypted.

According to Google, the goal of these protections is to prevent attackers from decrypting user data without knowing the user's passcode. The company admits that the protections are only as strong as the secure environment that verifies the passcode – a weak link can compromise an entire security system even if every other component is secure.

This is where a hardware security module comes in. Google says that attackers will face more difficulty in attacking the device when it is performing "security-critical operations in tamper-resistant hardware".

So what does a tamper-resistant hardware security module actually mean? In the Pixel 2, the tamper-resistant security module is in the form of a discrete chip, which is separate from the main SoC (the Qualcomm Snapdragon 835 in the Pixel 2's case). According to Google, the security module includes its own flash, RAM, processing unit, and other resources inside a single package. Therefore, it can control its own execution. This also helps it rebuff external attempts to tamper with it.

Pixel 2 Hardware Security Module

Google further states: "The package is resistant to physical penetration and designed to resist many side channel attacks, including power analysis, timing analysis, and electromagnetic sniffing. The hardware is also resilient against many physical fault injection techniques including attempts to run outside normal operating conditions, such as wrong voltage, wrong clock speed, or wrong temperature." Therefore, the tamper-resistant claim would seem to hold true on account of the above facts.

The Pixel 2's tamper-resistant hardware security module also helps to protect the device against software-only attacks. According to Google, it has an extremely small attack surface. This is because it performs very few functions, as it is dedicated hardware used for only specific purposes rather than being general-purpose hardware.

The key step in the process is that passcode verification occurs in the security module. Google states that even in the event of a full compromise elsewhere, the attacker cannot derive a user's disk encryption key without compromising the security module first – showing one of the major benefits of hardware security modules.

Google concludes by stating that the security module is designed in a such a manner that nobody – including Google itself – can update the passcode verification to a weakened version without having prior knowledge of the user's passcode.

For us, the blog post by Google was certainly illuminating. The hardware security module isn't a groundbreaking feature, but it reinforces the software protection that had existed before. Google did not identify the source of supply of the module, but XDA Senior Recognized Developer Dees_troy has stated that it was supplied by NXP. Already, there are concerns that security features like this may hinder development for the devices, showing that the battle between the focus on security and device development capabilities is still alive.

Source: Google




Android Advices
Nov 3, 2017 4:50 PM • by Pavan Kumar B.C
Sony Xperia XZ1 gets $110 price cut in US, now available for $590

Sony's Xperia XZ1 gets another price cut in the US and this flagship device is currently available for $589 on Amazon which is $110 lessor than its previous price. Currently, the Blue color variant is priced at $589 while the other options are available for $599.99. There is no information on how long the price cut will be implemented or till when the offer is valid so the users need to act soon to get their hands on the Xperia XZ1 for a discounted price.

Coming to the device, the Xperia XZ1 was launched a few weeks back and came with a 5.2-inch IPS LCD display with 1080 x 1920 pixels resolutions giving a pixel density of 424ppi with the latest Corning Gorilla Glass 5 protection on top. Moreover, under the hood, there is the Qualcomm Snapdragon 835 SoC Octa-core processor coupled with 4GB of RAM and Adreno 540 GPU. Sony is known for making good camera smartphones and this device comes with a 19MP main sensor with EIS, F/2.0 aperture size, laser autofocus and LED flash.

It also comes with features like touch focus, face/smile detection, panorama, HDR and few other sensors. It is also capable of capturing 2160p videos at 30fps and it will be accompanied with a 13MP camera on the front for video calls and selfies which also comes with EIS and 1/3" sensor. There is a fingerprint sensor on the side to enhance the security levels and has sensors like proximity, parameter, compass and few other.

There is a non-removable Li-Ion 2700 mAh battery on the back and comes with quick charge 3.0 for fast charging. The handset is available in Black, Warm Silver, Venus Pink, and Moonlit Blue color variants. The onboard storage is limited to 64GB which can be extended up to 256GB via microSD card slot. Are you planning to get this device on discounted price? Comment in the section below and stay tuned for more news and updates.

Source




 
 

This email has been sent by Froze ONE (isnanmm0@gmail.com). It is the potion result of 'Tech: Topic watch' from the dashboard 'Personal Dashboard', tab 'Tech > Android'. Unsubscribe

 
 
 

Subscribe to receive free email updates:

0 Response to "Google Details the Tamper-Resistant Hardware Security Module on the Pixel 2..."

Post a Comment