A Simple Mobile Plausibly Deniable System Using Image Steganography and Secure Hardware

Author(s)Xia, Lichen
Author(s)Liao, Jinghui
Author(s)Chen, Niusen
Author(s)Chen, Bo
Author(s)Shi, Weisong
Date Accessioned2024-06-14T18:27:55Z
Date Available2024-06-14T18:27:55Z
Publication Date2024-06-19
DescriptionThis article was originally published in Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems SaT-CPS ’24, June 21, 2024, Porto, Portugal. The version of record is available at: https://doi.org/10.1145/3643650.3658607. © 2024 Copyright held by the owner/author(s). This work is licensed under a Creative Commons Attribution International 4.0 License (https://creativecommons.org/licenses/by/4.0/).
AbstractTraditional encryption methods cannot defend against coercive attacks in which the adversary captures both the user and the possessed computing device, and forces the user to disclose the decryption keys. Plausibly deniable encryption (PDE) has been designed to defend against this strong coercive attacker. At its core, PDE allows the victim to plausibly deny the very existence of hidden sensitive data and the corresponding decryption keys upon being coerced. Designing an efficient PDE system for a mobile platform, however, is challenging due to various design constraints bound to the mobile systems. Leveraging image steganography and the built-in hardware security feature of mobile devices, namely TrustZone, we have designed a Simple Mobile Plausibly Deniable Encryption (SMPDE) system which can combat coercive adversaries and, meanwhile, is able to overcome unique design constraints. In our design, the encoding/decoding process of image steganography is bounded together with Arm TrustZone. In this manner, the coercive adversary will be given a decoy key, which can only activate a DUMMY trusted application that will instead sanitize the sensitive information stored hidden in the stego-image upon decoding. On the contrary, the actual user can be given the true key, which can activate the PDE trusted application that can really extract the sensitive information from the stego-image upon decoding. Security analysis and experimental evaluation justify both the security and the efficiency of our design.
SponsorThis work was supported by US National Science Foundation under grant number CNS-2313139, CNS-1928331 and CNS-1928349. Niusen Chen and Bo Chen were also supported by US National Science Foundation under grant number CNS-2225424.
CitationLichen Xia, Jinghui Liao, Niusen Chen, Bo Chen, and Weisong Shi. 2024. A Simple Mobile Plausibly Deniable System Using Image Steganography and Secure Hardware. In Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (SaT-CPS ’24), June 21, 2024, Porto, Portugal. ACM, New York, NY, USA, 9 pages. https://doi.org/10.1145/ 3643650.3658607
ISBN979-8-4007-0555-7/24/06
URLhttps://udspace.udel.edu/handle/19716/34500
Languageen_US
PublisherProceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems
dc.rightsAttribution 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
Keywordsplausibly deniable encryption
Keywordsmobile devices
KeywordsTrustZone
Keywordsimage steganography
TitleA Simple Mobile Plausibly Deniable System Using Image Steganography and Secure Hardware
TypeArticle
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
A Simple Mobile Plausibly Deniable System Using Image.pdf
Size:
1.22 MB
Format:
Adobe Portable Document Format
Description:
Main article
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.22 KB
Format:
Item-specific license agreed upon to submission
Description: