Cracking the Core: Hardware Vulnerabilities in Android Devices Unveiled

被引:2
作者
Munoz, Antonio [1 ]
机构
[1] Univ Malaga, Network Informat & Comp Secur Lab NICS, Malaga 29071, Spain
关键词
Android hardware vulnerabilities; mobile device security; system-on-chip (SoC) security; trusted execution environment (TEE); hardware vulnerability mitigations; side-channel attacks;
D O I
10.3390/electronics13214269
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As Android devices become more prevalent, their security risks extend beyond software vulnerabilities to include critical hardware weaknesses. This paper provides a comprehensive and systematic review of hardware-related vulnerabilities in Android systems, which can bypass even the most sophisticated software defenses. We compile and analyze an extensive range of reported vulnerabilities, introducing a novel categorization framework to facilitate a deeper understanding of these risks, classified by affected hardware components, vulnerability type, and the potential impact on system security. The paper addresses key areas such as memory management flaws, side-channel attacks, insecure system-on-chip (SoC) resource allocation, and cryptographic vulnerabilities. In addition, it examines feasible countermeasures, including hardware-backed encryption, secure boot mechanisms, and trusted execution environments (TEEs), to mitigate the risks posed by these hardware threats. By contextualizing hardware vulnerabilities within the broader security architecture of Android devices, this review emphasizes the importance of hardware security in ensuring system integrity and resilience. The findings serve as a valuable resource for both researchers and security professionals, offering insights into the development of more robust defenses against the emerging hardware-based threats faced by Android devices.
引用
收藏
页数:26
相关论文
共 67 条
  • [11] cwe.mitre, CWE-1189: Improper Isolation of Shared Resources on System-on-a-Chip
  • [12] cwe.mitre.org, CWE-1300: Improper Protection of Physical Side-Channels
  • [13] cwe.mitre.org, CWE-125: Out-of-Bounds Read
  • [14] cwe.mitre.org, CWE-226: Sensitive Information in Resource Not Removed Before Reuse
  • [15] cwe.mitre.org, CWE-1274: Improper Access Control for Volatile Memory Containing Boot Code
  • [16] cwe.mitre.org, CWE-416: Use After Free
  • [17] cwe.mitre.org, CWE-1332: Improper Handling of Faults That Lead to Instruction Skips
  • [18] cwe.mitre.org, CWE-1191: On-Chip Debug and Test Interface with Improper Access Control
  • [19] cwe.mitre.org, CWE-1272: Sensitive Information Uncleared Before Debug/Power State Transition
  • [20] Dejon N., 2022, Ph.D. Thesis