Arm Community
Arm Community
  • Site
  • User
  • Site
  • Search
  • User
Arm Community blogs
Arm Community blogs
Architectures and Processors blog TrustZone and FIDO: Protecting your privacy and identity
  • Blogs
  • Mentions
  • Sub-Groups
  • Tags
  • Jump...
  • Cancel
More blogs in Arm Community blogs
  • AI blog

  • Announcements

  • Architectures and Processors blog

  • Automotive blog

  • Embedded and Microcontrollers blog

  • Internet of Things (IoT) blog

  • Laptops and Desktops blog

  • Mobile, Graphics, and Gaming blog

  • Operating Systems blog

  • Servers and Cloud Computing blog

  • SoC Design and Simulation blog

  • Tools, Software and IDEs blog

Tell us what you think
Tags
  • tee
  • fido
  • TrustZone
Actions
  • RSS
  • More
  • Cancel
Related blog posts
Related forum threads

TrustZone and FIDO: Protecting your privacy and identity

Rob Coombs
Rob Coombs
May 22, 2015
1 minute read time.

Identity thieves are getting quite sophisticated when it comes to stealing your username and password.   We might be wary of an unsolicited email containing a link but what if it came from a friend's email account?  This happened to my wife recently - her friend's PC had been taken over and was sending believable emails to all her contacts (the PC was later encrypted by the hackers and held to ransom for  bitcoins).  If you clicked the link up would pop a window purporting to be from Google asking you to login with your username and password... .  Then there is the issue of having to remember too many long and complex passwords for the different web services we all use.     I think most of us would agree that passwords aren't safe and they are painful to use.

Fortunately the combination of a new authentication protocol called FIDO (Fast ID Online) and biometrics is changing the landscape rapidly.   The FIDO Alliance is a group of approximately 200 companies working together to create a new protocol that provides simpler, stronger authentication.   It can work with many different types of authenticator such as fingerprint sensor, iris scanner or trusted PIN entry.  The device (not the remote sever) creates a public/private key pair for each combination of user/device/relying party during registration and provides the public key to the relying party.   The sensitive parts of the algorithm e.g. crypto, matching, key stores need to be protected from scalable attacks.   Fortunately ARM based applications processors usually implement a TrustZone based Trusted Execution Environment consisting of isolation hardware, authenticated trusted boot and a small Trusted OS.   The TEE is being standardised by GlobalPlatform who are working on a security certification scheme so that it will soon be possible for platforms to be tested by 3rd party labs.  The attached white paper looks at how the TrustZone based TEE is being used with FIDO based systems to protect assets and accelerate the revolution to a world without passwords. 


TrustZone and FIDO white paper final.pdf
Anonymous
Parents
  • wangyong
    wangyong over 10 years ago

    The link address can be accessed now, thanks.

    • Cancel
    • Up 0 Down
    • Reply
    • More
    • Cancel
Comment
  • wangyong
    wangyong over 10 years ago

    The link address can be accessed now, thanks.

    • Cancel
    • Up 0 Down
    • Reply
    • More
    • Cancel
Children
No Data
Architectures and Processors blog
  • Scalable Matrix Extension: Expanding the Arm Intrinsics Search Engine

    Chris Walsh
    Chris Walsh
    Arm is pleased to announce that the Arm Intrinsics Search Engine has been updated to include the Scalable Matrix Extension (SME) intrinsics, including both SME and SME2 intrinsics.
    • October 3, 2025
  • Arm A-Profile Architecture developments 2025

    Martin Weidmann
    Martin Weidmann
    Each year, Arm publishes updates to the A-Profile architecture alongside full Instruction Set and System Register documentation. In 2025, the update is Armv9.7-A.
    • October 2, 2025
  • When a barrier does not block: The pitfalls of partial order

    Wathsala Vithanage
    Wathsala Vithanage
    Acquire fences aren’t always enough. See how LDAPR exposed unsafe interleavings and what we did to patch the problem.
    • September 15, 2025