Securely storing sensitive personal data is critical for protecting privacy. Currently, many persons use smartphones to store their private data. However, smartphones suffer from many security issues. To overcome this situation, the PCAS project is designing a secure personal storage device called the Secure Portable Device (SPD), to be attached to a smartphone for securely storing sensitive personal data. However, this device is unavailable, closed, and expensive to deploy for prototyping applications. We propose a platform that emulates the SPD and the smartphone using a board with an ARM processor with the TrustZone security extension. This platform is open, inexpensive, and secure. A payment application is used as an example to show the platform's capabilities. As a proof-of-concept, we implemented this platform and provide a performance evaluation using a i.MX53 board.
QC 20160719