| 移动终端完整性保护的安全导则 |
 |
移动终端完整性保护的目标是确保移动终端以预期的方式运行。这意味着,移动终端上的硬件、固件和软件(例如,操作系统、预安装的应用程序)没有被任何手段或以任何方式损害。如果攻击者损害固件或软件,或者修改硬件(例如,ROM、保留单元)的配置,或者改变硬件(例如,闪存),则攻击者可以控制或破坏移动终端的功能。
当移动终端开机时,它从启动阶段开始,以验证硬件组件并加载一个或多个软件模块。此后,移动终端进入运行阶段,并达到操作状态,在该状态下,移动终端准备好用于其预期目的。为了修复固件/软件(FW/SW)的漏洞和弱点,移动终端需要不时地更新。这称为FW/SW更新阶段。每个阶段都为攻击者提供了对移动终端完整性发起安全威胁的机会。
ITU-T X.1129建议书分析了移动终端在启动阶段、运行阶段和FW/SW更新阶段面临的安全威胁,定义了安全要求,并为移动终端完整性保护提供了安全导则。
|
|
|
|
|
| Ed. |
ITU-T Recommendation |
Status |
Summary |
Table of Contents |
Download |
|
1
|
X.1129 (12/2025)
|
In force
|
here
|
here
|
here
|
|
|
|
ITU-T Supplement
|
Title
|
Status
|
Summary
|
Table of contents
|
Download
|
|
X Suppl. 19 (04/2013)
|
ITU-T X.1120-X.1139 series – Supplement on security aspects of smartphones
|
In force
|
here
|
here
|
here
|
|
X Suppl. 24 (09/2014)
|
ITU-T X.1120-X.1139 series - Supplement on a secure application distribution framework for communication devices
|
In force
|
here
|
here
|
here
|
| Title |
Approved on |
Download |
|
Guidelines for identity-based cryptosystems used for cross-domain secure communications
|
2023
|
here
|
|
Overview of hybrid approaches for key exchange with quantum key distribution
|
2022
|
here
|
|
Guidelines for security management of using artificial intelligence technology
|
2022
|
here
|
|
Successful use of security standards (2nd edition)
|
2020
|
here
|
|
Description of the incubation mechanism and ways to improve it
|
2020
|
here
|
|
Strategic approaches to the transformation of security studies
|
2020
|
here
|
|