Skip to main navigation Skip to search Skip to main content

An REE-independent Approach to Identify Callers of TEEs in TrustZone-enabled Cortex-M Devices

  • Antonio Ken Iannillo
  • , Sean Rivera
  • , Darius Suciu
  • , Radu Sion
  • , Radu State
  • University of Luxembourg
  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

6 Scopus citations

Abstract

Internet of Things (IoT) devices are becoming increasingly ubiquitous in our lives, from personal health monitoring to house and factory management. Further, IoT devices are becoming increasingly complex, and ensuring their security is of paramount importance. As a result, they started to include Trusted Execution Environments (TEEs) to protect security-critical IoT operations. This paper focuses on improving the security of the next-generation IoT devices by introducing Secure Informer, an identification and authentication mechanism for ARM TrustZone for Cortex-M. Under Secure Informer, the TEE can directly determine the Rich Execution Environment (REE) context without introducing additional communication or dependency on the REE software stack. We implement our solution for ARMV8-M architecture, showing its efficacy with no need to change the source code of the REE. Empirical results show that Secure Informer can help mitigate confused deputy attacks targeting TEE-running services while only incurring an average 3.2% overhead on the device performance and requiring an additional 464 lines (52 bytes in the compiled binary file) to the TEE.

Original languageEnglish
Title of host publicationCPSS 2022 - Proceedings of the 8th ACM Cyber-Physical System Security Workshop
PublisherAssociation for Computing Machinery, Inc
Pages85-94
Number of pages10
ISBN (Electronic)9781450391764
DOIs
StatePublished - May 30 2022
Event8th ACM Cyber-Physical System Security Workshop, CPSS 2022, co-located with ACM AsiaCCS 2022 - Virtual, Online, Japan
Duration: May 30 2022 → …

Publication series

NameCPSS 2022 - Proceedings of the 8th ACM Cyber-Physical System Security Workshop

Conference

Conference8th ACM Cyber-Physical System Security Workshop, CPSS 2022, co-located with ACM AsiaCCS 2022
Country/TerritoryJapan
CityVirtual, Online
Period05/30/22 → …

Keywords

  • caller identification
  • confused deputy attack
  • tee
  • trustzone for cortex-m

Fingerprint

Dive into the research topics of 'An REE-independent Approach to Identify Callers of TEEs in TrustZone-enabled Cortex-M Devices'. Together they form a unique fingerprint.

Cite this