TY - GEN
T1 - An REE-independent Approach to Identify Callers of TEEs in TrustZone-enabled Cortex-M Devices
AU - Iannillo, Antonio Ken
AU - Rivera, Sean
AU - Suciu, Darius
AU - Sion, Radu
AU - State, Radu
N1 - Publisher Copyright:
© 2022 Owner/Author.
PY - 2022/5/30
Y1 - 2022/5/30
N2 - Internet of Things (IoT) devices are becoming increasingly ubiquitous in our lives, from personal health monitoring to house and factory management. Further, IoT devices are becoming increasingly complex, and ensuring their security is of paramount importance. As a result, they started to include Trusted Execution Environments (TEEs) to protect security-critical IoT operations. This paper focuses on improving the security of the next-generation IoT devices by introducing Secure Informer, an identification and authentication mechanism for ARM TrustZone for Cortex-M. Under Secure Informer, the TEE can directly determine the Rich Execution Environment (REE) context without introducing additional communication or dependency on the REE software stack. We implement our solution for ARMV8-M architecture, showing its efficacy with no need to change the source code of the REE. Empirical results show that Secure Informer can help mitigate confused deputy attacks targeting TEE-running services while only incurring an average 3.2% overhead on the device performance and requiring an additional 464 lines (52 bytes in the compiled binary file) to the TEE.
AB - Internet of Things (IoT) devices are becoming increasingly ubiquitous in our lives, from personal health monitoring to house and factory management. Further, IoT devices are becoming increasingly complex, and ensuring their security is of paramount importance. As a result, they started to include Trusted Execution Environments (TEEs) to protect security-critical IoT operations. This paper focuses on improving the security of the next-generation IoT devices by introducing Secure Informer, an identification and authentication mechanism for ARM TrustZone for Cortex-M. Under Secure Informer, the TEE can directly determine the Rich Execution Environment (REE) context without introducing additional communication or dependency on the REE software stack. We implement our solution for ARMV8-M architecture, showing its efficacy with no need to change the source code of the REE. Empirical results show that Secure Informer can help mitigate confused deputy attacks targeting TEE-running services while only incurring an average 3.2% overhead on the device performance and requiring an additional 464 lines (52 bytes in the compiled binary file) to the TEE.
KW - caller identification
KW - confused deputy attack
KW - tee
KW - trustzone for cortex-m
UR - https://www.scopus.com/pages/publications/85134402971
U2 - 10.1145/3494107.3522774
DO - 10.1145/3494107.3522774
M3 - Conference contribution
AN - SCOPUS:85134402971
T3 - CPSS 2022 - Proceedings of the 8th ACM Cyber-Physical System Security Workshop
SP - 85
EP - 94
BT - CPSS 2022 - Proceedings of the 8th ACM Cyber-Physical System Security Workshop
PB - Association for Computing Machinery, Inc
T2 - 8th ACM Cyber-Physical System Security Workshop, CPSS 2022, co-located with ACM AsiaCCS 2022
Y2 - 30 May 2022
ER -