Skip to main navigation Skip to search Skip to main content

Overseer: Enforcing fine-grained memory access control across execution environments

  • Darius Suciu
  • , Sandeep Kiran Pinjala
  • , Bin Sun
  • , Radu Sion
  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

TrustZone enables Rich Execution Environments (REEs) and Trusted Execution Environments (TEEs) to share physical memory by building virtual address spaces without knowing each other's mapping. While TEE hardware protection guarantees that the REE ("Normal World") is restricted to accessing non-secure memory exclusively, the Secure OS and Trusted Applications (TAs) operating within the TEE ("Secure World") can map physical memory belonging to REE OS and applications. As a result, vulnerabilities within TEE code, in conjunction with the inherent semantic gap between the REE and TEE can be leveraged by malicious actors to completely bypass REE security policies and leak or compromise REE-sensitive data or code. Our comprehensive analysis of TAs from commercial TrustZone devices and associated CVEs in the past decade has revealed numerous REE and TEE physical memory access vulnerabilities across multiple vendors. To mitigate the security impact of this critical semantic gap, we introduce Overseer, a secure monitor mechanism that prevents unauthorized physical memory mappings by TEEs, one of the important enablers of compromise. Overseer further enables the Secure OS and the TAs running inside the TEE to regulate the invocation of Secure Monitor Calls (SMCs) and System Calls. Overseer's performance overhead is under 2% on average. A detailed CVE analysis shows that Overseer can mitigate the attack surface of over 53 TA vulnerabilities.

Original languageEnglish
Title of host publicationASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery, Inc
Pages743-758
Number of pages16
ISBN (Electronic)9798400723568
DOIs
StatePublished - Jun 4 2026
Event21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026 - Bangalore, India
Duration: Jun 1 2026Jun 5 2026

Publication series

NameASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security

Conference

Conference21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
Country/TerritoryIndia
CityBangalore
Period06/1/2606/5/26

Keywords

  • Access Control
  • ARM TrustZone
  • Hardware Security

Fingerprint

Dive into the research topics of 'Overseer: Enforcing fine-grained memory access control across execution environments'. Together they form a unique fingerprint.

Cite this