Low-Cost Privilege Separation with Compile Time Compartmentalization for Embedded Systems
Arslan Khan, Dongyan Xu, Dave Jing Tian
Abstract
Embedded systems are pervasive and find various applications all around us. These systems run on low-power microcontrollers with real-time constraints. Developers often sacrifice security to meet these constraints by running the entire software stack with the same privilege. Existing work has utilized compartmentalization to mitigate the situation but suffers from a high overhead due to extensive runtime checking to achieve isolation between different compartments in the system, resulting in a rare adoption. In this paper, we present Compartmentalized Real-Time C (CRT-C), a low-cost compile-time compartmentalization mechanism for embedded systems to achieve privilege separation in a linear address space using specialized programming language dialects. Each programming dialect restricts the programming capabilities of a part of a program, formalizing different compartments within the program. CRT-C uses static analysis to identify various compartments in firmware and realizes the least privilege in the system by enforcing compartment-specific policies. We design and implement a new compiler to compile CRT-C to generate compartmentalized firmware that is ready to run on commodity embedded systems. We evaluate CRT-C with two Real-Time Operating Systems (RTOSs): FreeRTOS and Zephyr. Our evaluation shows that CRT-C can provide compartmentalization to embedded systems to thwart various attacks while incurring an average runtime overhead of 2.63% and memory overhead of 1.75%. CRT-C provides a practical solution to both retrofit legacy and secure new applications for embedded systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 045dfa42-62d4-4cac-8e65-b8d24fac8731Cited by top-tier papers6
- Rust for Embedded Systems: Current State and Open ProblemsAyushi Sharma, Shashank Sharma, Sai Ritvik Tanksalkar, Santiago Torres-Arias et al.CCS 2024 · 12 citations
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.S&P 2025
- PEARTS: Provable Execution in Real-Time Embedded SystemsAntonio Joia Neto, Norrathep Rattanavipanon, Ivan De Oliveira NunesS&P 2025
- TZ-DATASHIELD: Automated Data Protection for Embedded Systems via Data-Flow-Based CompartmentalizationZelun Kong, Minkyung Park, Le Guan, Ning Zhang et al.NDSS 2025
- BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKSYinggang Guo, Zicheng Wang, Weiheng Bai, Qingkai Zeng et al.NDSS 2025
Builds on11
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu et al.NDSS 2018 · 127 citations
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava et al.S&P 2017 · 122 citations
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 89 citations
Related papers
- EC: Embedded Systems Compartmentalization via Intra-Kernel IsolationArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng et al.USENIX Security 2025
- Holistic Control-Flow Protection on Real-Time Embedded Systems with KageYufei Du, Zhuojia Shen, Komail Dharsee, Jie Zhou et al.USENIX Security 2022
- D-Box: DMA-enabled Compartmentalization for Embedded ApplicationsAlejandro Mera, Yi Hui Chen, Ruimin Sun, Engin Kirda et al.NDSS 2022
- Trust Nothing: RTOS Security without Run-Time Software TCBEric Ackermann, Sven BugielUSENIX Security 2026
