Minimum viable device drivers for ARM trustzone
Liwei Guo, Felix Xiaozhu Lin
Abstract
While TrustZone can isolate IO hardware, it lacks drivers for modern IO devices. Rather than porting drivers, we propose a novel approach to deriving minimum viable drivers: developers exercise a full driver and record the driver/device interactions; the processed recordings, dubbed driverlets, are replayed in the TEE at run time to access IO devices. Driverlets address two key challenges: correctness and expressiveness, for which they build on a key construct called interaction template. The interaction template ensures faithful reproduction of recorded IO jobs (albeit on new IO data); it accepts dynamic input values; it tolerates nondeterministic device behaviors. We demonstrate driverlets on a series of sophisticated devices, making them accessible to Trust-Zone for the first time to our knowledge. Our experiments show that driverlets are secure, easy to build, and incur acceptable overhead (1.4×-2.7× compared to native drivers). Driverlets fill a critical gap in the TrustZone TEE, realizing its long-promised vision of secure IO.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d0c43b4-df26-44db-842a-94a105bb89a7Cited by top-tier papers13
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne et al.USENIX Security 2024 · 36 citations
- STI: Turbocharge NLP Inference at the Edge via Elastic PipeliningLiwei Guo, Wonkyo Choe, Felix Xiaozhu LinASPLOS 2023 · 25 citations
- D2MoE: Dual Routing and Dynamic Scheduling for Efficient On-Device MoE-based LLM ServingHaodong Wang, Qihua Zhou, Zicong Hong, Song GuoMobiCom 2025 · 8 citations
- ProvCam: A Camera Module with Self-Contained TCB for Producing Verifiable VideosYuxin (Myles) Liu, Zhihao Yao, Mingyi Chen, Ardalan Amiri Sani et al.MobiCom 2024 · 7 citations
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao et al.NDSS 2026 · 4 citations
Builds on4
- Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile SystemsSeyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang et al.USENIX Security 2018 · 81 citations
- Enabling Refinable Cross-Host Attack Investigation with Efficient Data Flow Tagging and TrackingYang Ji, Sangho Lee, Mattia Fazzini, Joey Allen et al.USENIX Security 2018 · 70 citations
- BinRec: dynamic binary lifting and recompilationAnil Altinay, Joseph Nash, Taddeus Kroes, Prabhu Rajasekaran et al.EuroSys 2020 · 51 citations
- GPUReplay: a 50-KB GPU stack for client MLHeejin Park, Felix Xiaozhu LinASPLOS 2022 · 10 citations
Related papers
- μUSB: Practical and Safe USB Driver Reuse for Arm TrustZoneXuankai Zhang, Sijin Li, Pei Meng, Meng Wang et al.OSDI 2026
- MyTEE: Own the Trusted Execution Environment on Embedded DevicesSeung-Kyun Han, Jinsoo JangNDSS 2023
- ReZone: Disarming TrustZone with TEE Privilege ReductionDavid Cerdeira, José Martins, Nuno Santos, Sandro PintoUSENIX Security 2022
- PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using EmulationLee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen et al.USENIX Security 2020
- LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Haobo Li, Lan Luo et al.NDSS 2024
