USENIX Security2026Top-tier venue
Trust Nothing: RTOS Security without Run-Time Software TCB
Eric Ackermann, Sven Bugiel
Abstract
Embedded devices face an ever-expanding threat landscape: vulnerabilities in application software, operating system kernels, and peripherals threaten the embedded device integrity. Existing computer-architectural defenses fully consider at most two of these threat vectors in their security model. This paper aims at addressing this gap using a novel capability architecture. To this end, we combine a token capability approach suitable for building an untrusted operating system with protection against malicious devices without requiring hardware changes to peripherals. First, we develop and evaluate a full FPGA implementation of our capability architecture around legacy hardware components. Further, we present a soft real-time operating system based on Zephyr that has no run-time software TCB . To this end, we disaggregate Zephyr's subsystems into small, mutually isolated components. All subsystems that exist at run time, including scheduler, allocator and DMA drivers, and all peripherals are fully untrusted . We believe that our work offers a foundation for more rigorous security-by-design in tomorrow's security-critical embedded devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97aae8e5-3dc4-419d-a8d6-2520d7dc592dBuilds on13
- Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy PeripheralsA. Theodore Markettos, Colin Rothwell, Brett F. Gutstein, Allison Pearce et al.NDSS 2019 · 97 citations
- SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux KernelYueqi Chen, Xinyu XingCCS 2019 · 76 citations
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM ArchitecturesKha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon LeeCCS 2023 · 5 citations
- Adaptive CHERI Compartmentalization for Heterogeneous AcceleratorsJianyi Cheng, A. Theodore Markettos, Alexandre Joannou, Paul Metzger et al.ISCA 2025 · 4 citations
Related papers
- Low-Cost Privilege Separation with Compile Time Compartmentalization for Embedded SystemsArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading AttacksXinhui Shao, Zhen Ling, Yue Zhang, Huaiyu Yan et al.USENIX Security 2025
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- RT-TEE: Real-time System Availability for Cyber-physical Systems using ARM TrustZoneJinwen Wang, Ao Li, Haoran Li, Chenyang Lu et al.S&P 2022 · 69 citations
