Lune

USENIX Security2026Top-tier venue

XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-M

Yunju Gu, Jaeyeol Park, Donghyun Kwon

2026Year

Abstract

Arm TrustZone-M (TZ-M) provides hardware-based isolation for tiny embedded systems by partitioning execution into secure and non-secure states. However, despite this isolation, memory vulnerabilities in software running within either state can still be exploited to perform control-flow hijacking attacks. To mitigate these threats, numerous control-flow integrity (CFI) studies have been proposed for embedded systems, but they have several limitations: many neglect the secure state, fail to protect control-flow events during TZ-M security state transitions, or incur prohibitive performance overhead.

In this paper, we present XCFI, a comprehensive CFI mechanism for TZ-M. XCFI employs a 32-bit control-flow identifier (CID) based protection to uniformly enforce fine-grained CFI across both secure and non-secure states, covering all control-flow events, including indirect branches, returns, and exceptions. Crucially, XCFI extends CFI enforcement to cross-state control-flow events in TZ-M, which have not been protected by prior work. Overall, XCFI provides comprehensive control-flow protection across all TZ-M execution contexts while incurring only modest runtime overhead.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on19

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines