USENIX Security2026Top-tier venue
XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-M
Yunju Gu, Jaeyeol Park, Donghyun Kwon
Abstract
Arm TrustZone-M (TZ-M) provides hardware-based isolation for tiny embedded systems by partitioning execution into secure and non-secure states. However, despite this isolation, memory vulnerabilities in software running within either state can still be exploited to perform control-flow hijacking attacks. To mitigate these threats, numerous control-flow integrity (CFI) studies have been proposed for embedded systems, but they have several limitations: many neglect the secure state, fail to protect control-flow events during TZ-M security state transitions, or incur prohibitive performance overhead.
In this paper, we present XCFI, a comprehensive CFI mechanism for TZ-M. XCFI employs a 32-bit control-flow identifier (CID) based protection to uniformly enforce fine-grained CFI across both secure and non-secure states, covering all control-flow events, including indirect branches, returns, and exceptions. Crucially, XCFI extends CFI enforcement to cross-state control-flow events in TZ-M, which have not been protected by prior work. Overall, XCFI provides comprehensive control-flow protection across all TZ-M execution contexts while incurring only modest runtime overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on19
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski et al.S&P 2016 · 227 citations
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez et al.USENIX Security 2019 · 168 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
Related papers
- Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and DefenseZheyuan Ma, Xi Tan, Lukasz Ziarek, Ning Zhang et al.DAC 2023 · 8 citations
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 13 citations
- TZ-DATASHIELD: Automated Data Protection for Embedded Systems via Data-Flow-Based CompartmentalizationZelun Kong, Minkyung Park, Le Guan, Ning Zhang et al.NDSS 2025
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma et al.USENIX Security 2020
- MyTEE: Own the Trusted Execution Environment on Embedded DevicesSeung-Kyun Han, Jinsoo JangNDSS 2023
