USENIX Security2026Top-tier venue
ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical Systems
Ruizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang, Yunbo Wang
Abstract
Real-time embedded systems are prevalent in cyber-physical applications such as drones and autonomous vehicles. Due to their high complexity, the environmental uncertainties, and the openness to remote control, these systems are vulnerable to control-flow hijacking and data-only attacks that compromise runtime integrity and reliability. Traditional control-flow integrity (CFI) and data-flow integrity (DFI) approaches impose excessive overhead, while the control-flow attestation (CFA) allows detection latency incompatible with real-time constraints. This paper presents ARTO, the first control-flow and data-flow protection approach that integrates the control-flow attestation to provide strong security with competitive runtime overhead. Through the prover-side path segmentation and hash-based validation result caching, ARTO provides partial context-sensitive protection at minimal runtime cost, offloading complete context-sensitive detection to the remote verifier. Furthermore, ARTO implements an equivalence-class-based data-flow protection that combines the address-based target check for memory reads with the value-based checks to protect critical variables, stronger than the SOTA operation integrity enforcement in validating the read source for critical variables. Extensive evaluations on robotic vehicle autopilots confirm ARTO's efficacy in mitigating both control-flow and data-only attacks while maintaining runtime overhead within real-time limits, outperforming SOTA CFA and operation-integrity enforcement methods in operation execution time.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d60d20f1-a9c5-4c22-89eb-68871feb5c4bBuilds on17
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- Enforcing Unique Code Target Property for Control-Flow IntegrityHong Hu, Chenxiong Qian, Carter Yagemann, Simon Pak Ho Chung et al.CCS 2018 · 142 citations
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu et al.NDSS 2018 · 127 citations
- Efficient Protection of Path-Sensitive Control SecurityRen Ding, Chenxiong Qian, Chengyu Song, William Harris et al.USENIX Security 2017 · 123 citations
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava et al.S&P 2017 · 122 citations
Related papers
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 89 citations
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah et al.USENIX Security 2024 · 8 citations
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
- ARI: Attestation of Real-time Mission Execution IntegrityJinwen Wang, Yujie Wang, Ao Li, Yang Xiao et al.USENIX Security 2023
- DIALED: Data Integrity Attestation for Low-end Embedded DevicesIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Gene TsudikDAC 2021 · 27 citations
