DIALED: Data Integrity Attestation for Low-end Embedded Devices
Ivan De Oliveira Nunes, Sashidhar Jakkamsetti, Gene Tsudik
Abstract
Verifying integrity of software execution in low-end microcontroller units (MCUs) is a well-known open problem. The central challenge is how to securely detect software exploits with minimal overhead, since these MCUs are designed for low cost, low energy and small size. Some recent work yielded inexpensive hardware/software co-designs for remotely verifying code and execution integrity. In particular, a means of detecting unauthorized code modifications and control-flow attacks were proposed, referred to as Remote Attestation (RA) and Control-Flow Attestation (CFA), respectively. Despite this progress, detection of dataonly attacks remains elusive. Such attacks exploit software vulnerabilities to corrupt intermediate computation results stored in data memory, changing neither the program code nor its control flow. Motivated by lack of any current techniques (for low-end MCUs) that detect these attacks, in this paper we propose, implement and evaluate DIALED 1 , the first Data-Flow Attestation (DFA) technique applicable to the most resource-constrained embedded devices (e.g., TI MSP430). DIALED works in tandem with a companion CFA scheme to detect all (currently known) types of runtime software exploits at fairly low cost.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d7c4f6d6-9403-4f33-be1b-dba4ffb3601dCited by top-tier papers10
- Privacy-from-Birth: Protecting Sensed Data from Malicious Sensors with VERSAIvan De Oliveira Nunes, Seoyeon Hwang, Sashidhar Jakkamsetti, Gene TsudikS&P 2022 · 11 citations
- ASAP: reconciling asynchronous real-time operations and proofs of execution in simple embedded systemsAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesDAC 2022 · 7 citations
- Caveat (IoT) Emptor: Towards Transparency of IoT Device PresenceSashidhar Jakkamsetti, Youngil Kim, Gene TsudikCCS 2023 · 5 citations
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
- TAT: Attesting Trajectory Integrity of Industrial Robotic ArmsChengtao Yao, Chengcheng Zhao, Peng Cheng, Jiming ChenUSENIX Security 2026
Builds on5
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- VRASED: A Verified Hardware/Software Co-Design for Remote AttestationIvan De Oliveira Nunes, Karim Eldefrawy, Norrathep Rattanavipanon, Michael Steiner et al.USENIX Security 2019 · 135 citations
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 89 citations
- APEX: A Verified Architecture for Proofs of Execution on Remote Devices under Full Software CompromiseIvan De Oliveira Nunes, Karim Eldefrawy, Norrathep Rattanavipanon, Gene TsudikUSENIX Security 2020
Related papers
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
- IDA: Hybrid Attestation with Support for Interrupts and TOCTOUFatemeh Arkannezhad, Justin Feng, Nader SehatbakhshNDSS 2024
- ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical SystemsRuizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang et al.USENIX Security 2026
- Intellectual Property Exposure: Subverting and Securing Intellectual Property Encapsulation in Texas Instruments MicrocontrollersMarton Bognar, Cas Magnus, Frank Piessens, Jo Van BulckUSENIX Security 2024 · 4 citations
- One for All and All for One: GNN-based Control-Flow Attestation for Embedded DevicesMarco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn et al.S&P 2024 · 11 citations
