Trust-V: Toward Secure and Reliable Storage for Trusted Execution Environments
Seung-Kyun Han, Jiyeon Yang, Jinsoo Jang
Abstract
Trusted execution environments (TEEs) provide strong isolation for security-critical applications (enclaves) and their runtime data from potentially malicious operating systems. While TEEs also support secure storage by sealing data and storing it persistently on media, they do not ensure the integrity of sealed data, leaving it vulnerable to deletion or manipulation by an untrusted OS. In this work, we present Trusted Storage, a runtime storage isolation mechanism for TEEs that guarantees the integrity of TEE persistent data. The core design partitions storage into trusted and untrusted regions and enforces access control by locking MMIO regions and monitoring block I/O. To ensure portability, Trusted Storage requires no hardware modifications or additional hardware. We implemented a prototype, Trust-V, on the RISC-V platform. In particular, to support secure operation on legacy devices where security features are limited, Trust-V introduces a Virtual-M mode, a sandboxed privileged execution environment in machine mode, for securely hosting the monitor. Our evaluation demonstrates that, although Trust-V incurs up to 3.86× system overhead, it allows TEE software to reliably store and retrieve persistent data.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d7e64446-6103-482e-a359-382b168885feRelated papers
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig et al.DAC 2022 · 11 citations
- Dorami: Privilege Separating Security Monitor on RISC-V TEEsMark Kuhne, Stavros Volos, Shweta ShindeUSENIX Security 2025
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution EnvironmentsMoein Ghaniyoun, Kristin Barber, Yuan Xiao, Yinqian Zhang et al.ISCA 2023 · 6 citations
- Elasticlave: An Efficient Memory Model for EnclavesJason Zhijingcheng Yu, Shweta Shinde, Trevor E. Carlson, Prateek SaxenaUSENIX Security 2022
