Whole-Program Control-Flow Path Attestation
Nikita Yadav, Vinod Ganapathy
Abstract
Path attestation is an approach to remotely attest the execution of a program P. In path attestation, a prover platform, which executes P, convinces a remote verifier V of the integrity of P by recording the path that P takes as it executes a particular input. While a number of prior techniques have been developed for path attestation, they have generally been applied to record paths only for parts of P's execution. In this paper, we consider the problem of whole program control-flow path attestation, i.e., to attest the execution of the entire program path in P. We show that prior approaches for path attestation use sub-optimal techniques that fundamentally fail to scale to whole program paths, and impose a large runtime overhead on the execution of P. We then develop Blast, an approach that reduces these overheads using a number of novel approaches inspired by prior work from the program profiling literature. Our experiments show that Blast makes path attestation more practical for use on a wide variety of embedded programs. CCS CONCEPTS • Security and privacy → Embedded systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f2b1e252-1b55-4d23-af9f-50b14117a79eCited by top-tier papers6
- One for All and All for One: GNN-based Control-Flow Attestation for Embedded DevicesMarco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn et al.S&P 2024 · 11 citations
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 9 citations
- SoK: Integrity, Attestation, and Auditing of Program ExecutionMahmoud Ammar, Adam Caulfield, Ivan De Oliveira NunesS&P 2025
- TAT: Attesting Trajectory Integrity of Industrial Robotic ArmsChengtao Yao, Chengcheng Zhao, Peng Cheng, Jiming ChenUSENIX Security 2026
- EXIA: Trusted Transitions for Enclaves via External-Input AttestationZhen Huang, Yidi Kao, Sanchuan Chen, Guoxing Chen et al.NDSS 2026
Builds on9
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- VRASED: A Verified Hardware/Software Co-Design for Remote AttestationIvan De Oliveira Nunes, Karim Eldefrawy, Norrathep Rattanavipanon, Michael Steiner et al.USENIX Security 2019 · 135 citations
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu et al.NDSS 2018 · 127 citations
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava et al.S&P 2017 · 122 citations
Related papers
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 89 citations
- RAP-Track: Efficient Control Flow Attestation via Parallel Tracking in Commodity MCUsAntonio Joia Neto, Adam Caulfield, Ivan De Oliveira NunesDAC 2025 · 1 citation
- DIALED: Data Integrity Attestation for Low-end Embedded DevicesIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Gene TsudikDAC 2021 · 27 citations
- ARTO: Efficient Execution Integrity Attestation for Real-Time Operation of Cyber-Physical SystemsRuizhe Zhao, Cong Sun, Zongzhen Li, Tiantian Wang et al.USENIX Security 2026
- ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow AttestationAdam Caulfield, Norrathep Rattanavipanon, Ivan De Oliveira NunesUSENIX Security 2023
