Mind the Gap: Studying the Insecurity of Provably Secure Embedded Trusted Execution Architectures
Marton Bognar, Jo Van Bulck, Frank Piessens
Abstract
The security claims of a system can be supported or refuted by different kinds of evidence. On the one hand, attack research uses empirical, experimental, inductive methods to refute security claims. If motivated and competent attackers do not succeed in breaking a specific security property, this provides some support (but no definite proof) that the system is secure.
On the other hand, formal methods use mathematical, deductive methods that can prove the security of a model of the system. The process of constructing a proof can uncover vulnerabilities that can then be fixed. The use of formal methods can be very powerful and is attractive because it seems to provide irrefutable evidence of security. However, that evidence applies only to the mathematical model, not to any actual system, and, hence, it is important to understand the gap between the model and the real-world system.
In this paper, we present a case study that examines this gap for two embedded security architectures that use formal methods to prove their security properties. Despite strong formal evidence for security, we discover numerous attacks against the implementations, all of which falsify proven security properties. These attacks range from exploiting simple programming errors to a novel DMA-based side-channel attack. The simple attacks demonstrate that the construction of systems and proofs is errorprone, while some of the more sophisticated attacks serve as examples to show that formal methods alone can never guarantee the security of a real-world system.
From our case study, we also distill actionable guidelines on how to provide stronger evidence for the security of a system.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f7077641-1ef5-457d-b146-7933c52695f1Cited by top-tier papers10
- BUSted!!! Microarchitectural Side-Channel Attacks on the MCU Bus InterconnectCristiano Rodrigues, Daniel Oliveira, Sandro PintoS&P 2024 · 15 citations
- Intellectual Property Exposure: Subverting and Securing Intellectual Property Encapsulation in Texas Instruments MicrocontrollersMarton Bognar, Cas Magnus, Frank Piessens, Jo Van BulckUSENIX Security 2024 · 4 citations
- Libra: Architectural Support For Principled, Secure And Efficient Balanced Execution On High-End ProcessorsHans Winderix, Marton Bognar, Lesly-Ann Daniel, Frank PiessensCCS 2024 · 4 citations
- MCU-Wide Timing Side Channels and Their DetectionJohannes Müller, Anna Lena Duque Antón, Lucas Deutschmann, Dino Mehmedagic et al.DAC 2024 · 1 citation
- Cerisier: A Program Logic for Attestation in a Capability MachineJune Rousseau, Denis Carnier, Thomas Van Strydonck, Steven Keuchel et al.PLDI 2026
Builds on15
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- HACL*: A Verified Modern Cryptographic LibraryJean Karim Zinzindohoué, Karthikeyan Bhargavan, Jonathan Protzenko, Benjamin BeurdoucheCCS 2017 · 258 citations
Related papers
- Security Verification of Low-Trust ArchitecturesQinhan Tan, Yonathan Fisseha, Shibo Chen, Lauren Biernacki et al.CCS 2023 · 5 citations
- Impeccable Circuits IIAein Rezaei Shahmirzadi, Shahram Rasoolzadeh, Amir MoradiDAC 2020 · 34 citations
- Specification and Verification of Strong Timing Isolation of Hardware EnclavesStella Lau, Thomas Bourgeat, Clément Pit-Claudel, Adam ChlipalaCCS 2024 · 1 citation
- Sockeye: Bug-finding and proofs for platform configurations and hardware based on reference manualsBen Fiedler, Sedan Abdelgawad, Teymour Aldridge, Viktor Fukala et al.SOSP 2026
- HardFails: Insights into Software-Exploitable Hardware BugsGhada Dessouky, David Gens, Patrick Haney, Garrett Persyn et al.USENIX Security 2019 · 149 citations
