Cache-in-the-Middle (CITM) Attacks: Manipulating Sensitive Data in Isolated Execution Environments
Jie Wang, Kun Sun, Lingguang Lei, Shengye Wan, Yuewu Wang, Jiwu Jing
Abstract
The traditional usage of ARM TrustZone has difficulty on solving the conflicts between the manufacturers that want to minimize the trusted computing base by constraining the installation of third-party applications in the secure world and the third-party application developers who prefer to have the freedom of installing their applications into the secure world. To address this issue, researchers propose to create Isolated Execution Environments (called IEEs) in the normal world to protect the security-sensitive applications. In this paper, we perform a systematic study on the IEE data protection models and the ARM cache attributes, and discover three cache-based attacks called CITM that can be leveraged to manipulate the sensitive data protected in IEEs. Specifically, due to the inefficient and incoherent security measures on the cache that maps to the IEE memory (i.e., memory designated for IEEs), attackers in the normal world may compromise the security of IEE data by manipulating the IEE memory during concurrent execution, bypassing the security measures enforced when a security-sensitive application is suspended or finished, or misusing the incomplete security measures during IEE's context switching processes. We conduct case studies of CITM attacks on three well-known IEE systems including SANCTUARY, Ginseng, and TrustICE to illustrate the feasibility to exploit them on real hardware testbeds. Finally, we analyze the root causes of the CITM attacks and propose a countermeasure to defeat them. The experimental results show that our defense scheme has a small overhead.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get fc32b556-098a-4ad8-8b7e-e71c707d36ffCited by top-tier papers6
- Spill the TeA: An Empirical Study of Trusted Application Rollback Prevention on Android SmartphonesMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 8 citations
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 4 citations
- Reconstruct Your Previous Conversations! Comprehensively Investigating Privacy Leakage Risks in Conversations with GPT ModelsJunjie Chu, Zeyang Sha, Michael Backes, Yang ZhangEMNLP 2024 · 3 citations
- FortifyPatch: Towards Tamper-Resistant Live Patching in Linux-Based HypervisorZhenyu Ye, Lei Zhou, Fengwei Zhang, Wenqiang Jin et al.ISSTA 2024 · 1 citation
- TEEzz: Fuzzing Trusted Applications on COTS Android DevicesMarcel Busch, Aravind Machiry, Chad Spensky, Giovanni Vigna et al.S&P 2023
Related papers
- SANCTUARY: ARMing TrustZone with User-space EnclavesFerdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi et al.NDSS 2019 · 191 citations
- CaSE: Cache-Assisted Secure Execution on ARM ProcessorsNing Zhang, Kun Sun, Wenjing Lou, Yiwei Thomas HouS&P 2016 · 104 citations
- Hardware-Backed Heist: Extracting ECDSA Keys from Qualcomm's TrustZoneKeegan RyanCCS 2019 · 90 citations
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao et al.NDSS 2026 · 4 citations
- Ginseng: Keeping Secrets in Registers When You Distrust the Operating SystemMin Hong Yun, Lin ZhongNDSS 2019 · 48 citations
