Demystifying Pointer Authentication on Apple M1
Zechao Cai, Jiaxun Zhu, Wenbo Shen, Yutian Yang, Rui Chang, Yu Wang, Jinku Li, Kui Ren
摘要
Pointer Authentication (PA) was introduced by ARMv8.3 to safeguard the integrity of pointers. While the ARM specification allows vendors to implement and customize PA, Apple has tailored it on their hardware to protect iPhones and Macs with M-series chips. Since its debut, Apple PA has been considered effective in defeating pointer corruption. However, its details have not been publicly disclosed. To shed light on Apple PA customization, this paper conducts an in-depth reverse engineering study focused on Apple PA's hardware implementation and usage on the M1 chip. We develop a reverse engineering framework and propose novel techniques to uncover and confirm our new findings. Our study uncovers that Apple PA has implemented several hardware-based diversifiers to counter pointer forgery attacks across various domains, which is previously unknown to researchers outside of Apple. We further discover that the XNU kernel (the kernel used by iOS and macOS) incorporates nine types of modifiers for signing and authenticating pointers and customized key management based on Apple PA hardware. Based on our in-depth understanding of Apple PA, we perform a security analysis of PA-based control-flow integrity and data-flow integrity in the XNU kernel, identifying four attack surfaces. Apple has fixed these issues in a security update and assigned us a new CVE.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- On Bridging the Gap between Control Flow Integrity and Attestation SchemesMahmoud Ammar, Ahmed Abdelraoof, Silviu VlasceanuUSENIX Security 2024 · 被引用 9 次
- PeTAL: Ensuring Access Control Integrity against Data-only Attacks on LinuxJuhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song 等CCS 2024 · 被引用 6 次
- iEnFlow: Endogenous Control-Flow Attacks via Conditional Branch Prediction on Apple SiliconKaiyuan Rong, Jiajie Chen, Junqi Fang, Peng Qu 等CCS 2026
- Lippen: a Lightweight in-Place Pointer Encryption Architecture for Pointer IntegrityErfan Iravani, Lalit Prasad Peri, Mohannad Ismail, Charitha Tumkur Siddalingaradhya 等ISCA 2026
- Demystifying the Access Control Mechanism of ESXi VMKernelYue Liu, Zexiang Zhang, Jiaxun Zhu, Hao Zheng 等NDSS 2026
它引用的顶会 Paper4
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- PACStack: an Authenticated Call StackHans Liljestrand, Thomas Nyman, Lachlan J. Gunn, Jan-Erik Ekberg 等USENIX Security 2021 · 被引用 63 次
- PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer AuthenticationYuan Li, Wende Tan, Zhizheng Lv, Songtao Yang 等CCS 2022 · 被引用 30 次
- Tightly Seal Your Sensitive Pointers with PACTightMohannad Ismail, Andrew Quach, Christopher Jelesnianski, Yeongjin Jang 等USENIX Security 2022
相关 Paper
- In-Kernel Control-Flow Integrity on Commodity OSes using ARM Pointer AuthenticationSungbae Yoo, Jinbum Park, Seolheui Kim, Yeji Kim 等USENIX Security 2022
- PACMAN: attacking ARM pointer authentication with speculative executionJoseph Ravichandran, Weon Taek Na, Jay Lang, Mengjia YanISCA 2022 · 被引用 68 次
- Fractal: An Operating System Designed for Microarchitecture Reverse EngineeringJoseph Ravichandran, Mengjia YanS&P 2026
- POP and PUSH: Demystifying and Defending against (Mach) Port-oriented ProgrammingMin Zheng, Xiaolong Bai, Yajin Zhou, Chao Zhang 等NDSS 2021
- Camouflage: Hardware-assisted CFI for the ARM Linux kernelRémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik EkbergDAC 2020 · 被引用 18 次
