XCFI: Comprehensive Control-Flow Integrity for Arm TrustZone-M
Yunju Gu, Jaeyeol Park, Donghyun Kwon
摘要
Arm TrustZone-M (TZ-M) provides hardware-based isolation for tiny embedded systems by partitioning execution into secure and non-secure states. However, despite this isolation, memory vulnerabilities in software running within either state can still be exploited to perform control-flow hijacking attacks. To mitigate these threats, numerous control-flow integrity (CFI) studies have been proposed for embedded systems, but they have several limitations: many neglect the secure state, fail to protect control-flow events during TZ-M security state transitions, or incur prohibitive performance overhead.
In this paper, we present XCFI, a comprehensive CFI mechanism for TZ-M. XCFI employs a 32-bit control-flow identifier (CID) based protection to uniformly enforce fine-grained CFI across both secure and non-secure states, covering all control-flow events, including indirect branches, returns, and exceptions. Crucially, XCFI extends CFI enforcement to cross-state control-flow events in TZ-M, which have not been protected by prior work. Overall, XCFI provides comprehensive control-flow protection across all TZ-M execution contexts while incurring only modest runtime overhead.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg 等CCS 2016 · 被引用 311 次
- A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelVictor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski 等S&P 2016 · 被引用 227 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
相关 Paper
- Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and DefenseZheyuan Ma, Xi Tan, Lukasz Ziarek, Ning Zhang 等DAC 2023 · 被引用 8 次
- SHERLOC: Secure and Holistic Control-Flow Violation Detection on Embedded SystemsXi Tan, Ziming ZhaoCCS 2023 · 被引用 13 次
- TZ-DATASHIELD: Automated Data Protection for Embedded Systems via Data-Flow-Based CompartmentalizationZelun Kong, Minkyung Park, Le Guan, Ning Zhang 等NDSS 2025
- Silhouette: Efficient Protected Shadow Stacks for Embedded SystemsJie Zhou, Yufei Du, Zhuojia Shen, Lele Ma 等USENIX Security 2020
- MyTEE: Own the Trusted Execution Environment on Embedded DevicesSeung-Kyun Han, Jinsoo JangNDSS 2023
