On Runtime Software Security of TrustZone-M Based IoT Devices

On Runtime Software Security of TrustZone-M Based IoT Devices
复制标题

DOI:
10.1109/globecom42002.2020.9322370
复制
发表时间:
2020-07
期刊:
GLOBECOM 2020 - 2020 IEEE Global Communications Conference
影响因子:
--
通讯作者:
Lan Luo;Yue Zhang;C. Zou;Xinhui Shao;Zhen Ling;Xinwen Fu
Lan Luo;Yue Zhang;C. Zou;Xinhui Shao;Zhen Ling;Xinwen Fu
中科院分区:
其他
文献类型:
--
作者:
Lan Luo;Yue Zhang;C. Zou;Xinhui Shao;Zhen Ling;Xinwen Fu

文献摘要

相似文献

物联网(IoT)设备日益融入我们的日常生活。然而,这类智能设备面临着广泛的攻击面。特别是,如果物联网设备使用资源受限微控制器(MCU),则在运行时针对设备软件的攻击是具有挑战性的。TrustZone-M是对MCU的TrustZone扩展,是一种加强基于MCU的物联网设备的新兴安全技术。本文首次对启用TrustZone-M的MCU中的潜在软件安全问题进行了安全分析。我们在TrustZone-M的上下文中探讨了针对代码注入的基于堆栈的缓冲区溢出(BOF)攻击、面向返回的编程(ROP)攻击、基于堆的BOF攻击、格式字符串攻击以及对非安全可调用(NSC)函数的攻击。我们使用使用ARM Cortex-M23处理器和TrustZone-M技术的微芯片SAM L11 MCU来验证这些攻击。文中还讨论了缓解这些软件攻击的策略。
Internet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension for MCUs, is an emerging security technique fortifying MCU based IoT devices. This paper presents the first security analysis of potential software security issues in TrustZone-M enabled MCUs. We explore the stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against Non-secure Callable (NSC) functions in the context of TrustZone-M. We validate these attacks using the Microchip SAM L11 MCU, which uses the ARM Cortex-M23 processor with the TrustZone-M technology. Strategies to mitigate these software attacks are also discussed.