ISC-FLAT: On the Conflict Between Control Flow Attestation and Real-Time Operations

ISC-FLAT: On the Conflict Between Control Flow Attestation and Real-Time Operations
复制标题

DOI:
10.1109/rtas58335.2023.00018
复制
发表时间:
2023-03
期刊:
2023 IEEE 29th Real-Time and Embedded Technology and Applications Symposium (RTAS)
影响因子:
--
通讯作者:
Antonio Joia Neto;I. O. Nunes
Antonio Joia Neto;I. O. Nunes
中科院分区:
其他
文献类型:
--
作者:
Antonio Joia Neto;I. O. Nunes

文献摘要

被引文献

相似文献

物联网小工具和网络物理系统(CPS)的广泛采用使嵌入式设备越来越重要。对于通用计算机,使它们更容易受到可能破坏其软件完整性的远程利用。提出的技术可以远程评估嵌入式MCU软件的可信度进步,当前的CFA方法具有基本的限制:它们在执行的软件操作中被证明是简单地说的CFA技术是不安全的,除非在MCU上打断中断。我们提出了中断安全控制流的认证(ISC-FLAT):与现有MCU兼容的CFA技术(即,不需要硬件更改)并在不损害CFA报告的真实性的情况下启用中断处理。为了安全地生成不可原谅的CFA报告,而无需排除处理中断的应用程序。与现有的基于TEE的CFA方法相比,Cortex-M33 MCU并证明它会导致最小的运行时开销,而CFA方法不支持中断。
The wide adoption of IoT gadgets and CyberPhysical Systems (CPS) makes embedded devices increasingly important. While some of these devices perform mission-critical tasks, they are usually implemented using Micro-Controller Units (MCUs) that lack security mechanisms on par with those available to general-purpose computers, making them more susceptible to remote exploits that could corrupt their software integrity. Motivated by this problem, prior work has proposed techniques to remotely assess the trustworthiness of embedded MCU software. Among them, Control Flow Attestation (CFA) enables remote detection of runtime abuses that illegally modify the program’s control flow during execution (e.g., control flow hijacking and code reuse attacks). Despite these advances, current CFA methods share a fundamental limitation: they preclude interrupts during the execution of the software operation being attested. Simply put, existing CFA techniques are insecure unless interrupts are disabled on the MCU. On the other hand, we argue that the lack of interruptability can obscure CFA usefulness, as most embedded applications depend on interrupts to process asynchronous events in real-time. To address this limitation, we propose Interrupt-Safe Control Flow Attestation (ISC-FLAT): a CFA technique that is compatible with existing MCUs (i.e., does not require hardware changes) and enables interrupt handling without compromising the authenticity of CFA reports. Similar to other CFA techniques that do not require customized hardware modifications, ISC-FLAT leverages a Trusted Execution Environment (TEE) (in particular, our prototype is built on ARM TrustZone-M) to securely generate unforgeable CFA reports without precluding applications from processing interrupts. We implement a fully functional ISC-FLAT prototype on the ARM Cortex-M33 MCU and demonstrate that it incurs minimal runtime overhead when compared to existing TEE-based CFA methods that do not support interrupts.