D-Box: DMA-enabled Compartmentalization for Embedded Applications

D-Box: DMA-enabled Compartmentalization for Embedded Applications
复制标题

DOI:
10.14722/ndss.2022.24053
复制
发表时间:
2022-01
期刊:
ArXiv
影响因子:
--
通讯作者:
Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
中科院分区:
其他
文献类型:
--
作者:
Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu

文献摘要

被引文献

相似文献

嵌入式和物联网(IoT)设备在许多领域的采用率都有所增加。这些设备的安全性非常重要,因为它们通常用于控制关键基础设施、医疗设备和车辆。隔离微控制器(MCU)资源以提高其安全性的现有解决方案面临重大挑战,例如特定硬件不可用、存储器保护单元(MPU)限制以及严重缺乏直接存储器访问(DMA)支持。然而,DMA是嵌入式应用的功耗和性能要求的基础。在本文中,我们提出了D-Box,这是一种系统性方法,可以为使用实时操作系统(RTOS)的嵌入式应用程序的分区解决方案实现安全DMA操作。D-Box定义了一个参考体系结构和工作流程,以全面保护DMA操作。它提供了实用的方法来强化内核,并定义基于功能的安全策略,以便轻松定义具有强大安全属性的DMA操作。我们在流行的FreeRTOS-MPU(F-MPU)之上实现了Cortex-M3/M4的D-Box原型。D-Box程序和更严格的安全模型支持DMA操作,但与标准F-MPU相比,它暴露的ROP(返回定向编程)小工具少了41倍。D-Box仅增加了2%的处理器开销,同时将外围操作基准的功耗降低了18.2%。D-Box的安全属性和性能在可编程逻辑控制器(PLC)应用的真实案例研究中进行了测试和确认。
Embedded and Internet-of-Things (IoT) devices have seen an increase in adoption in many domains. The security of these devices is of great importance as they are often used to control critical infrastructure, medical devices, and vehicles. Existing solutions to isolate microcontroller (MCU) resources in order to increase their security face significant challenges such as specific hardware unavailability, Memory Protection Unit (MPU) limitations and a significant lack of Direct Memory Access (DMA) support. Nevertheless, DMA is fundamental for the power and performance requirements of embedded applications. In this paper, we present D-Box, a systematic approach to enable secure DMA operations for compartmentalization solutions of embedded applications using real-time operating systems (RTOS). D-Box defines a reference architecture and a workflow to protect DMA operations holistically. It provides practical methods to harden the kernel and define capability-based security policies for easy definition of DMA operations with strong security properties. We implemented a D-Box prototype for the Cortex-M3/M4 on top of the popular FreeRTOS-MPU (F-MPU). The D-Box procedures and a stricter security model enabled DMA operations, yet it exposed 41 times less ROP (return-orienting-programming) gadgets when compared with the standard F-MPU. D-Box adds only a 2% processor overhead while reducing the power consumption of peripheral operation benchmarks by 18.2%. The security properties and performance of D-Box were tested and confirmed on a real-world case study of a Programmable Logic Controller (PLC) application.