TZ-KPM:Kernel Protection Mechanism on Embedded Devices on Hardware-Assisted Isolated Environment
Xianyi Zheng, Yanhong He, Jiangang Ma, Gang Shi, Dan Meng · 2016
With the rapid development of network technology and the increasingly complexity of system function, the embedded system is facing more and more serious threats. Previous researches on kernel monitoring and protection widely relies on higher privileged system components, such as hardware virtualization extensions, to isolate security tools from potential kernel attacks. These approaches increase both the maintenance effort and the code base size of privileged system components, which consequently increases the risk of having security vulnerabilities. In this paper, we have proposed a kernel protection mechanism called TZ_KPM on TrustZone enabled platform. Our prototype can secure system execution environment and provide kernel code integrity protection and malicious process detection based on hardware-assisted isolated environment. At the same time, we secure the communication by shared memory and provide user identification to ensure that the system switches to the secure world safely. Additionally, we can ensure we call the services in the secure world safely by showing the tag on the interface of the called service based on the trusted GUI (TGUI). Thus, we can distinguish the fake interface made by the malicious attackers in the normal world. We have evaluated our prototype on a simulation environment by using ARM FastModel and presented our implementation on a real development by using ARM CoreTile Express A9x4. Our experiment result and security analysis show that TZ_KPM can be retrofitted to existing monolithic kernels, and provide important security benefits.