Ambassy: A Runtime Framework to Delegate Trusted Applications in an ARM/FPGA Hybrid System

Dongil Hwang, Sanzhar Yeleuov, Jiwon Seo, Minu Chung, Hyungon Moon, Yunheung Paek · IEEE Transactions on Mobile Computing · 2021

Many mobile systems run on ARM-based devices today. People use these for increasingly diverse yet security-sensitive applications. ARM has adopted a security model to tackle this threat, where they manage private information in an isolatedtrusted execution environment(TEE) provided byTrustZone. This TrustZone-based model has been proven effective, but due to security concerns, it is available solely for the vendor's applications, thereby hindering the broad use of TrustZone. Consequently, we propose a runtime framework backed by TrustZone to construct a secondary TEE.Ambassyhas its residence built on an on-chip field-programmable gate array (FPGA), which is a standard component in anARM/FPGA hybridsystem readily available on the market today. This study, to the best of our knowledge, is the first attempt to broaden the use of TrustZone by using an FPGA to build a secondary TEE for arbitrary third-parties, which otherwise should be expelled to the Normal World. This paper describes many design challenges that we have overcome to fully implementAmbassyon an FPGA. Our experiments demonstrate the practicality ofAmbassyby presenting the security analysis and performance results of third-party application samples. The samples all run safely onAmbassy, with shorter execution times than regular TEE applications in TrustZone (by a factor of 5.5–52).

Read the paper · More papers on PaperTik