An REE-independent Approach to Identify Callers of TEEs in TrustZone-enabled Cortex-M Devices

Antonio Ken Iannillo, Sean Rivera, Darius Suciu, Radu Sion, Radu State · 2022

Internet of Things (IoT) devices are becoming increasingly ubiquitous in our lives, from personal health monitoring to house and factory management. Further, IoT devices are becoming increasingly complex, and ensuring their security is of paramount importance. As a result, they started to include Trusted Execution Environments (TEEs) to protect security-critical IoT operations. This paper focuses on improving the security of the next-generation IoT devices by introducing Secure Informer, an identification and authentication mechanism for ARM TrustZone for Cortex-M. Under Secure Informer, the TEE can directly determine the Rich Execution Environment (REE) context without introducing additional communication or dependency on the REE software stack. We implement our solution for ARMV8-M architecture, showing its efficacy with no need to change the source code of the REE. Empirical results show that Secure Informer can help mitigate confused deputy attacks targeting TEE-running services while only incurring an average 3.2% overhead on the device performance and requiring an additional 464 lines (52 bytes in the compiled binary file) to the TEE.

Read the paper · More papers on PaperTik