openIPE: An Extensible Memory Isolation Framework for Microcontrollers
Márton Bognár, Jo Van Bulck · 2025
Given the popularity of low-end microcontrollers, manufacturers and researchers have proposed memory isolation mechanisms for these devices. However, current proposals face two main shortcomings. First, due to a lack of extensible reference implementations of commercial specifications, academic systems commonly use custom memory isolation mechanisms, reducing compatibility and the chance of real-world adoption. Second, recent research has demonstrated crucial and overlapping vulnerabilities, including in commercial systems. Unfortunately, efforts to mitigate and validate these issues are hindered by the disconnect in codebases.This paper proposes openIPE, an open research platform for extensible, industry-compliant hardware-software co-designs. Our platform introduces minimal hardware extensions for memory isolation based on Texas Instruments’ specification for Intellectual Property Encapsulation (IPE), alongside a versatile firmware layer enabling rapid prototyping of advanced security extensions. We establish a robust security testing infrastructure and demonstrate the capabilities of our framework through a comprehensive study on secure interrupt handling, an important research area for microcontrollers. Our evaluation shows that openIPE allows for the independent reproduction and comparison of existing proposals and enables a novel solution that achieves strong architectural and microarchitectural security with minimal hardware modifications and low overhead.