Contributions à la sécurité des logiciels embarqués dans la chaîne de confiance

Bouffard, Guillaume · HAL (Le Centre pour la Communication Scientifique Directe) · 2025

This habilitation thesis (HDR) focuses on securing software in embedded systems through the concept of a Chain of Trust (CoT). When I began my research in 2011, the protection of sensitive operations primarily relied on smart cards, the main example of a hardware Root of Trust (RoT). These minimalist devices provided high security with very low power consumption, at the cost of limited performance. Their principles were later extended to Secure Elements (SEs), which are now standard hardware RoTs.From 2016, the growing complexity of embedded systems and increasing performance demands led to a shift of critical operations to Trusted Execution Environments (TEEs) running on application processors. These architectures now rely on a CoT rooted in the hardware RoT.This manuscript presents my contributions to the analysis and hardening of embedded software across the CoT: the hardware RoT, the TEE, and the Rich Execution Environment (REE). I first investigated SEs, especially Java Card platforms, as well as the security of their interfaces and underlying hardware.I then extended this work to TEEs, typically implemented by sharing the application processor with the REE to balance performance and energy efficiency. As with SEs, hardware robustness is key. I analyze the impact of fault injection attacks on existing TEEs.Finally, in modern systems, access to TEE or SE functionality is often limited for third-party developers. Sensitive applications must therefore run in the REE, an untrusted environment. I studied their vulnerability to white-box attacks and explored software-level countermeasures, such as code obfuscation, to improve resilience and enhance the overall security of the CoT.

Read the paper · More papers on PaperTik