arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SMARM+:分析与增强实时物联网环境中用于远程认证的混洗测量

SMARM+: Analyzing and Enhancing Shuffled Measurements for Remote Attestation in Real-Time IoT Settings

Amarin Laohajirapan, Norrathep Rattanavipanon

arXiv 2607.23698首次发表:更新:

AI 中文总结

研究实时物联网环境中远程认证的SMARM,在运行FreeRTOS和Zephyr的硬件上实现并引入FAR量化其实时兼容性。发现其对块大小敏感,进而提出SMARM+,包含SMARM+PRNG和SMARM+FPE,权衡安全存储减少、认证运行时和能量开销,为不同部署提供选择指导。

AI 中文摘要

远程认证(RA)是检测物联网设备软件受损的轻量级安全原语。传统RA方案需要原子、不可中断的内存测量,难以与实时工作负载并行部署。SMARM通过按秘密、混洗的块顺序测量内存来解决此限制,将不可中断周期缩短为单个块测量的持续时间。但SMARM最初为基于微内核的系统设计,未在RTOS驱动的实时环境中研究。本文首次对基于实时RTOS的设置中的SMARM进行系统研究,在运行FreeRTOS和Zephyr的商用ARM TrustZone-M硬件上实现SMARM,并引入频率准确率(FAR)量化不同工作负载下认证与实时执行共存的程度。评估表明SMARM的实时兼容性对块大小高度敏感。为解决此限制,提出SMARM+,包括SMARM+PRNG和SMARM+FPE,旨在降低安全存储需求,同时保留SMARM的安全保证和实时行为。评估突出了安全存储减少、认证运行时和能量开销之间的权衡,并为不同部署设置在SMARM、SMARM+PRNG和SMARM+FPE之间的选择提供指导。

英文摘要

Remote attestation (RA) is a lightweight security primitive for detecting software compromise on IoT devices. Traditional RA schemes require atomic, non-interruptible memory measurements, making them difficult to deploy alongside real-time workloads. SMARM addresses this limitation by measuring memory in a secret, shuffled block order, reducing the non-interruptibility period to the duration of a single block measurement. However, SMARM was originally designed for microkernel-based systems and has not been studied in RTOS-driven real-time environments. In this work, we present the first systematic study of SMARM in real-time RTOS-based setups. We implement SMARM on commodity ARM TrustZone-M hardware running FreeRTOS and Zephyr, and introduce the Frequency Accuracy Ratio (FAR) to quantify the extent to which attestation can coexist with real-time execution under varying workloads. Our evaluation shows that SMARM's real-time compatibility is highly sensitive to block size: large blocks significantly degrade real-time availability, while small blocks incur substantial secure-storage overhead, limiting deployability on memory-constrained devices. To address this limitation, we propose SMARM+, a family of enhanced SMARM variants consisting of SMARM+PRNG and SMARM+FPE. They are designed to reduce secure-storage requirements while preserving SMARM's security guarantees and real-time behavior. Our evaluation highlights the trade-off between secure-storage reduction, attestation runtime, and energy overhead, and provides guidance on selecting among SMARM, SMARM+PRNG, and SMARM+FPE for different deployment settings.

CommentsSubmitted to IEEE Access

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑