arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.13287cs.AR

ROLoad-PMP:为内核与裸机固件保护敏感操作

ROLoad-PMP: Securing Sensitive Operations for Kernels and Bare-Metal Firmware

Wende Tan, Chenyang Li, Yangyu Chen, Yuan Li, Chao Zhang, Jianping Wu

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出轻量级软硬件协同设计方案ROLoad-PMP,通过新指令与程序加固机制保护内核、裸机固件的敏感操作,仅占用极少硬件与性能开销,安全保障优于ARM BTI等现有方案。

中文摘要 AI 辅助

攻击者入侵受害系统的常见方式是用攻击者控制的输入劫持敏感操作(如控制流转移)。现有解决方案通常仅保护部分目标,且性能开销高,在资源有限的系统(如物联网设备)或内核、裸机固件等底层软件上难以部署。本文提出轻量级软硬件协同设计方案ROLoad-PMP,用于保护底层软件的敏感操作不被劫持。首先,我们提出新指令,仅从带特定密钥的只读内存区域加载数据,保证(可能已被损坏的)数据指针所指向对象的完整性;其次,我们提供程序加固机制,在编译时将敏感操作的操作数分类并放入带不同密钥的只读内存,运行时用ROLoad-PMP系列指令加载,以此保护敏感操作。我们基于RISC-V实现了ROLoad-PMP的FPGA原型,并展示了重要防御应用——前向控制流完整性。结果显示,ROLoad-PMP仅占用极少额外硬件资源(<1.40%),还能实现诸多轻量级防御(如开销可忽略<0.853%),且比现有硬件解决方案(如ARM BTI和Intel CET)提供更广泛、更强的安全保障。

英文摘要

A common way for attackers to compromise victim systems is hijacking sensitive operations (e.g., control-flow transfers) with attacker-controlled inputs. Existing solutions in general only protect parts of these targets and have high performance overheads, which are impractical and hard to deploy on systems with limited resources (e.g., IoT devices) or for low-level software like kernels and bare-metal firmware. In this paper, we present a lightweight hardware-software co-design solution ROLoad-PMP to protect sensitive operations from being hijacked for low-level software. First, we propose new instructions, which only load data from read-only memory regions with specific keys, to guarantee the integrity of pointees pointed by (potentially corrupted) data pointers. Then, we provide a program hardening mechanism to protect sensitive operations, by classifying and placing their operands into read-only memory with different keys at compile-time and loading them with ROLoad-PMP-family instructions at runtime. We have implemented an FPGA-based prototype of ROLoad-PMP based on RISC-V, and demonstrated an important defense application, i.e., forward-edge control-flow integrity. Results showed that ROLoad-PMP only costs few extra hardware resources (< 1.40%). Moreover, it enables many lightweight (e.g., with negligible overheads < 0.853%) defenses, and provides broader and stronger security guarantees than existing hardware solutions, e.g., ARM BTI and Intel CET.

补充信息

↑