arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MATEE:通过Arm指针认证高效弥合TrustZone中的语义鸿沟

MATEE: Efficiently Bridging the Semantic Gap in TrustZone via Arm Pointer Authentication

Shiqi Liu, Xiang Li, Jie Wang, Yongpeng Gao, Jiajin Hu

arXiv 2608.20583首次发表:更新:

AI 中文总结

MATEE是面向TEE的系统,利用Arm指针认证绑定请求与客户端应用身份,在不修改现有应用的前提下防御语义鸿沟漏洞,运行时开销仅2.19%。

AI 中文摘要

可信执行环境(TEE)采用基于硬件的隔离机制,以保障敏感代码与数据的保密性和完整性,其中Arm TrustZone是一种普遍的实现方式,它将系统划分为安全世界和普通(非安全)世界。然而这种划分导致安全世界对普通世界的运行信息可见性非常有限,在两个世界之间形成了语义鸿沟。具体而言,安全世界在接收来自普通世界的数据请求时缺乏有效的用户身份认证,因此普通世界中的恶意客户端应用(CA)可利用精心构造的请求参数欺骗安全世界中的可信应用(TA),从而窃取其他CA存储的敏感数据。我们对这类语义鸿沟漏洞(SGV)进行了系统分类,并提出了一种面向TEE的名为MATEE的mate系统,以防御SGV。MATEE利用Arm指针认证(PA)将每个请求绑定到对应CA的身份,随后在CA访问敏感数据时验证该身份,从而防止恶意请求伪造。值得注意的是,MATEE无需修改现有CA和TA即可隔离不同CA的敏感数据。我们的评估表明,MATEE可成功防御SGV,且运行时开销极小,仅为2.19%。

英文摘要

Trusted Execution Environments (TEEs) employ hardware-based isolation mechanisms to safeguard the confidentiality and integrity of sensitive code and data. One such prevalent implementation is Arm TrustZone, which partitions the system into the secure and normal (non-secure) worlds. However, this partitioning results in the secure world having very limited visibility into the operating information of the normal world, creating a semantic gap between these two worlds. Specifically, the secure world lacks an effective user identity authentication when receiving data requests from the normal world. Consequently, malicious Client Applications (CAs) in the normal world can deceive Trusted Applications (TAs) in the secure world by utilizing elaborate request parameters, compromising the sensitive data stored by other CAs. We systematically classify these Semantic Gap Vulnerabilities (SGVs) and propose a mate system for the TEE called MATEE to defend against SGVs. MATEE utilizes Arm Pointer Authentication (PA) to bind each request to the corresponding CA's identity and then verifies the identity when the CA accesses sensitive data, thereby preventing malicious request forgery. In particular, MATEE isolates sensitive data of different CAs without modifying existing CAs and TAs. Our evaluation demonstrates that MATEE successfully defends against SGVs with a minimal runtime overhead (2.19%).

CommentsPublished in IEEE Transactions on Dependable and Secure Computing (TDSC)

Journal refIEEE Transactions on Dependable and Secure Computing, vol. 22, no. 2, pp. 1491-1505, March-April 2025

DOI:10.1109/TDSC.2024.3445296

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑