scieee Open visual document viewer

Attacking TrustZone on devices lacking memory protection

Stajnrod, Ron,Ben Yehuda, Raz,Zaidenberg, Nezer Jacob

Full text

This is a sel -a chi ed e sion o an o iginal a icle. This e sion may di e om he o iginal in pagina ion and ypog aphic de ails. Au ho (s): Ti le: Yea : Ve sion: Copy igh : Righ s: Righ s u l: Please ci e he o iginal e sion: CC BY 4.0 h ps://c ea i ecommons.o g/licenses/by/4.0/ A acking T us Zone on de ices lacking memo y p o ec ion © The Au ho (s) 2021 Published e sion S ajn od, Ron; Ben Yehuda, Raz; Zaidenbe g, Neze Jacob S ajn od, R., Ben Yehuda, R., & Zaidenbe g, N. J. (2022). A acking T us Zone on de ices lacking memo y p o ec ion. Jou nal o Compu e Vi ology and Hacking Techniques, 18(3), 259-269. h ps://doi.o g/10.1007/s11416-021-00413-y 2022 Jou nal o Compu e Vi ology and Hacking Techniques h ps://doi.o g/10.1007/s11416-021-00413-y ORIGINAL PAPER A acking T us Zone on de ices lacking memo y p o ec ion Ron S ajn od1·Raz Ben Yehuda2·Neze Jacob Zaidenbe g2,3 Recei ed: 11 Augus 2021 / Accep ed: 26 No embe 2021 © The Au ho (s) 2021 Abs ac ARM T us Zone o e s a T us ed Execu ion En i onmen (TEE) embedded in o he p ocesso co es. Some endo s o e ARM modules ha do no ully comply wi h T us Zone speci ica ions, which may lead o ulne abili ies in he sys em. In his pape , we p esen a DMA a ack u o ial om he insecu e wo ld on o he secu e wo ld, and he design and implemen a ion o his a ack in a eal insecu e ha dwa e. Keywo ds T us Zone ·Secu i y 1 In oduc ion The de elopmen o he In e ne o Things (IoT) is hailed as he hi d wa e o wo ld in o ma ion de elopmen a e compu e s and he In e ne [56], wi h embedded sys ems as he d i ing o ce o echnological de elopmen in many domains in he eme ging pos -PC e a. As an inc easing num- be o compu a ional de ices in eg a e in o ou li es in a pe asi e and in isible way, secu i y becomes c i ical o he dependabili y o all in elligen sys ems buil upon hese embedded sys ems [40]. Embedded IoT p oduc s a e inc easingly no connec ed o he powe g id. The e o e, such de ices a e cons ained in e ms o compu ing powe due o limi ed elec ic powe [29]. The cons ained na u e o such de ices means we a e ying o “build a o ess om pebbles.” The e o e, we mus ake he bes secu i y measu es o p e en malicious ac i i y on hose de ices gi en he limi ed condi ions, which o en means cu ing co ne s compa ed wi h o he esou ce- ich a eas o compu ing (pe sonal compu e s, se e s, e c.). BNeze Jacob Zaidenbe g [email p o ec ed] Ron S ajn od [email p o ec ed] Raz Ben Yehuda [email p o ec ed] 1In e disciplina y Cen e , He zliya, Is ael 2Uni e si y o Jy äskylä, Jy äskylä, Finland 3College o Managemen Academic S udies, Is ael Uni e si y o Jy äaskylä, Rishon LeZion, Is ael ARM T us Zone [5] was in oduced as pa o he ARM 6 a chi ec u eandiswidelyusedinsma phones, able s, wea - ables, and o he de ices. As T us Zone gains popula i y in ha dwa e secu i y a chi ec u e o mobile de ices and IoT, i is i al o ensu e he secu i y o T us Zone i sel [57]. Though ARM T us Zone is a g ea way o implemen secu i y mechanisms ac oss IoT-embedded de ices, i is s ill p one o inadequa e ha dwa e and so wa e implemen a- ions.Thus, heha dwa eo di e en companieslikeGoogle, Samsung, Huawei, e c., migh s ill be a ec ed by se e e ulne abili ies ha comp omise he en i e secu i y sui e [11,21,33,43]. One o he key ea u es o he AMBA (Ad anced Mic o- con olle Bus A chi ec u e) AXI (Ad anced Ex ensible In e ace) [3] is add ess space sepa a ion. Thus, lacking hem c ea es insecu e memo y sepa a ion be ween he no - mal wo ld and he secu e wo ld. In his pape , we p esen a Di ec Memo y Access (DMA) a ack [26] on OP-TEE (Open Po able T us ed Execu ion En i onmen ) [18,39]. OP-TEE is one o he common ope a ing sys ems ha un on T us Zone. OP-TEE is a popula , open-sou ce, T us Zone ope a ing sys em. We used OP-TEE as a e e ence T us Zone OS o demons a e he a ack p esen ed in his pape , hough he a ack is no due o an OP-TEE bug bu a he a missing ha dwa e ea u e. Ou a ack allows an a acke o execu e a bi a y code in he secu e wo ld o ead a bi a y da a om he secu e wo ld in o he ich OS. Ou a ack is a con ol- low a ack [14,55] on he OP-TEE ke nel. Also in he pape , we show a ha dwa e ulne abili y on SoC [10] ha comp omises ARM T us Zone. Using he 123 R. S ajn od e al. Fig. 1 No mal and secu ed wo lds ©A m DMA a ack, we gain he abili y o eplace us ed appli- ca ions wi h malicious ones. Fu he mo e, we demons a e an a ack on a Raspbe y Pi compu e and explain how his me hod a ec s o he pla o ms. This pape also p o ides measu es o mi iga e his ulne abili y. The a ack was no possible when AMBA AXI was p esen . Un o una ely, he AMBAAXIisno p esen ona ewmode nha dwa ede ices, including Raspbe y Pi 3,4 and Je son Nano. 2 Backg ound 2.1 ARM T us Zone ARM T us Zone echnology aims o es ablish us in ARM- based pla o ms. In con as o a TPM (T us ed Pla o m Module), which is designed as a ixed- unc ion de ice wi h a p ede ined ea u e se , T us Zone ep esen s a much mo e lexible app oach by le e aging he CPU as a eely p o- g ammable us ed pla o m module. To do ha , ARM in oduced a special CPU mode called ‘secu e mode’ in addi- ion o he egula no mal mode, he eby es ablishing he no ions o a ‘secu e wo ld’ and a ‘no mal wo ld’ (Fig. 1). The dis inc ion be ween hese wo lds is en i ely o hogonal o he s anda d ing p o ec ion be ween use -le el and ke nel- le el code, and hidden om he ope a ing sys em unning in he no mal wo ld [1]. As an example, he Linux ke nel uns in EL1 and he use space p ocesses execu e in EL0. The sepa a ion o he secu e and no mal wo lds p o ec s speci ic RAM anges and pe iphe als only accessible by he secu e wo ld. This sep- a a ion means ha a comp omised no mal wo ld code (in he use space o he ke nel) canno access hese memo y anges o de ices. Howe e , his sepa a ion is en i ely a i i- cial. The same co es un bo h secu e and no mal wo lds, and hey use he same RAM (Fig. 2). The Non-Secu e (NS) bi de e mines whe he he CPU execu es in he no mal wo ld o in he secu e wo ld con ex o c ea e a sepa a ion in mem- o y. T us Zone echnology ex ends beyond he p ocesso in o he SoC pe iphe als connec ed wi h he SoC, such as Fig. 2 NS Bi ©Lina o he DRAM con olle (Fig. 2), he DMA (Di ec Memo y Access), he secu e boo ROM, he GIC (Gene ic In e - up Con olle ), he T us Zone Add ess Space Con olle (TZASC), he T us Zone P o ec ion Con olle (TZPC), and he Dynamic Memo y Con olle (DMC). The abo e com- ponen s communica e h ough he AXI bus and he SoC communica es wi h pe iphe als h ough he AXI_ o_APB b idge. Thi d-pa y companies implemen he SoC pe iph- e als; he e o e, some endo s do no comply en i ely wi h T us Zone speci ica ions o educe cos s. I is possible o access he en i e memo y om he secu e wo ld bu no ice e sa. To a e se o EL3, we use he Secu e Moni o Call (SMC) ins uc ion. Un o una ely, he SMCimplemen a ion dependson hemanu ac u e and, hus, is p one o bugs and o he ulne abili ies [21]. This pape ocuses on he physical le el o memo y isola ion. T us Zoneenablesmemo ypa i ionsbe weenno maland secu e wo lds by using he TZASC and he TZPC. In addi- ion, hesecon olle s p o idea secu eI/O o pe iphe als o e s anda d in e aces. Fo ins ance, he TZPC ou es he SPI access o he secu e wo ld. Fu he mo e, he NS bi secu es on-chip pe iphe als om accessing om he Rich Execu- ion En i onmen (REE) [8]. TZASC u ilizes he NS bi o a memo y-mapped de ice like DRAM. These wo de ices equi e suppo om he AXI bus, which is endo -speci ic. Examples o he secu e wo ld us ed applica ions a e secu e PIN and biome ic checks. Ano he us ed applica- ion use case is Digi al Righ Managemen (DRM) o online media. Again, p i a e in o ma ion is kep wi hin he secu e wo ld so hacke s canno access he keys equi ed o e e se- enginee he sys em. [36] desc ibes many mo e use cases o T us Zone o IoT and mobile de ices. 2.2 OP-TEE OP-TEE [39] is a T us ed Execu ion En i onmen (TEE) designed as a companion o a non-secu e Linux ke nel unning on ARM Co ex-A co es using he T us Zone ech- nology. OP-TEE implemen s TEE In e nal Co e API 1.1.x, which is he API exposed o T us ed Applica ions and he TEE Clien API 1.0, which is he API desc ibing how o communica e wi h a TEE. The GlobalPla o m API de ines 123 A acking T us Zone on de ices lacking memo y p o ec ion Fig. 3 Ou line o T us Zone ©Miled opedia hese speci ica ions [22]. The non-secu e OS is e e ed o as he Rich Execu ion En i onmen (REE) in TEE speci ica- ions. OP-TEE is widesp ead in Snapd agon, IMX7, Hikey, D agonBoa d, and many o he p oduc s. OP-TEE is designed p ima ily o ely on he ARM T us Zone echnology as he unde lying ha dwa e isola ion mechanism. Howe e , i is compa ible wi h o he isola ion echnologies sui able o he TEE concep and goals, such as unning as a i ual machine o on a dedica ed p ocesso co e. The main design goals o OP-TEE a e: –Isola ion - OP-TEE p o ides isola ion om he non- secu e OS and p o ec s he loaded T us ed Applica ions (TAs) om each o he by using unde lying ha dwa e sup- po . –Small oo p in - OP-TEE should emain small enough o eside in a easonable amoun o on-chip memo y as ound on ARM-based sys ems. –Po abili y - OP-TEE is aimed o be pluggable o di e - en a chi ec u es and mus suppo a ious se ups such as mul iple clien OSs o mul iple TEEs. OP-TEE o e s h eads and sha ed memo y be ween he REE o he secu ed OS, secu ed in e up s RPC om he secu e wo ld o he REE and he SMC in e ace communica ion om he REE o he secu e wo ld. OP-TEE main componen s a e he: – OP-TEEbina yOSexecu inginsecu eEL1 (T us Zone); – OP-TEE Linux ke nel d i e ; – Linux use space lib a ies; and – a Linux use space daemon ( ee-supplican ) ha pe o ms se iceson behal o he OP-TEE OS. I is esponsible o passing he secu ed pa o he TA in o he secu e wo ld. The e a e se e al ypes o TAs. The ea ly TAs ha d-link o OP-TEE co e bina y and, he e o e, a e a ailable be o e he REE uns. The second ype is an REE File sys em TA, which is a ailable once he REE OS uns. The TA is composed o wo pa s: secu ed and non-secu ed. I is signed and may be enc yp ed. The key used o sign he TA is he same key used osign heo iginalOP-TEE bina yco eblob usedwhenbuil . Each TA is composed o wo pa s: a Linux use space applica ion and a secu e wo ld applica ion. TA execu ion ol- lows he nex s eps: 1. Ini ialize Con ex and Open Session: C ea es a con ex and loads he TA secu e pa in o he OP-TEE co e in he T us Zone. 2. In oke command. The non-secu e pa sends commands o he secu ed TA ecei e . 3. Close session and Finalize con ex . OP-TEE secu e s o age manage implemen s a secu e ile sys em in wo ways: REE-FS and p o ec ed memo y (i pos- sible). When a TA w i es da a o he secu ed s o age, he us ed s o age in okes TEE ile sys em ope a ions o s o e he da a. Then he TEE ile sys em enc yp s he da a and passes he da a o ee supplican , keeping he da a in he REE ile sys em. The TEE ile sys em is isible in he Linux ile sys em as a di ec o y. Each objec wi hin he TEE is assigned an in e nal iden i ie in addi ion o he TA objec s. Kep in he TEE ile sys em, he key-manage esponsibil- i ies a e da a enc yp ion and dec yp ion. I uses h ee ypes o keys: –SSK - Secu e s o age keys –TSK - TA s o age keys –FEK - File sys em key The FEK de i es om TSK, which de i es om he SSK. The SSK de i es om he unique ha dwa e key (HUK). The HUK may no be accessible om he REE and i is up o he manu ac u e o p o ide i , and p o ide access o i . The OP-TEE ke nel is no enc yp ed. The e o e, a DMA a ack on he OP-TEE ke nel is mo e s aigh o wa d han on a TA-enc yp ed p og am as i bypasses he MMU pe mis- sions model and he need o enc yp he code. Each TA is signed and op ionally enc yp ed wi h a p i a e key. The dec yp ion akes place in OP-TEE in he T us Zone. Thus, he p og am in i s dec yp ed o m is only isible in he secu ed RAM and he p ocesso ’s EL3 cache. I is, he e o e, sensible o a ack in he dec yp ion a ea. 3 The DMA a ack Di ec Memo y Access (DMA) allows I/O de ices o access he memo y. DMA has e ol ed since i s incep ion and a e in oducingmanyhigh-speedI/Ope iphe als, endo ss a ed o inco po a e DMA engines o ini ia e DMA ansac ions wi hou coo dina ing wi h he DMA con olle . 123 R. S ajn od e al. ARMimplemen s head ancedmic ocon olle busa chi- ec u e (AMBA), an open s anda d o on-chip in e connec speci ica ion. DMA ansac ions connec h ough he DMA con olle o he on-SOC AMBA AXI Bus (AMBA ad anced ex ensible in e ace), and he AMBA AXI Bus suppo s he T us Zone NS-bi . Thus, he DMA con olle can han- dle secu e and non-secu e e en s simul aneously, wi h ull suppo o in e up s and pe iphe als. Examples o DMA de ices a e g aphic ca ds, ne wo k adap e s, Fi eWi e, Thun- de Bol , e c. Al hough DMA is essen ial o as I/O ans- ac ions, i also opens new ulne abili ies o DMA a acks [7,26,46]. 3.1 A ack goal On a SOC lacking an SMMU (Sys em Memo y Managemen Uni ) o TZASC, unning OP-TEE wi hou NS-bi suppo , hesecu edmemo y isaccessible h ough DMA ansac ions. Th ough his ulne abili y, we can exploi T us Zone. We escala e p i ileges by eading da a om he secu e wo ld. In his a ack, we injec code o he Moni o in EL3, hus execu ing malicious p og ams in he secu e wo ld OS. This injec ion le s us bypass any alida ion o he secu e ope a ing sys em and makes i possible o pa ch he EL1 ke nel and execu e a bi a y code. 3.2 The a ack -‘ us ed’a bi a y code execu ion We base he a ack p imi i e on W i e Wha Whe e ul- ne abili y achie ed using DMA ansac ions. We use his ulne abili y o show ha we can gain access o execu e a bi- a y code in he OP-TEE OS. We bypass OP-TEE OS TA signa u e alida ion and gain con ol o e e y us ed appli- ca ion in he sys em, which we p esen la e in he pape . Ou app oach is o change he opcodes ha e u n e o alues o key unc ions wi hou changing he s ack. This echnique impedes CFI ools such as gcc compile s ack gua d [13], Clang CFI [2], o kFCI [34] o de ec ou a ack. T us ed applica ions a e loca ed on he REE ile sys em because i usually con ains mo e memo y; using his ile sys- em makes i easie o upda e hose applica ions. The us ed applica ions a e buil sepa a ely om he us ed ope a ing sys em (simila o Linux ke nel and use space applica ions in he no mal wo ld) and a e signed wi h a p i a e key om he manu ac u e o he de ice applica ion (e.g. Samsung sign hei us ed applica ions wi h hei p i a e key). Typical usages o us ed applica ions a e DRM alida ions, HMAC (keyed-hash message au hen ica ion code)-based one- ime passwo d,AES enc yp ion and mo e. Using he us edappli- ca ions, hede ice’s manu ac u e can ensu e a comp omised use o ke nel will no b eak he de ice’s in eg i y. When he manu ac u e wan s o upda e a us ed applica ion, hey sign he new e sion wi h he same p i a e key and dis ibu e i o Table 1 PI3 speci ica ions SoC B oadcom BCM2837 CPU 4 co es, ARM Co ex A53, 1.2GHz, (clocked o 700MHz) RAM 1GB LPDDR2 (900MHz) Clock 19.2MHz he use s. When he secu e wo ld OS execu es a us ed appli- ca ion, a secu i y e o will occu i he signa u e is in alid and he p og am will no un. In ou a ack, we i s use a DMA a ack o ead memo y pages om he RAM. Pe iphe al de ices such as Fi eWi e, PCI-connec ed de ices (Ne wo k ca ds, GPU, e c.) can ini i- a e a DMA a ack, as demons a ed by [46,49], and [26]. The CPU can also ini ia e DMA a acks by ac i a ing he DMA con olle . A e eading memo y pages om he RAM, we analyse he memo y and compa e i o ARM T us ed Fi mwa e o loca e simila unc ions. (Mos T us Zone so - wa e implemen a ions a e based on ARM T us ed Fi mwa e, making e e se-enginee ing he code simple .) Mo eo e , some signi ican endo s’ secu e OS (T us ed Execu ion En i onmen ) is in he ma ke (QSEE, OP-TEE). We com- pa e ou memo y dump o he compiled e sions o hose; by doing so, we can ind he unc ions ha alida e us ed applica ion signa u es. Because in some cases, some o he widely used TEE OS uses Add ess Space Layou Randomi- sa ion(ASLR) [12], we can use he add ess om ou memo y dump o o e ide us ed applica ions signa u e alida ions wi h a DMA a ack. A e doing so, we can jus eplace any TA wi h ou own malicious TA. Thus, e en hough we do no know he co ec signa u e p i a e key, he TEE OS will succeed o alida e ou malicious TA. 4 A ack e alua ion 4.1 Raspbe y Pi pla o m We use a Raspbe y PI3 Model B o demons a e he a ack. Table 1p esen s he Raspbe y PI3 Model B’s main speci i- ca ions. Figu e 4p esen s he BCM2837 chip. This B oadcom SOC suppo s T us Zone and DMA ansac ions h ough he AMBA Ad anced Mic ocon olle Bus A chi ec u e AXI (Ad anced Ex ensible In e ace). As men ioned ea lie , no all endo s’ implemen a ions comply wi h he en i e ha d- wa e speci ica ions. Fo example, Fig. 4shows ha he BCM2837 has he co ec AXI bus, bu i lacks he TZASC and TZPC, making i ulne able o DMA a acks. 123 A acking T us Zone on de ices lacking memo y p o ec ion Fig. 4 BCM2387 O e iew ©P emie Fa nell L d Table 2 DMA Con ol Block Da a S uc u e 32-bi Wo d O se Desc ip ion Associa ed Read- only Regis e 0 T ans e TI In o ma ion 1 Sou ce Add ess SOURCE_AD 2 Des ina ion Add ess DEST_AD 3 T ans e Leng h TXFR_LEN 4 2D Mode S ide STRIDE 5 Nex Con ol Block Add ess NEXTCONBK 6–7 Rese ed - se o ze o N/A 4.2 OP-TEE o PI OP-TEE suppo s Raspbe y Pi 3 Model B. In addi ion, he ARM T us ed Fi mwa e is he basis o implemen ing secu e wo ld so wa e o he ARM A-P o ile a chi ec u es (ARM 8-A and ARM 7-A), including an Excep ion Le el 3 (EL3) Secu e Moni o . ARM T us ed Fi mwa e o he Raspbe y Pi p o ides a sui able s a ing poin o he p o- duc isa ion o secu e wo ld boo and un ime i mwa e [4]. When a endo uses OP-TEE on any ha dwa e in gene al and on Raspbe y Pi speci ically, hey will mos likely use a us ed applica ion o implemen ha dwa e secu i y measu es and secu e hei de ices [35]. Table 3 DMA Con olle 32-bi Add ess o se Regis e name Desc ip ion 0 CS DMA Channel Con ol and S a us 1 CONBLK_AD DMA Channel Con ol Block Add ess 2 TI DMA Channel T ans e In o ma ion 3 SOURCE_AD DMA Channel Sou ce Add ess 4 DEST_AD DMA Channel Des ina ion Add ess 5 TXFR_LEN DMA Channel T ans e Leng h 6 STRIDE DMA Channel 2D S ide 7 NEXTCONBK DMA Channel Nex CB Add ess 8 DEBUG DMA Channel Debug 4.3 Raspbe y Pi DMA As no ed ea lie , he CPU can access he DMA con olle . The e o e, we chose o pe o m his a ack h ough he CPU. We au ho ed a Linux ke nel module o pe o m he DMA ansac ions.This module maps he DMA con olle and con- igu es he DMA con ol block o ini ia e DMA ansac ions. InOP-TEE’sLinuxke nel, heDMAcon olle add essspace is no a ailable o he use space. Howe e , i is plausible o assume ha an IoT de ice, o example, will enable his de ice o pe iphe als access. We a gue an a ack is possi- ble in many IoT de ices, and we will show he ollowing scena ios: 1. Some IoT de ices map physical memo y o he use space o inc ease pe o mance and sa e ke nel access, leading o DMA con olle access. 2. Linux-based de ices (IoT de ices, ou e s, e c.) do no upda e hei ke nel e sions e y o en due o compa ibil- i y issues and many de ices. Thus one day’s ulne abili y can be used o exploi he de ice and gain oo access o pe o m ac ions on he DMA con olle [37,50]. 3. A ack pe iphe al de ice (Blue oo h/WIFI chip, SSD con- olle , e c.) o pe o m malicious DMA ansac ions [17,47,52]. All hose scena ios may lead o a DMA a ack and, on some de ices, o T us Zone ulne abili y. 123 R. S ajn od e al. Fig. 5 Open session low Table 2p esen s he Con ol Block s uc u e o a DMA in he Raspbe y Pi. Table 3shows he DMA Con olle egis- e s. To ini ia e a DMA ansac ion, we i s se he Con ol Block s uc u e and hen se CONBLK_AD in he DMA con- olle s uc u e. We pe o m wo ypes o DMA ansac ions: 1. Se SOURCE_AD o he secu e wo ld physical add ess o ead da a o he secu e wo ld. 2. Se DEST_AD o he secu e wo ld physical add ess o w i e malicious code o he secu e wo ld, he eby achie - ing a bi a y code execu ion. 5 The a ack - e alua ion on aspbe y Pi In he OP-TEE en i onmen , us ed applica ions a e signed wi h he key om he build o he o iginal OP-TEE co e blob. T us ed applica ions consis o a signed ELF heade , named om he UUID o he us ed applica ion (se du ing compila ion ime) and he su ix . a. When a us ed applica ion is eplaced in he REE ile- sys em wi h he new one, he signa u es and UUID a e alida ed by he OP-TEE OS (Fig. 5). OP-TEE p o ides a Linux ke nel d i e o in e ac wi h he OP-TEE in T us Zone. Fo ins ance, he PTA_SYSTEM _OPEN _TA_BINARY unc ion access he OP-TEE OS. PTA_SYSTEM_OPEN_TA_BINARY calls sys em _open _ a _bina y, which looks o he use - us ed applica ion ELF by he UUID in he s o age ( ile-sys em). A e inding he us ed applica ion ELF in he REE ile-sys em, he OP-TEE OS loads he ELF heade and maps he TA sec ions in o he secu e memo y using PTA _SYSTEM_MAP _TA_BINARY. A e loading he us edapplica ion, heuse isable oin oke he us ed applica ion unc ionali y h ough he OP-TEE Linux ke nel d i e . We ocus on wo unc ions: ee_ s_ a_open and ee_ s_ a_ ead called by PTA _SYSTEM _OPEN _TA _BINARY, and PTA _SYSTEM _MAP _TA _BINARY, espec i ely. T us ed applica ions bina ies con ain a signed heade so ha a malicious use canno eplace he us ed applica- ions. I a malicious use eplaces a us ed applica ion, hen OP-TEE OS e u ns a secu i y e o when execu ing hose us ed applica ions. In o de o OP-TEE OS o al- ida e hose signa u es as a us ed applica ion execu es, he unc ion ee_ s_ a_open loads he us ed applica ion heade , alida es he applica ion heade signa u e (Fig. 6) and ali- da es i s size (Fig. 7). When OP-TEE OS maps he TA in o he secu e memo y, i loads he applica ion o he memo y using ee_ s_ a_ ead, which alida es he enc yp ed us ed applica ion signa u e (Figs. 8and 9). In he i s s ep, we e e se-enginee ed OP-TEE OS (using ada e2 [31]) in o de o ind key opcodes o bo h unc ions o exploi (Figs. 6,7,8,9). We used DMA ansac ions o ead chunks o physical RAM in o de o ind he opcodes ha ma ch he unc ions abo e. Once we loca ed he opcodes in he memo y and no iced ha hese unc ions load in he 123 A acking T us Zone on de ices lacking memo y p o ec ion 1/∗Valida e heade signa u e ∗/ 2 es = shd e i y signa u e(shd ); 3i ( es != TEESUCCESS) 4go o e o ee payload ; 5 Fig. 6 ee_ s_ a_open Heade signa u e alida ion 1i ( a size != o s + shd −>img size) { 2 es = TEEERROR SECURITY ; 3go o e o ee hash ; 4} 5 Fig. 7 ee_ s_open TA size alida ion Fig. 8 ee_ s_ a_ ead dec yp s a TA heade same loca ion in physical memo y e e y ime. We used DMA ansac ions o o e ide he e u n alues o he alida ions men ioned abo e (Figs. 6,7,8,9), he eby gaining he abil- i y o compile ou own us ed applica ion, sign i wi h an a bi a y key and execu e i on he machine. We eplaced wo ypeso opcodes: hecompa isonopcode o w0 egis e was eplaced wi h cmp w0,w0 so i always e u ned ue and, when mo ing he e u n alue o he unc- ion o w0 egis e , we eplaced his command wi h eo w0,w0,w0 so he alue o w0 egis e would be 0, again ha - ing he e u n alues o he alida ion unc ions equal ue. We we e able o pe o m his eplacemen using jus a simple DMA ansac ion wi h he con ol block DEST_AD, which con ains he physical add ess o he opcodes we ound, all o which a e loca ed in he secu e wo ld memo y. In ou case, we compiled a new TA wi h he same UUID as he o igi- nal one and pu i in he ile-sys em loca ion. By execu ing ou malicious TA, we gained he abili y o manipula e ARM T us Zone o un in alidly signed bina ies. Fo ins ance, we compiled a ake AES TA (gi en in he examples o he OP- TEE sui e) ha enc yp s da a wi h ou malicious key. Thus, e e y ime he use uses his TA o pe o m AES, i will no enc yp he da a wi h he sec e key. Fig. 9 ee_ s_ ead alida es he enc yp ed heade agains he hash o he plain heade 5.1 O he a ack possibili ies Using DMA a acks on he T us Zone gi es a wide ange o a ack possibili ies. In his pape , we show he usage o DMA a acks o pe o m ACE (A bi a y Code Execu ion); howe e , i isalsopossible o use his me hod o eada bi a y code om physical memo y whe eby a malicious use can access sensi i e da a. 6 Mi iga ion When choosing an SoC, you mus compa e he de ice equi emen s o he SoC ea u es. In ou case, when selec - ing an SoC, we wan o make su e he SoC a chi ec u e has all he chips equi ed o ARM T us Zone o wo k co ec ly (TZASC, TZPC, suppo ed bus, e c.). Un o una ely, check- ing he SoC a chi ec u e is no always easy and no au oma ic because no all endo s publish hei SoC a chi ec u e. We sugges ha SoC endo s be mo e anspa en abou hei a chi ec u e when i comes o secu i y ea u es. We also ecommend ha manu ac u e s ensu e hei SoC ha dwa e suppo sT us ZoneARMCo eandT us Zonespeci ica ions. In cases whe e a ully compa ible T us Zone is no a ail- able (lack o ha dwa e on he SoC ha makes he T us Zone secu e), we lis o he p o ec ion echniques: – Using SMMU (simila o IOMMU on In el x86) o con- igu e speci ic add esses o DMA con olle s. SMMU wo ks as MMU o BUS access so any memo y access h ough he BUS is ma ched o he pe mission con ig- u ed o he accessed add ess. Wi h SMMU and a co ec con igu a ion, a DMA a ack h ough pe iphe als will no be possible. I is also impo an o no e a ke nel a acke could change his con igu a ion. – In he case o Raspbe y Pi, by disabling he DMA con- olle , a non-p i ileged use o pe iphe al would no be able o use DMA ansac ions. – Se he secu e wo ld on a di e en RAM wi hou DMA con olle mapping so he e is no physical in e ace be ween he no mal and secu e wo lds. 123 R. S ajn od e al. A so wa e echnique would enc yp pa s o he OP-TEE code i sel , mainly he TA deciphe unc ions. Then, when OP-TEE uns hese unc ions,i dec yp s hemin o hecache, alida es he TA, and e ic s he p ocesso s’ cache. Using his me hod [54], an a acke would ha e o ime his a ack o ge he RAM code. Howe e , combining his me hod wi h ASLR impedes he a ack. 7 Rela ed wo k In he a ea o ARM, [11] e al. desc ibe a downg ade o oll- back a ack. A us ed applica ion is enc yp ed o secu i y pu poses by public and p i a e keys ha o igina e om he ha dwa e. In cases when he sys em is upda ed, old TAs can s ill be execu ed on he new sys em. A downg ade a ack is when an a acke exploi s a ulne abili y in he old TA e - sion by pa ching he old e sion on o he new TA e sion. Acco ding o [11], he abo e applies o he OP-TEE and QSEE (Qualcomm’s Secu e Execu ion En i onmen ). [11] e al. desc ibe a simple p ocedu e o mobile phones: oo he de ice, emoun he ‘sys em’ pa i ion in READ-WRITE mode, eplace hecu en us le wi h anold ulne able us - le and use he us le . [11] e al. desc ibe ano he possible ollback a ack on he chain o us and p o es i possible o downg ade he boo loade success ully. Many wo ds ha e been w i en on side-channel a acks and o he ulne able a ge s in ARM a chi ec u e in p io esea ch. Fo example, A mageddon [32] e al. explo e a acks on ARM caches, concen a ing on c oss-co e cache a acks in non- oo ed ARM mobile de ices and showing a no el app oach o exploi he cohe ence p o ocols. Al hough mos sma phones ha e mul iple p ocesso s ha do no sha e caches, cache cohe ence p o ocols allow p ocesso s o e ch cache lines. By exploi ing he lack o cache lush on ‘old’ ARM co es (be o e ARM 8), a no el echnique ha analy- ses cache e ic ion s a egies and ano he app oach o pe o m cycle- iming wi hou oo access, he A mageddon [32]e al. p o ide a me hod o gain sensi i e in o ma ion such as in e -keys oke imings o he leng h o a swipe ac ion. As o T us Zone ulne abili y, A mageddon [32]e al.shows a cache a ack used o moni o cache ac i i y caused wi hin he ARM T us Zone om he no mal wo ld. Flush and Reload a ack [53] e al. ake ad an age o he cohe ence p o ocol in a mul ip ocesso compu e . In mos ARM p ocesso s, he las -le el cache is inclusi e (i.e. i includes low-le el cache lines); he e o e, examining he con en o he las -le el cache may p o ide he con en s o low-le elcachelineso ano he co e.Howe e , heAu oLock [19] ool assesses he ac ual isk in cache a acks, p e en s c oss-cache e ic ions and highligh s he in icacies o cache a acks in ARM. [19] e al. claim ha unlike In el p oces- so s, many ARM caches a e bo h inclusi e and exclusi e and, he e o e, ha den he LLC (las -le el cache) a acks. In hei wo k,Demme e al. [16] demons a e ha small changes o he cache a chi ec u e ha e a conside able impac on side- channel ulne abili y. Finally, [28] e al. p esen in hei wo k a side-channel cache a ack agains Samsung T us Zone ia he And oid’s Keymas e c yp og aphic unc ions. Like cache a acks, DMA a acks a e con inuously unde esea ch. [49] e al. show ha by dumping memo y e- quen ly enough using DMA ansac ions, w i e pa e ns can be examined. Some algo i hms, such as he RSA Mon - gome y ladde [23], may leak sec e s. DAGGER [46], a DMA-based keys oke logge , ex il a es cap u ed da a o an ex e nal en i y and canno be de ec ed by an i- i us so - wa e. [46] shows how DAGGER can s eal c yp og aphic keys, a ge OS ke nel s uc u e, and copy iles om he ile cache on Linux and Windows h ough DMA malwa e e en i he memo y add esses a e andom. [46] e al. also o e coun e measu es o de ec DMA a acks. [9] e al. in eg a e DMA a acks h ough Fi eWi e in o Me asploi [24]. Thus, an a acke could use Me asploi [24] o payload selec ion, session con ol, e c. and a ack ia DMA o e Fi ewi e. TRESOR-HUNT [7] elies on he insigh ha DMA- capable ad e sa ies a e no es ic ed o simply eading physical memo y bu can w i e a bi a y alues o memo y as well. Ha d disk enc yp ion keys we e conside ed sa e i no sa ed on he RAM. S ill, TRESOR-HUNT [7] injec s mali- ciouscode o he ke nelusingaDMAa ackand hen ex ac s disk enc yp ion keys om he CPU in o he a ge sys em’s memo y om which hey can be e ie ed using a no mal DMA ans e . [48] e al. show ha an ad e sa y wi h physi- calaccess oade icecould impe sona e he de ice’s memo y con olle by a aching a malicious memo y con olle o he exposed pins o each DIMM socke o RAM; by doing so, an a acke would ha e ull access (READ/WRITE) o he a - ge memo y. Du lo e al. [17] in oduce he ulne abili y o emo e code execu ion on a ne wo k adap e and how i could comp omise he sys em- unning ke nel using DMA a ack. BROADPWN [6] is a no el app oach o p i ilege escala ion om exploi ing a bug in B oadcom WiFi chip in o a DMA a ack on he main p ocesso o he de ice. The e a e also ha dwa e ools ha pe o m a acks, such as PCI leech [41] ha pe o ms DMA a acks, Lan u le [27] ha pe o ms a man-in- he-middle a ack, and kon-boo [25] ha bypasses Windows passwo d p o ec ion [45]. The eme ging cache, DMA and ha dwa e a acks demon- s a e ha so wa e bugs can impose secu i y isks, and weak ha dwa e implemen a ion is becoming mo e com- mon, speci ically when new ea u es ely on old secu- i y assump ions. Fo example, in he Raspbe y PI case, CVE-2018-18068 is a p i ilege escala ion ulne abili y o non-au ho ised memo y access ia in e -p ocesso debug- ging. This ulne abili y is also demons a ed by [38]e al. who show ha because ARM 7 ( he ARM debugging 123