scieee Science in your language
[en] (orig)

Attacking TrustZone on devices lacking memory protection

Read accessible full text

Attacking TrustZone on devices lacking memory protection

Author: Stajnrod, Ron,Ben Yehuda, Raz,Zaidenberg, Nezer Jacob
Publisher: Springer Science and Business Media LLC
Year: 2022
Source: https://jyx.jyu.fi/bitstream/123456789/79482/1/Stajnrod2021_Article_AttackingTrustZoneOnDevicesLac.pdf
This is a sel -a chi ed e sion o an o iginal a icle. This e sion
may di e om he o iginal in pagina ion and ypog aphic de ails.
Au ho (s):
Ti le:
Yea :
Ve sion:
Copy igh :
Righ s:
Righ s u l:
Please ci e he o iginal e sion:
CC BY 4.0
h ps://c ea i ecommons.o g/licenses/by/4.0/
A acking T us Zone on de ices lacking memo y p o ec ion
© The Au ho (s) 2021
Published e sion
S ajn od, Ron; Ben Yehuda, Raz; Zaidenbe g, Neze Jacob
S ajn od, R., Ben Yehuda, R., & Zaidenbe g, N. J. (2022). A acking T us Zone on de ices lacking
memo y p o ec ion. Jou nal o Compu e Vi ology and Hacking Techniques, 18(3), 259-269.
h ps://doi.o g/10.1007/s11416-021-00413-y
2022
Jou nal o Compu e Vi ology and Hacking Techniques
h ps://doi.o g/10.1007/s11416-021-00413-y
ORIGINAL PAPER
A acking T us Zone on de ices lacking memo y p o ec ion
Ron S ajn od1·Raz Ben Yehuda2·Neze Jacob Zaidenbe g2,3
Recei ed: 11 Augus 2021 / Accep ed: 26 No embe 2021
© The Au ho (s) 2021
Abs ac
ARM T us Zone o e s a T us ed Execu ion En i onmen (TEE) embedded in o he p ocesso co es. Some endo s o e
ARM modules ha do no ully comply wi h T us Zone speci ica ions, which may lead o ulne abili ies in he sys em. In his
pape , we p esen a DMA a ack u o ial om he insecu e wo ld on o he secu e wo ld, and he design and implemen a ion
o his a ack in a eal insecu e ha dwa e.
Keywo ds T us Zone ·Secu i y
1 In oduc ion
The de elopmen o he In e ne o Things (IoT) is hailed
as he hi d wa e o wo ld in o ma ion de elopmen a e
compu e s and he In e ne [56], wi h embedded sys ems
as he d i ing o ce o echnological de elopmen in many
domains in he eme ging pos -PC e a. As an inc easing num-
be o compu a ional de ices in eg a e in o ou li es in a
pe asi e and in isible way, secu i y becomes c i ical o
he dependabili y o all in elligen sys ems buil upon hese
embedded sys ems [40].
Embedded IoT p oduc s a e inc easingly no connec ed
o he powe g id. The e o e, such de ices a e cons ained
in e ms o compu ing powe due o limi ed elec ic powe
[29]. The cons ained na u e o such de ices means we a e
ying o “build a o ess om pebbles.” The e o e, we mus
ake he bes secu i y measu es o p e en malicious ac i i y
on hose de ices gi en he limi ed condi ions, which o en
means cu ing co ne s compa ed wi h o he esou ce- ich
a eas o compu ing (pe sonal compu e s, se e s, e c.).
BNeze Jacob Zaidenbe g
[email p o ec ed]
Ron S ajn od
[email p o ec ed]
Raz Ben Yehuda
[email p o ec ed]
1In e disciplina y Cen e , He zliya, Is ael
2Uni e si y o Jy äskylä, Jy äskylä, Finland
3College o Managemen Academic S udies, Is ael Uni e si y
o Jy äaskylä, Rishon LeZion, Is ael
ARM T us Zone [5] was in oduced as pa o he ARM 6
a chi ec u eandiswidelyusedinsma phones, able s, wea -
ables, and o he de ices. As T us Zone gains popula i y in
ha dwa e secu i y a chi ec u e o mobile de ices and IoT, i
is i al o ensu e he secu i y o T us Zone i sel [57].
Though ARM T us Zone is a g ea way o implemen
secu i y mechanisms ac oss IoT-embedded de ices, i is s ill
p one o inadequa e ha dwa e and so wa e implemen a-
ions.Thus, heha dwa eo di e en companieslikeGoogle,
Samsung, Huawei, e c., migh s ill be a ec ed by se e e
ulne abili ies ha comp omise he en i e secu i y sui e
[11,21,33,43].
One o he key ea u es o he AMBA (Ad anced Mic o-
con olle Bus A chi ec u e) AXI (Ad anced Ex ensible
In e ace) [3] is add ess space sepa a ion. Thus, lacking
hem c ea es insecu e memo y sepa a ion be ween he no -
mal wo ld and he secu e wo ld. In his pape , we p esen
a Di ec Memo y Access (DMA) a ack [26] on OP-TEE
(Open Po able T us ed Execu ion En i onmen ) [18,39].
OP-TEE is one o he common ope a ing sys ems ha un
on T us Zone. OP-TEE is a popula , open-sou ce, T us Zone
ope a ing sys em. We used OP-TEE as a e e ence T us Zone
OS o demons a e he a ack p esen ed in his pape , hough
he a ack is no due o an OP-TEE bug bu a he a missing
ha dwa e ea u e.
Ou a ack allows an a acke o execu e a bi a y code in
he secu e wo ld o ead a bi a y da a om he secu e wo ld
in o he ich OS. Ou a ack is a con ol- low a ack [14,55]
on he OP-TEE ke nel.
Also in he pape , we show a ha dwa e ulne abili y on
SoC [10] ha comp omises ARM T us Zone. Using he
123
R. S ajn od e al.
Fig. 1 No mal and secu ed wo lds ©A m
DMA a ack, we gain he abili y o eplace us ed appli-
ca ions wi h malicious ones. Fu he mo e, we demons a e
an a ack on a Raspbe y Pi compu e and explain how his
me hod a ec s o he pla o ms. This pape also p o ides
measu es o mi iga e his ulne abili y. The a ack was no
possible when AMBA AXI was p esen . Un o una ely, he
AMBAAXIisno p esen ona ewmode nha dwa ede ices,
including Raspbe y Pi 3,4 and Je son Nano.
2 Backg ound
2.1 ARM T us Zone
ARM T us Zone echnology aims o es ablish us in ARM-
based pla o ms. In con as o a TPM (T us ed Pla o m
Module), which is designed as a ixed- unc ion de ice wi h
a p ede ined ea u e se , T us Zone ep esen s a much mo e
lexible app oach by le e aging he CPU as a eely p o-
g ammable us ed pla o m module. To do ha , ARM
in oduced a special CPU mode called ‘secu e mode’ in addi-
ion o he egula no mal mode, he eby es ablishing he
no ions o a ‘secu e wo ld’ and a ‘no mal wo ld’ (Fig. 1).
The dis inc ion be ween hese wo lds is en i ely o hogonal
o he s anda d ing p o ec ion be ween use -le el and ke nel-
le el code, and hidden om he ope a ing sys em unning in
he no mal wo ld [1].
As an example, he Linux ke nel uns in EL1 and he
use space p ocesses execu e in EL0. The sepa a ion o he
secu e and no mal wo lds p o ec s speci ic RAM anges and
pe iphe als only accessible by he secu e wo ld. This sep-
a a ion means ha a comp omised no mal wo ld code (in
he use space o he ke nel) canno access hese memo y
anges o de ices. Howe e , his sepa a ion is en i ely a i i-
cial. The same co es un bo h secu e and no mal wo lds, and
hey use he same RAM (Fig. 2). The Non-Secu e (NS) bi
de e mines whe he he CPU execu es in he no mal wo ld
o in he secu e wo ld con ex o c ea e a sepa a ion in mem-
o y. T us Zone echnology ex ends beyond he p ocesso
in o he SoC pe iphe als connec ed wi h he SoC, such as
Fig. 2 NS Bi ©Lina o
he DRAM con olle (Fig. 2), he DMA (Di ec Memo y
Access), he secu e boo ROM, he GIC (Gene ic In e -
up Con olle ), he T us Zone Add ess Space Con olle
(TZASC), he T us Zone P o ec ion Con olle (TZPC), and
he Dynamic Memo y Con olle (DMC). The abo e com-
ponen s communica e h ough he AXI bus and he SoC
communica es wi h pe iphe als h ough he AXI_ o_APB
b idge. Thi d-pa y companies implemen he SoC pe iph-
e als; he e o e, some endo s do no comply en i ely wi h
T us Zone speci ica ions o educe cos s.
I is possible o access he en i e memo y om he secu e
wo ld bu no ice e sa. To a e se o EL3, we use he
Secu e Moni o Call (SMC) ins uc ion. Un o una ely, he
SMCimplemen a ion dependson hemanu ac u e and, hus,
is p one o bugs and o he ulne abili ies [21]. This pape
ocuses on he physical le el o memo y isola ion.
T us Zoneenablesmemo ypa i ionsbe weenno maland
secu e wo lds by using he TZASC and he TZPC. In addi-
ion, hesecon olle s p o idea secu eI/O o pe iphe als o e
s anda d in e aces. Fo ins ance, he TZPC ou es he SPI
access o he secu e wo ld. Fu he mo e, he NS bi secu es
on-chip pe iphe als om accessing om he Rich Execu-
ion En i onmen (REE) [8]. TZASC u ilizes he NS bi o
a memo y-mapped de ice like DRAM. These wo de ices
equi e suppo om he AXI bus, which is endo -speci ic.
Examples o he secu e wo ld us ed applica ions a e
secu e PIN and biome ic checks. Ano he us ed applica-
ion use case is Digi al Righ Managemen (DRM) o online
media. Again, p i a e in o ma ion is kep wi hin he secu e
wo ld so hacke s canno access he keys equi ed o e e se-
enginee he sys em. [36] desc ibes many mo e use cases o
T us Zone o IoT and mobile de ices.
2.2 OP-TEE
OP-TEE [39] is a T us ed Execu ion En i onmen (TEE)
designed as a companion o a non-secu e Linux ke nel
unning on ARM Co ex-A co es using he T us Zone ech-
nology. OP-TEE implemen s TEE In e nal Co e API 1.1.x,
which is he API exposed o T us ed Applica ions and he
TEE Clien API 1.0, which is he API desc ibing how o
communica e wi h a TEE. The GlobalPla o m API de ines
123
A acking T us Zone on de ices lacking memo y p o ec ion
Fig. 3 Ou line o T us Zone ©Miled opedia
hese speci ica ions [22]. The non-secu e OS is e e ed o
as he Rich Execu ion En i onmen (REE) in TEE speci ica-
ions.
OP-TEE is widesp ead in Snapd agon, IMX7, Hikey,
D agonBoa d, and many o he p oduc s.
OP-TEE is designed p ima ily o ely on he ARM
T us Zone echnology as he unde lying ha dwa e isola ion
mechanism. Howe e , i is compa ible wi h o he isola ion
echnologies sui able o he TEE concep and goals, such
as unning as a i ual machine o on a dedica ed p ocesso
co e. The main design goals o OP-TEE a e:
–Isola ion - OP-TEE p o ides isola ion om he non-
secu e OS and p o ec s he loaded T us ed Applica ions
(TAs) om each o he by using unde lying ha dwa e sup-
po .
–Small oo p in - OP-TEE should emain small enough
o eside in a easonable amoun o on-chip memo y as
ound on ARM-based sys ems.
–Po abili y - OP-TEE is aimed o be pluggable o di e -
en a chi ec u es and mus suppo a ious se ups such as
mul iple clien OSs o mul iple TEEs.
OP-TEE o e s h eads and sha ed memo y be ween he REE
o he secu ed OS, secu ed in e up s RPC om he secu e
wo ld o he REE and he SMC in e ace communica ion
om he REE o he secu e wo ld.
OP-TEE main componen s a e he:
– OP-TEEbina yOSexecu inginsecu eEL1 (T us Zone);
– OP-TEE Linux ke nel d i e ;
– Linux use space lib a ies; and
– a Linux use space daemon ( ee-supplican ) ha pe o ms
se iceson behal o he OP-TEE OS. I is esponsible o
passing he secu ed pa o he TA in o he secu e wo ld.
The e a e se e al ypes o TAs. The ea ly TAs ha d-link o
OP-TEE co e bina y and, he e o e, a e a ailable be o e he
REE uns. The second ype is an REE File sys em TA, which
is a ailable once he REE OS uns. The TA is composed o
wo pa s: secu ed and non-secu ed. I is signed and may be
enc yp ed. The key used o sign he TA is he same key used
osign heo iginalOP-TEE bina yco eblob usedwhenbuil .
Each TA is composed o wo pa s: a Linux use space
applica ion and a secu e wo ld applica ion. TA execu ion ol-
lows he nex s eps:
1. Ini ialize Con ex and Open Session: C ea es a con ex
and loads he TA secu e pa in o he OP-TEE co e in he
T us Zone.
2. In oke command. The non-secu e pa sends commands
o he secu ed TA ecei e .
3. Close session and Finalize con ex .
OP-TEE secu e s o age manage implemen s a secu e ile
sys em in wo ways: REE-FS and p o ec ed memo y (i pos-
sible). When a TA w i es da a o he secu ed s o age, he
us ed s o age in okes TEE ile sys em ope a ions o s o e
he da a. Then he TEE ile sys em enc yp s he da a and
passes he da a o ee supplican , keeping he da a in he REE
ile sys em. The TEE ile sys em is isible in he Linux ile
sys em as a di ec o y. Each objec wi hin he TEE is assigned
an in e nal iden i ie in addi ion o he TA objec s.
Kep in he TEE ile sys em, he key-manage esponsibil-
i ies a e da a enc yp ion and dec yp ion. I uses h ee ypes
o keys:
–SSK - Secu e s o age keys
–TSK - TA s o age keys
–FEK - File sys em key
The FEK de i es om TSK, which de i es om he SSK.
The SSK de i es om he unique ha dwa e key (HUK). The
HUK may no be accessible om he REE and i is up o he
manu ac u e o p o ide i , and p o ide access o i .
The OP-TEE ke nel is no enc yp ed. The e o e, a DMA
a ack on he OP-TEE ke nel is mo e s aigh o wa d han
on a TA-enc yp ed p og am as i bypasses he MMU pe mis-
sions model and he need o enc yp he code.
Each TA is signed and op ionally enc yp ed wi h a p i a e
key. The dec yp ion akes place in OP-TEE in he T us Zone.
Thus, he p og am in i s dec yp ed o m is only isible in he
secu ed RAM and he p ocesso ’s EL3 cache. I is, he e o e,
sensible o a ack in he dec yp ion a ea.
3 The DMA a ack
Di ec Memo y Access (DMA) allows I/O de ices o access
he memo y. DMA has e ol ed since i s incep ion and a e
in oducingmanyhigh-speedI/Ope iphe als, endo ss a ed
o inco po a e DMA engines o ini ia e DMA ansac ions
wi hou coo dina ing wi h he DMA con olle .
123
R. S ajn od e al.
ARMimplemen s head ancedmic ocon olle busa chi-
ec u e (AMBA), an open s anda d o on-chip in e connec
speci ica ion. DMA ansac ions connec h ough he DMA
con olle o he on-SOC AMBA AXI Bus (AMBA ad anced
ex ensible in e ace), and he AMBA AXI Bus suppo s
he T us Zone NS-bi . Thus, he DMA con olle can han-
dle secu e and non-secu e e en s simul aneously, wi h ull
suppo o in e up s and pe iphe als. Examples o DMA
de ices a e g aphic ca ds, ne wo k adap e s, Fi eWi e, Thun-
de Bol , e c. Al hough DMA is essen ial o as I/O ans-
ac ions, i also opens new ulne abili ies o DMA a acks
[7,26,46].
3.1 A ack goal
On a SOC lacking an SMMU (Sys em Memo y Managemen
Uni ) o TZASC, unning OP-TEE wi hou NS-bi suppo ,
hesecu edmemo y isaccessible h ough DMA ansac ions.
Th ough his ulne abili y, we can exploi T us Zone. We
escala e p i ileges by eading da a om he secu e wo ld.
In his a ack, we injec code o he Moni o in EL3, hus
execu ing malicious p og ams in he secu e wo ld OS. This
injec ion le s us bypass any alida ion o he secu e ope a ing
sys em and makes i possible o pa ch he EL1 ke nel and
execu e a bi a y code.
3.2 The a ack -‘ us ed’a bi a y code execu ion
We base he a ack p imi i e on W i e Wha Whe e ul-
ne abili y achie ed using DMA ansac ions. We use his
ulne abili y o show ha we can gain access o execu e a bi-
a y code in he OP-TEE OS. We bypass OP-TEE OS TA
signa u e alida ion and gain con ol o e e y us ed appli-
ca ion in he sys em, which we p esen la e in he pape . Ou
app oach is o change he opcodes ha e u n e o alues
o key unc ions wi hou changing he s ack. This echnique
impedes CFI ools such as gcc compile s ack gua d [13],
Clang CFI [2], o kFCI [34] o de ec ou a ack.
T us ed applica ions a e loca ed on he REE ile sys em
because i usually con ains mo e memo y; using his ile sys-
em makes i easie o upda e hose applica ions. The us ed
applica ions a e buil sepa a ely om he us ed ope a ing
sys em (simila o Linux ke nel and use space applica ions
in he no mal wo ld) and a e signed wi h a p i a e key om
he manu ac u e o he de ice applica ion (e.g. Samsung
sign hei us ed applica ions wi h hei p i a e key). Typical
usages o us ed applica ions a e DRM alida ions, HMAC
(keyed-hash message au hen ica ion code)-based one- ime
passwo d,AES enc yp ion and mo e. Using he us edappli-
ca ions, hede ice’s manu ac u e can ensu e a comp omised
use o ke nel will no b eak he de ice’s in eg i y. When he
manu ac u e wan s o upda e a us ed applica ion, hey sign
he new e sion wi h he same p i a e key and dis ibu e i o
Table 1 PI3 speci ica ions
SoC B oadcom BCM2837
CPU 4 co es, ARM Co ex A53, 1.2GHz,
(clocked o 700MHz)
RAM 1GB LPDDR2 (900MHz)
Clock 19.2MHz
he use s. When he secu e wo ld OS execu es a us ed appli-
ca ion, a secu i y e o will occu i he signa u e is in alid
and he p og am will no un.
In ou a ack, we i s use a DMA a ack o ead memo y
pages om he RAM. Pe iphe al de ices such as Fi eWi e,
PCI-connec ed de ices (Ne wo k ca ds, GPU, e c.) can ini i-
a e a DMA a ack, as demons a ed by [46,49], and [26]. The
CPU can also ini ia e DMA a acks by ac i a ing he DMA
con olle . A e eading memo y pages om he RAM,
we analyse he memo y and compa e i o ARM T us ed
Fi mwa e o loca e simila unc ions. (Mos T us Zone so -
wa e implemen a ions a e based on ARM T us ed Fi mwa e,
making e e se-enginee ing he code simple .) Mo eo e ,
some signi ican endo s’ secu e OS (T us ed Execu ion
En i onmen ) is in he ma ke (QSEE, OP-TEE). We com-
pa e ou memo y dump o he compiled e sions o hose;
by doing so, we can ind he unc ions ha alida e us ed
applica ion signa u es. Because in some cases, some o he
widely used TEE OS uses Add ess Space Layou Randomi-
sa ion(ASLR) [12], we can use he add ess om ou memo y
dump o o e ide us ed applica ions signa u e alida ions
wi h a DMA a ack. A e doing so, we can jus eplace any
TA wi h ou own malicious TA. Thus, e en hough we do
no know he co ec signa u e p i a e key, he TEE OS will
succeed o alida e ou malicious TA.
4 A ack e alua ion
4.1 Raspbe y Pi pla o m
We use a Raspbe y PI3 Model B o demons a e he a ack.
Table 1p esen s he Raspbe y PI3 Model B’s main speci i-
ca ions.
Figu e 4p esen s he BCM2837 chip. This B oadcom
SOC suppo s T us Zone and DMA ansac ions h ough
he AMBA Ad anced Mic ocon olle Bus A chi ec u e AXI
(Ad anced Ex ensible In e ace). As men ioned ea lie , no
all endo s’ implemen a ions comply wi h he en i e ha d-
wa e speci ica ions. Fo example, Fig. 4shows ha he
BCM2837 has he co ec AXI bus, bu i lacks he TZASC
and TZPC, making i ulne able o DMA a acks.
123

A acking T us Zone on de ices lacking memo y p o ec ion
Fig. 4 BCM2387 O e iew ©P emie Fa nell L d
Table 2 DMA Con ol Block Da a S uc u e
32-bi Wo d
O se
Desc ip ion Associa ed Read-
only Regis e
0 T ans e TI
In o ma ion
1 Sou ce Add ess SOURCE_AD
2 Des ina ion Add ess DEST_AD
3 T ans e Leng h TXFR_LEN
4 2D Mode S ide STRIDE
5 Nex Con ol Block Add ess NEXTCONBK
6–7 Rese ed - se o ze o N/A
4.2 OP-TEE o PI
OP-TEE suppo s Raspbe y Pi 3 Model B. In addi ion,
he ARM T us ed Fi mwa e is he basis o implemen ing
secu e wo ld so wa e o he ARM A-P o ile a chi ec u es
(ARM 8-A and ARM 7-A), including an Excep ion Le el
3 (EL3) Secu e Moni o . ARM T us ed Fi mwa e o he
Raspbe y Pi p o ides a sui able s a ing poin o he p o-
duc isa ion o secu e wo ld boo and un ime i mwa e [4].
When a endo uses OP-TEE on any ha dwa e in gene al
and on Raspbe y Pi speci ically, hey will mos likely use a
us ed applica ion o implemen ha dwa e secu i y measu es
and secu e hei de ices [35].
Table 3 DMA Con olle
32-bi Add ess o se Regis e name Desc ip ion
0 CS DMA Channel
Con ol and S a us
1 CONBLK_AD DMA Channel
Con ol Block Add ess
2 TI DMA Channel
T ans e In o ma ion
3 SOURCE_AD DMA Channel
Sou ce Add ess
4 DEST_AD DMA Channel
Des ina ion Add ess
5 TXFR_LEN DMA Channel
T ans e Leng h
6 STRIDE DMA Channel
2D S ide
7 NEXTCONBK DMA Channel
Nex CB Add ess
8 DEBUG DMA Channel
Debug
4.3 Raspbe y Pi DMA
As no ed ea lie , he CPU can access he DMA con olle .
The e o e, we chose o pe o m his a ack h ough he CPU.
We au ho ed a Linux ke nel module o pe o m he DMA
ansac ions.This module maps he DMA con olle and con-
igu es he DMA con ol block o ini ia e DMA ansac ions.
InOP-TEE’sLinuxke nel, heDMAcon olle add essspace
is no a ailable o he use space. Howe e , i is plausible
o assume ha an IoT de ice, o example, will enable his
de ice o pe iphe als access. We a gue an a ack is possi-
ble in many IoT de ices, and we will show he ollowing
scena ios:
1. Some IoT de ices map physical memo y o he use space
o inc ease pe o mance and sa e ke nel access, leading
o DMA con olle access.
2. Linux-based de ices (IoT de ices, ou e s, e c.) do no
upda e hei ke nel e sions e y o en due o compa ibil-
i y issues and many de ices. Thus one day’s ulne abili y
can be used o exploi he de ice and gain oo access o
pe o m ac ions on he DMA con olle [37,50].
3. A ack pe iphe al de ice (Blue oo h/WIFI chip, SSD con-
olle , e c.) o pe o m malicious DMA ansac ions
[17,47,52].
All hose scena ios may lead o a DMA a ack and, on some
de ices, o T us Zone ulne abili y.
123
R. S ajn od e al.
Fig. 5 Open session low
Table 2p esen s he Con ol Block s uc u e o a DMA in
he Raspbe y Pi. Table 3shows he DMA Con olle egis-
e s. To ini ia e a DMA ansac ion, we i s se he Con ol
Block s uc u e and hen se CONBLK_AD in he DMA con-
olle s uc u e. We pe o m wo ypes o DMA ansac ions:
1. Se SOURCE_AD o he secu e wo ld physical add ess o
ead da a o he secu e wo ld.
2. Se DEST_AD o he secu e wo ld physical add ess o
w i e malicious code o he secu e wo ld, he eby achie -
ing a bi a y code execu ion.
5 The a ack - e alua ion on aspbe y Pi
In he OP-TEE en i onmen , us ed applica ions a e signed
wi h he key om he build o he o iginal OP-TEE co e
blob. T us ed applica ions consis o a signed ELF heade ,
named om he UUID o he us ed applica ion (se du ing
compila ion ime) and he su ix . a.
When a us ed applica ion is eplaced in he REE ile-
sys em wi h he new one, he signa u es and UUID a e
alida ed by he OP-TEE OS (Fig. 5).
OP-TEE p o ides a Linux ke nel d i e o in e ac wi h
he OP-TEE in T us Zone. Fo ins ance, he PTA_SYSTEM
_OPEN _TA_BINARY unc ion access he OP-TEE OS.
PTA_SYSTEM_OPEN_TA_BINARY calls sys em _open _ a
_bina y, which looks o he use - us ed applica ion ELF
by he UUID in he s o age ( ile-sys em). A e inding he
us ed applica ion ELF in he REE ile-sys em, he OP-TEE
OS loads he ELF heade and maps he TA sec ions in o he
secu e memo y using PTA _SYSTEM_MAP _TA_BINARY.
A e loading he us edapplica ion, heuse isable oin oke
he us ed applica ion unc ionali y h ough he OP-TEE
Linux ke nel d i e .
We ocus on wo unc ions:
ee_ s_ a_open and
ee_ s_ a_ ead
called by PTA _SYSTEM _OPEN _TA _BINARY, and
PTA _SYSTEM _MAP _TA _BINARY, espec i ely.
T us ed applica ions bina ies con ain a signed heade so
ha a malicious use canno eplace he us ed applica-
ions. I a malicious use eplaces a us ed applica ion,
hen OP-TEE OS e u ns a secu i y e o when execu ing
hose us ed applica ions. In o de o OP-TEE OS o al-
ida e hose signa u es as a us ed applica ion execu es, he
unc ion ee_ s_ a_open loads he us ed applica ion heade ,
alida es he applica ion heade signa u e (Fig. 6) and ali-
da es i s size (Fig. 7). When OP-TEE OS maps he TA in o
he secu e memo y, i loads he applica ion o he memo y
using ee_ s_ a_ ead, which alida es he enc yp ed us ed
applica ion signa u e (Figs. 8and 9).
In he i s s ep, we e e se-enginee ed OP-TEE OS (using
ada e2 [31]) in o de o ind key opcodes o bo h unc ions
o exploi (Figs. 6,7,8,9). We used DMA ansac ions o
ead chunks o physical RAM in o de o ind he opcodes
ha ma ch he unc ions abo e. Once we loca ed he opcodes
in he memo y and no iced ha hese unc ions load in he
123
A acking T us Zone on de ices lacking memo y p o ec ion
1/∗Valida e heade signa u e ∗/
2 es = shd e i y signa u e(shd );
3i ( es != TEESUCCESS)
4go o e o ee payload ;
5
Fig. 6 ee_ s_ a_open Heade signa u e alida ion
1i ( a size != o s + shd −>img size) {
2 es = TEEERROR SECURITY ;
3go o e o ee hash ;
4}
5
Fig. 7 ee_ s_open TA size alida ion
Fig. 8 ee_ s_ a_ ead dec yp s a TA heade
same loca ion in physical memo y e e y ime. We used DMA
ansac ions o o e ide he e u n alues o he alida ions
men ioned abo e (Figs. 6,7,8,9), he eby gaining he abil-
i y o compile ou own us ed applica ion, sign i wi h an
a bi a y key and execu e i on he machine.
We eplaced wo ypeso opcodes: hecompa isonopcode
o w0 egis e was eplaced wi h cmp w0,w0 so i always
e u ned ue and, when mo ing he e u n alue o he unc-
ion o w0 egis e , we eplaced his command wi h eo
w0,w0,w0 so he alue o w0 egis e would be 0, again ha -
ing he e u n alues o he alida ion unc ions equal ue.
We we e able o pe o m his eplacemen using jus a simple
DMA ansac ion wi h he con ol block DEST_AD, which
con ains he physical add ess o he opcodes we ound, all o
which a e loca ed in he secu e wo ld memo y. In ou case,
we compiled a new TA wi h he same UUID as he o igi-
nal one and pu i in he ile-sys em loca ion. By execu ing
ou malicious TA, we gained he abili y o manipula e ARM
T us Zone o un in alidly signed bina ies. Fo ins ance, we
compiled a ake AES TA (gi en in he examples o he OP-
TEE sui e) ha enc yp s da a wi h ou malicious key. Thus,
e e y ime he use uses his TA o pe o m AES, i will no
enc yp he da a wi h he sec e key.
Fig. 9 ee_ s_ ead alida es he enc yp ed heade agains he hash o
he plain heade
5.1 O he a ack possibili ies
Using DMA a acks on he T us Zone gi es a wide ange
o a ack possibili ies. In his pape , we show he usage o
DMA a acks o pe o m ACE (A bi a y Code Execu ion);
howe e , i isalsopossible o use his me hod o eada bi a y
code om physical memo y whe eby a malicious use can
access sensi i e da a.
6 Mi iga ion
When choosing an SoC, you mus compa e he de ice
equi emen s o he SoC ea u es. In ou case, when selec -
ing an SoC, we wan o make su e he SoC a chi ec u e has
all he chips equi ed o ARM T us Zone o wo k co ec ly
(TZASC, TZPC, suppo ed bus, e c.). Un o una ely, check-
ing he SoC a chi ec u e is no always easy and no au oma ic
because no all endo s publish hei SoC a chi ec u e. We
sugges ha SoC endo s be mo e anspa en abou hei
a chi ec u e when i comes o secu i y ea u es. We also
ecommend ha manu ac u e s ensu e hei SoC ha dwa e
suppo sT us ZoneARMCo eandT us Zonespeci ica ions.
In cases whe e a ully compa ible T us Zone is no a ail-
able (lack o ha dwa e on he SoC ha makes he T us Zone
secu e), we lis o he p o ec ion echniques:
– Using SMMU (simila o IOMMU on In el x86) o con-
igu e speci ic add esses o DMA con olle s. SMMU
wo ks as MMU o BUS access so any memo y access
h ough he BUS is ma ched o he pe mission con ig-
u ed o he accessed add ess. Wi h SMMU and a co ec
con igu a ion, a DMA a ack h ough pe iphe als will no
be possible. I is also impo an o no e a ke nel a acke
could change his con igu a ion.
– In he case o Raspbe y Pi, by disabling he DMA con-
olle , a non-p i ileged use o pe iphe al would no be
able o use DMA ansac ions.
– Se he secu e wo ld on a di e en RAM wi hou DMA
con olle mapping so he e is no physical in e ace
be ween he no mal and secu e wo lds.
123
R. S ajn od e al.
A so wa e echnique would enc yp pa s o he OP-TEE
code i sel , mainly he TA deciphe unc ions. Then, when
OP-TEE uns hese unc ions,i dec yp s hemin o hecache,
alida es he TA, and e ic s he p ocesso s’ cache. Using his
me hod [54], an a acke would ha e o ime his a ack o ge
he RAM code. Howe e , combining his me hod wi h ASLR
impedes he a ack.
7 Rela ed wo k
In he a ea o ARM, [11] e al. desc ibe a downg ade o oll-
back a ack. A us ed applica ion is enc yp ed o secu i y
pu poses by public and p i a e keys ha o igina e om he
ha dwa e. In cases when he sys em is upda ed, old TAs can
s ill be execu ed on he new sys em. A downg ade a ack is
when an a acke exploi s a ulne abili y in he old TA e -
sion by pa ching he old e sion on o he new TA e sion.
Acco ding o [11], he abo e applies o he OP-TEE and
QSEE (Qualcomm’s Secu e Execu ion En i onmen ). [11]
e al. desc ibe a simple p ocedu e o mobile phones: oo
he de ice, emoun he ‘sys em’ pa i ion in READ-WRITE
mode, eplace hecu en us le wi h anold ulne able us -
le and use he us le . [11] e al. desc ibe ano he possible
ollback a ack on he chain o us and p o es i possible o
downg ade he boo loade success ully.
Many wo ds ha e been w i en on side-channel a acks
and o he ulne able a ge s in ARM a chi ec u e in p io
esea ch. Fo example, A mageddon [32] e al. explo e
a acks on ARM caches, concen a ing on c oss-co e cache
a acks in non- oo ed ARM mobile de ices and showing a
no el app oach o exploi he cohe ence p o ocols. Al hough
mos sma phones ha e mul iple p ocesso s ha do no sha e
caches, cache cohe ence p o ocols allow p ocesso s o e ch
cache lines. By exploi ing he lack o cache lush on ‘old’
ARM co es (be o e ARM 8), a no el echnique ha analy-
ses cache e ic ion s a egies and ano he app oach o pe o m
cycle- iming wi hou oo access, he A mageddon [32]e
al. p o ide a me hod o gain sensi i e in o ma ion such as
in e -keys oke imings o he leng h o a swipe ac ion. As
o T us Zone ulne abili y, A mageddon [32]e al.shows
a cache a ack used o moni o cache ac i i y caused wi hin
he ARM T us Zone om he no mal wo ld.
Flush and Reload a ack [53] e al. ake ad an age o he
cohe ence p o ocol in a mul ip ocesso compu e . In mos
ARM p ocesso s, he las -le el cache is inclusi e (i.e. i
includes low-le el cache lines); he e o e, examining he
con en o he las -le el cache may p o ide he con en s o
low-le elcachelineso ano he co e.Howe e , heAu oLock
[19] ool assesses he ac ual isk in cache a acks, p e en s
c oss-cache e ic ions and highligh s he in icacies o cache
a acks in ARM. [19] e al. claim ha unlike In el p oces-
so s, many ARM caches a e bo h inclusi e and exclusi e
and, he e o e, ha den he LLC (las -le el cache) a acks. In
hei wo k,Demme e al. [16] demons a e ha small changes
o he cache a chi ec u e ha e a conside able impac on side-
channel ulne abili y. Finally, [28] e al. p esen in hei wo k
a side-channel cache a ack agains Samsung T us Zone ia
he And oid’s Keymas e c yp og aphic unc ions.
Like cache a acks, DMA a acks a e con inuously unde
esea ch. [49] e al. show ha by dumping memo y e-
quen ly enough using DMA ansac ions, w i e pa e ns can
be examined. Some algo i hms, such as he RSA Mon -
gome y ladde [23], may leak sec e s. DAGGER [46], a
DMA-based keys oke logge , ex il a es cap u ed da a o
an ex e nal en i y and canno be de ec ed by an i- i us so -
wa e. [46] shows how DAGGER can s eal c yp og aphic
keys, a ge OS ke nel s uc u e, and copy iles om he ile
cache on Linux and Windows h ough DMA malwa e e en
i he memo y add esses a e andom. [46] e al. also o e
coun e measu es o de ec DMA a acks. [9] e al. in eg a e
DMA a acks h ough Fi eWi e in o Me asploi [24]. Thus,
an a acke could use Me asploi [24] o payload selec ion,
session con ol, e c. and a ack ia DMA o e Fi ewi e.
TRESOR-HUNT [7] elies on he insigh ha DMA-
capable ad e sa ies a e no es ic ed o simply eading
physical memo y bu can w i e a bi a y alues o memo y as
well. Ha d disk enc yp ion keys we e conside ed sa e i no
sa ed on he RAM. S ill, TRESOR-HUNT [7] injec s mali-
ciouscode o he ke nelusingaDMAa ackand hen ex ac s
disk enc yp ion keys om he CPU in o he a ge sys em’s
memo y om which hey can be e ie ed using a no mal
DMA ans e . [48] e al. show ha an ad e sa y wi h physi-
calaccess oade icecould impe sona e he de ice’s memo y
con olle by a aching a malicious memo y con olle o he
exposed pins o each DIMM socke o RAM; by doing so, an
a acke would ha e ull access (READ/WRITE) o he a -
ge memo y. Du lo e al. [17] in oduce he ulne abili y o
emo e code execu ion on a ne wo k adap e and how i could
comp omise he sys em- unning ke nel using DMA a ack.
BROADPWN [6] is a no el app oach o p i ilege escala ion
om exploi ing a bug in B oadcom WiFi chip in o a DMA
a ack on he main p ocesso o he de ice.
The e a e also ha dwa e ools ha pe o m a acks, such
as PCI leech [41] ha pe o ms DMA a acks, Lan u le [27]
ha pe o ms a man-in- he-middle a ack, and kon-boo [25]
ha bypasses Windows passwo d p o ec ion [45].
The eme ging cache, DMA and ha dwa e a acks demon-
s a e ha so wa e bugs can impose secu i y isks, and
weak ha dwa e implemen a ion is becoming mo e com-
mon, speci ically when new ea u es ely on old secu-
i y assump ions. Fo example, in he Raspbe y PI case,
CVE-2018-18068 is a p i ilege escala ion ulne abili y o
non-au ho ised memo y access ia in e -p ocesso debug-
ging. This ulne abili y is also demons a ed by [38]e
al. who show ha because ARM 7 ( he ARM debugging
123