Search arXiv⌕ Search

arXiv subjects

Yongpeng Gao

Publications and source records attributed to Yongpeng Gao.

2 recordsLinked to original sources

NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA

Arm Confidential Compute Architecture (CCA) provides hardware primitives for confidential computing, but its standard CVM-based deployment model still isolates software only at the VM granularity. This leaves two critical gaps: the guest OS remains in the Trusted Computing Base, and applications lack any intra-process isolation boundary, exposing secrets to vulnerabilities such as Heartbleed. While intra-address-space isolation offers a theoretical solution, realizing it under an adversarial OS faces a fundamental scalability-efficiency trade-off: existing hardware primitives are either strictly limited in domain capacity or incur prohibitive privileged-switching latency. To bridge this gap, we propose NanoZone, a novel isolation architecture built on Arm CCA primitives. Rather than extending the realm-world software stack, NanoZone protects normal-world processes and enforces fine-grained intra-process isolation from a minimal root-world monitor. NanoZone unifies the speed of user-space permission switching with the capacity of physical address space isolation to achieve effectively unlimited domain scalability. To mask the latency of privileged transitions, it employs a locality-aware scheduling policy that maximizes execution residency within the fast user-level tier. To defeat an adversarial OS, NanoZone anchors its root of trust in the root world, offloading critical isolation enforcement away from the untrusted kernel. Against intra-process adversaries, it further leverages hardware-assisted Code-Pointer Integrity (CPI) to prevent domain-switching abuse. We prototyped NanoZone on Arm's official emulator and on physical hardware. Evaluation on real-world server applications shows that, compared to process-level isolation systems, our fine-grained protection preserves about 95% of their throughput.

cs.CR↗

MATEE: Efficiently Bridging the Semantic Gap in TrustZone via Arm Pointer Authentication

Trusted Execution Environments (TEEs) employ hardware-based isolation mechanisms to safeguard the confidentiality and integrity of sensitive code and data. One such prevalent implementation is Arm TrustZone, which partitions the system into the secure and normal (non-secure) worlds. However, this partitioning results in the secure world having very limited visibility into the operating information of the normal world, creating a semantic gap between these two worlds. Specifically, the secure world lacks an effective user identity authentication when receiving data requests from the normal world. Consequently, malicious Client Applications (CAs) in the normal world can deceive Trusted Applications (TAs) in the secure world by utilizing elaborate request parameters, compromising the sensitive data stored by other CAs. We systematically classify these Semantic Gap Vulnerabilities (SGVs) and propose a mate system for the TEE called MATEE to defend against SGVs. MATEE utilizes Arm Pointer Authentication (PA) to bind each request to the corresponding CA's identity and then verifies the identity when the CA accesses sensitive data, thereby preventing malicious request forgery. In particular, MATEE isolates sensitive data of different CAs without modifying existing CAs and TAs. Our evaluation demonstrates that MATEE successfully defends against SGVs with a minimal runtime overhead (2.19%).

cs.CR↗