MATEE: Efficiently Bridging the Semantic Gap in TrustZone via Arm Pointer Authentication

📅 2026-08-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对TrustZone中的语义鸿沟问题,提出MATEE系统利用Arm指针认证技术绑定并验证客户端身份,有效防止恶意请求伪造,同时保持低运行时开销。
📝 Abstract
Trusted Execution Environments (TEEs) employ hardware-based isolation mechanisms to safeguard the confidentiality and integrity of sensitive code and data. One such prevalent implementation is Arm TrustZone, which partitions the system into the secure and normal (non-secure) worlds. However, this partitioning results in the secure world having very limited visibility into the operating information of the normal world, creating a semantic gap between these two worlds. Specifically, the secure world lacks an effective user identity authentication when receiving data requests from the normal world. Consequently, malicious Client Applications (CAs) in the normal world can deceive Trusted Applications (TAs) in the secure world by utilizing elaborate request parameters, compromising the sensitive data stored by other CAs. We systematically classify these Semantic Gap Vulnerabilities (SGVs) and propose a mate system for the TEE called MATEE to defend against SGVs. MATEE utilizes Arm Pointer Authentication (PA) to bind each request to the corresponding CA's identity and then verifies the identity when the CA accesses sensitive data, thereby preventing malicious request forgery. In particular, MATEE isolates sensitive data of different CAs without modifying existing CAs and TAs. Our evaluation demonstrates that MATEE successfully defends against SGVs with a minimal runtime overhead (2.19%).
Problem

Research questions and friction points this paper is trying to address.

Trusted Execution Environments
Semantic Gap
Arm TrustZone
User Identity Authentication
Sensitive Data
Innovation

Methods, ideas, or system contributions that make the work stand out.

Semantic Gap Vulnerabilities
Arm Pointer Authentication
Trusted Execution Environments
Identity Verification
🔎 Similar Papers
No similar papers found.
Shiqi Liu
Shiqi Liu
Central China Normal University & Monash University & Hunan Normal University
Large Language ModelsAgentAI for Social ScienceEducational Data MiningLearning Analytics
X
Xiang Li
Research Center for Basic Theories of Intelligent Computing, Research Institute of Basic Theories, Zhejiang Laboratory, Hangzhou, 311100, China
J
Jie Wang
Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China; also with JinYinHu Laboratory, Wuhan, 430040, China
Y
Yongpeng Gao
Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China; also with JinYinHu Laboratory, Wuhan, 430040, China
J
Jiajin Hu
Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China; also with JinYinHu Laboratory, Wuhan, 430040, China