More Granular, Less Trust: Enforcing Intra-Process Isolation with Arm CCA in an Untrusted Management Environment

📅 2026-08-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对特权攻击问题,提出CCAegis系统,利用Arm CCA架构和静态分析方法实现进程内隔离,减少对操作系统的信任依赖。
📝 Abstract
With the increasing adoption of confidential computing, security-sensitive applications are often deployed in confidential virtual machines (CVMs), which reduce reliance on third-party cloud providers. However, privilege attacks originating from the OS remain a significant threat in these environments. Existing finer-grained isolation schemes, such as SHELTER, provide process-level protection but are still vulnerable to intraprocess attacks and potential collusion between the OS and intra-process adversaries. Many current intra-process isolation techniques continue to depend on the OS to manage and enforce isolation domains, leading to a large Trusted Computing Base (TCB). This gap highlights the need for more granular, less trust-dependent confidential computing solutions. In this paper, we present CCAegis, a system that extends the Arm Confidential Compute Architecture (CCA) to enforce intra-process isolation of sensitive data and operations, safeguarding them from both intraprocess adversaries and the OS. We employ static analysis to track the flow of sensitive data and identify functions that handle such data. Permission-switching instructions are inserted at the function call and return points, adjusting permissions via the Granule Protection Table (GPT) to ensure that only designated functions can access the isolated data. Notably, CCAegis places trust solely in the Secure Monitor, which configures the GPTs and manages domain switching, thereby minimizing the TCB. We implemented CCAegis on both an official emulator and a real development board to assess its performance. Our experimental results show that CCAegis effectively isolates sensitive data and operations, with performance overheads ranging from 1.01x to 1.43x compared to the original version across real-world cryptographic workloads.
Problem

Research questions and friction points this paper is trying to address.

confidential computing
intra-process isolation
trusted computing base
privilege attacks
sensitive data
Innovation

Methods, ideas, or system contributions that make the work stand out.

Intra-Process Isolation
Arm CCA
Granule Protection Table
Trusted Computing Base
Confidential Computing
🔎 Similar Papers
No similar papers found.
Shiqi Liu
Shiqi Liu
Central China Normal University & Monash University & Hunan Normal University
Large Language ModelsAgentAI for Social ScienceEducational Data MiningLearning Analytics
Z
Zhouqi Jiang
Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China; and JinYinHu Laboratory, Wuhan, 430040, China
J
Jie Wang
Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China; and JinYinHu Laboratory, Wuhan, 430040, China
Wei Zhou
Wei Zhou
Huazhong University of Science and Technology
IoT SecuritySystem SecurityHardware Security
Kun Sun
Kun Sun
George Mason University
Systems and network security
Zhaohui Chen
Zhaohui Chen
Peking University
Applied CryptographyComputer Architectures
Y
Yulai Xie
Key Laboratory of Information Storage Systems, Ministry of Education, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, 430074, China