• Home
  • Search
  • Colony: A Privileged Trusted Execution Environment With Extensibility
  • Cite Icon18
  • https://doi.org/10.1109/tc.2021.3055293Copy DOI Icon

Colony: A Privileged Trusted Execution Environment With Extensibility

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The code base of system software is growing fast, which results in a large number of vulnerabilities: for example, 296 CVEs have been found in Xen hypervisor and 2195 CVEs in Linux kernel. To reduce the reliance on the trust of system software, many researchers try to provide trusted execution environments (TEEs), which can be categorized into two types: non-privileged TEEs and privileged TEEs. Non-privileged TEEs (e.g., Intel SGX) are extensible, but cannot protect security services like virtual machine introspection (VMI) due to the lack of system-level semantics. On the contrary, privileged TEEs (e.g., the secure world of ARM TrustZone) have system-level semantics, but any additional service implemented in the privileged TEE directly increases the TCB of the entire system. In this article, we propose a new design of TEE to support system-level security services and achieve better extensibility with a small TCB. Each TEE instance of the proposed design is named a <small>Colony</small>. Specifically, we introduce a <i>secure monitor</i> for isolation and capability management. Each <small>Colony</small> is assigned capabilities to access only necessary system-level semantics. We use the new TEE to build four security services, including secure device accessing, VMI tools, a system call tracer, and a much more complex service to virtualize ARM TrustZone with multiple <small>Colonies</small>. We have implemented the system on ARMv7 and ARMv8 platforms, in Xen hypervisor and Linux kernel, and perform a detailed evaluation to show its efficiency.<xref rid="fn1" ref-type="fn"><sup>1</sup></xref><fn id="fn1"><label>1.</label> This paper is an extended version of the conference paper published in USENIX Security&#x2019;17: vTZ: Virtualizing ARM TrustZone <xref ref-type="bibr" rid="ref29">[29]</xref> . A brief summary of differences is in Section<xref ref-type="sec" rid="sec8">8</xref> . </fn>

Similar Papers
  • Research Article

Pontis: A decentralized framework for unifying remote attestation and enabling interoperability between heterogeneous TEEs

  • Jul 01, 2026
  • Information Processing &amp; Management
  • Jun Li +6
  • Conference Article
  • Citations19

Secure enrollment and practical migration for mobile trusted execution environments

  • Nov 08, 2013
  • Claudio Marforio +4
  • Conference Article
  • Citations64

Hardware-Backed Heist

  • Nov 06, 2019
  • Keegan Ryan
  • Book Chapter

Formalizing and Verifying GP TEE TA Interface Specification Using Coq

  • Jan 01, 2017
  • Xia Yang +3
  • Conference Article
  • Citations11

Formal Verification of Memory Isolation for the TrustZone-based TEE

  • Dec 01, 2020
  • Yuwei Ma +5
  • Conference Article
  • Citations29

SecDeep

  • May 18, 2021
  • Renju Liu +4
  • Book Chapter
  • Citations36

Attestation Mechanisms for Trusted Execution Environments Demystified

  • Jan 01, 2022
  • Jämes Ménétrey +6
  • Research Article

Confronting the Limitations of Hardware-Assisted Security

  • Sep 01, 2020
  • IEEE Security &amp; Privacy
  • Mohammad Mannan +1
  • Conference Article
  • Citations58

Automated partitioning of android applications for trusted execution environments

  • May 14, 2016
  • Konstantin Rubinov +3
  • Research Article
  • Citations13

HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEE

  • Sep 27, 2023
  • Computers &amp; Security
  • Qifan Wang +5
  • Conference Article
  • Citations20

Securing Time in Untrusted Operating Systems with TimeSeal

  • Dec 01, 2019
  • Fatima M Anwar +3
  • Book Chapter
  • Citations6

An Effective Authentication for Client Application Using ARM TrustZone

  • Jan 01, 2017
  • Hang Jiang +5
  • Research Article
  • Citations1

SGXFault: An Efficient Page Fault Handling Mechanism for SGX Enclaves

  • May 01, 2024
  • IEEE Transactions on Dependable and Secure Computing
  • Omais Shafi Pandith
  • Preprint Article

Enhancing data security in GA4GH task execution services with confidential computing

  • Mar 20, 2024
  • Faculty of 1000 Research Ltd
  • Pavel Nikonorov +4
  • Conference Article
  • Citations14

Optimized trusted execution for hard real-time applications on COTS processors

  • Nov 06, 2019
  • Anway Mukherjee +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.