An exploration of ARM TrustZone technology

Behind the term TrustZone lies a security technology that is almost omnipresent in ARM-based devices, ranging from low-cost development boards to most mobile phones. Yet, there hardly exists a public body of knowledge around it. This prompted the Genode developers to investigate. Today, they published their findings in the form of a comprehensive article and an demonstration video.

In contrast to TPMs, which were designed as fixed-function devices with a predefined feature set, TrustZone represented a much more flexible approach by leveraging the CPU as a freely programmable trusted platform module. To do that, ARM introduced a special CPU mode called “secure mode” in addition to the regular normal mode, thereby establishing the notions of a “secure world” and a “normal world”. The distinction between both worlds is completely orthogonal to the normal ring protection between user-level and kernel-level code and hidden from the operating system running in the normal world. Furthermore, it is not limited to the CPU but propagated over the system bus to peripheral devices and memory controllers. This way, ARM-based platforms become effectively kind of a split personality. When secure mode is active, the software running on the CPU has a different view on the whole system than software running in non-secure mode.

The Genode team is nothing short of amazing. Not only are they developing unique software, they’re also doing stuff like this. Much respect for these women and men.

16 Comments

  1. 2014-04-10 10:11 pm
    • 2014-04-11 3:57 am
      • 2014-04-11 4:03 am
        • 2014-04-11 6:42 am
          • 2014-04-11 6:45 am
          • 2014-04-11 8:28 am
        • 2014-04-11 8:16 am
      • 2014-04-11 4:05 am
    • 2014-04-11 10:19 am
      • 2014-04-12 6:28 am
  2. 2014-04-11 1:32 am
  3. 2014-04-11 3:51 pm
    • 2014-04-11 7:48 pm
      • 2014-04-12 10:38 am
        • 2014-04-12 11:56 am
    • 2014-04-12 12:19 pm