Trusted Execution Environments (TEEs) on resource-constrained microcontrollers are an emerging area of interest, yet they present unique security challenges, particularly in managing encrypted code execution through limited secure memory. This paper presents a formal verification approach for Umbra, a TEE framework for ARM TrustZone-M, currently under development, that implements secure caching mechanisms to execute encrypted enclaves from flash memory. We employ model checking techniques to formally analyze critical security properties, including data isolation between secure and non-secure worlds, integrity of the Enclave Flash Block Cache (EFBC), and resilience against identified threats such as Direct Memory Access (DMA) handover attacks and timing-based side channels. Our threat model considers privileged attackers in the non-secure world and compromised host operating systems, analyzing vulnerabilities in DMA reconfiguration windows and context switch dependencies. Through formal modeling, we identify replay and timing side-channel attacks; by introducing countermeasures, these guarantees are restored in the model.
A formally verified secure caching mechanism on trustzone-enabled microcontrollers / Bramante, S., Busi, M., Cilardo, A., Focardi, R., Luccio, F., Mercogliano, S.. - (2026), pp. 1-3. (DATE 2026 - Design, Automation and Test in Europe Conference Verona, Italy 20-22/04/2026) [10.23919/DATE69613.2026.11539421].
A formally verified secure caching mechanism on trustzone-enabled microcontrollers
Bramante Salvatore;
2026
Abstract
Trusted Execution Environments (TEEs) on resource-constrained microcontrollers are an emerging area of interest, yet they present unique security challenges, particularly in managing encrypted code execution through limited secure memory. This paper presents a formal verification approach for Umbra, a TEE framework for ARM TrustZone-M, currently under development, that implements secure caching mechanisms to execute encrypted enclaves from flash memory. We employ model checking techniques to formally analyze critical security properties, including data isolation between secure and non-secure worlds, integrity of the Enclave Flash Block Cache (EFBC), and resilience against identified threats such as Direct Memory Access (DMA) handover attacks and timing-based side channels. Our threat model considers privileged attackers in the non-secure world and compromised host operating systems, analyzing vulnerabilities in DMA reconfiguration windows and context switch dependencies. Through formal modeling, we identify replay and timing side-channel attacks; by introducing countermeasures, these guarantees are restored in the model.| File | Dimensione | Formato | |
|---|---|---|---|
|
A_Formally_Verified_Secure_Caching_Mechanism_on_TrustZone-enabled_Microcontrollers.pdf
Accesso riservato
Descrizione: A Formally Verified Secure Caching Mechanism on TrustZone-enabled Microcontrollers
Tipologia:
Versione Editoriale (PDF)
Licenza:
Copyright dell'editore
Dimensione
248.93 kB
Formato
Adobe PDF
|
248.93 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


