UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets

Jubayer Mahmod, Matthew Hicks

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 5

Overview

The talk "UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets" by Jubayer Mahmod and Matthew Hicks from Virginia Tech introduces a groundbreaking physical attack methodology that systematically exploits transistor aging in SRAM (Static Random-Access Memory) to bypass hardware-backed security mechanisms like ARM TrustZone. This research demonstrates how secrets stored in on-chip memory, even after architectural erasure or isolation, can be exfiltrated by accelerating the physical aging process of memory cells. The ubiquity of ARM-based devices, from small sensors to desktop computers, underscores the critical importance of this vulnerability, challenging fundamental assumptions about the permanence of data erasure and the effectiveness of current hardware isolation techniques against sophisticated physical adversaries.

Watch on YouTube

Visual summary for UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets by Jubayer Mahmod, Matthew Hicks
Visual summary for UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets by Jubayer Mahmod, Matthew Hicks

Key moments

  1. 0:00 Introducing UnTrustZone: Bypassing TEEs via SRAM remnants
  2. 1:50 SRAM power-on state reveals analog data remnants
  3. 3:00 Accelerating aging to 'burn-in' data into SRAM
  4. 4:15 Arm TrustZone: Shared hardware, vulnerable secrets
  5. 6:00 Overcoming technical challenges to accelerate SRAM aging
  6. 7:00 Threat model and experimental setup overview
  7. 8:00 Demonstration: Exfiltrating cryptographic keys with UnTrustZone
  8. 8:40 Demonstration: High-accuracy proprietary firmware exfiltration

UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets

Speakers: Jubayer Mahmod; Matthew Hicks

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=KnNLuTITHi8

Overview

The talk "UnTrustZone: Systematic Accelerated Aging to Expose On-chip Secrets" by Jubayer Mahmod and Matthew Hicks from Virginia Tech introduces a groundbreaking physical attack methodology that systematically exploits transistor aging in SRAM (Static Random-Access Memory) to bypass hardware-backed security mechanisms like ARM TrustZone. This research demonstrates how secrets stored in on-chip memory, even after architectural erasure or isolation, can be exfiltrated by accelerating the physical aging process of memory cells. The ubiquity of ARM-based devices, from small sensors to desktop computers, underscores the critical importance of this vulnerability, challenging fundamental assumptions about the permanence of data erasure and the effectiveness of current hardware isolation techniques against sophisticated physical adversaries.

The core premise of UnTrustZone is to leverage controlled environmental stressors – specifically elevated voltage and temperature – to drastically reduce the time it takes for data remnants to become physically "burned in" to SRAM cells. This accelerated aging process biases the power-on state of individual SRAM cells, allowing an attacker with physical access to infer previously stored data with high accuracy. The research presents a novel path for attackers to retrieve sensitive information like cryptographic keys, proprietary firmware, and cached data, even from secure enclaves protected by ARM TrustZone, by operating at the device layer rather than relying on software vulnerabilities.

This work highlights a critical gap in the current security paradigm, where architectural safeguards are deemed sufficient against many physical attacks. UnTrustZone reveals that the physical characteristics of memory cells themselves can be manipulated to disclose information, necessitating a re-evaluation of how sensitive data is handled in hardware and prompting the development of new, device-level defensive strategies to truly secure on-chip secrets.

Background

▶ Watch: Introducing UnTrustZone: Bypassing TEEs via SRAM remnants (0:00)

The increasing prevalence of connected devices has unfortunately been accompanied by a rise in physical attacks, which often target systems that are readily accessible and may lack comprehensive physical security hardening. Traditional physical attacks, such as cold boot attacks or direct memory probing, aim to extract data from external memory. To counter these, security paradigms often advocate for storing sensitive data in plaintext on-chip SRAM and encrypting everything off-chip, leveraging Trusted Execution Environments (TEEs) like ARM TrustZone. TEEs are designed to either erase or block access to secure memory areas from an unauthorized security state, thus mitigating many external memory disclosure attacks. However, UnTrustZone reveals that this architectural barrier is insufficient due to the phenomenon of SRAM data remnants.

SRAM is the ubiquitous memory found inside most chips, used by processors for quick caches and by microcontrollers for runtime data. An SRAM cell typically consists of two cross-coupled inverters in a feedback loop, offering high speed and requiring no refresh. A key characteristic of SRAM is its power-on state: when an array of SRAM cells powers on, approximately 50% will settle into a logic '1' state and the other 50% into a logic '0' state. This distribution is largely random spatially. This randomness, however, is not absolute; it is a result of a race condition between the two inverters during startup. This race condition can be influenced by subtle physical biases within the cell.

The attack vector exploited by UnTrustZone is transistor aging. When a logic '1' (or '0') is stored in an SRAM cell for a prolonged period, the transistors associated with that state experience increased stress. Specifically, the P-MOS transistor (P1) of inverter one, if consistently 'on' when storing a '1', slows down due to Negative Bias Temperature Instability (NBTI). While other aging effects like PBTI (Positive Bias Temperature Instability) also occur, the overall effect on the P-MOS is often dominant. Over years, this aging process creates a physical bias in the cell, causing it to preferentially power on into the state it previously held. This provides an indirect way to infer previously stored data by observing subsequent power-on states. The challenge, however, is that this natural aging process is incredibly slow, taking years or even decades to manifest into a security concern.

The researchers realized that the physical phenomena driving aging – strong vertical electric fields in the gate region and elevated temperatures – can significantly accelerate this process. By exposing an SRAM cell that holds a secret to elevated voltage and temperature, the "baking" or burning-in of the secret into the analog layer of the silicon is dramatically accelerated. This insight forms the foundation of UnTrustZone: to accelerate the aging process to a practical timescale, thereby making long-term data remanence a real and immediate threat to on-chip secrets, even in systems protected by robust architectural isolation mechanisms like ARM TrustZone.

ARM TrustZone was chosen as the target TEE due to the ubiquity of ARM devices. TrustZone is a hardware-backed isolation mechanism that creates virtual cores, distinguishing between a "secure world" with higher security privileges and a "normal world." Software running in the non-secure state cannot access secure memory areas, preventing malicious or buggy software, including potentially compromised operating systems, from accessing critical data. However, a crucial observation is that secure and non-secure worlds share the same physical hardware, specifically cache lines which are made of SRAM. The only difference at the physical hardware level is a tag bit indicating whether a cache line belongs to the secure or normal world. This shared physical substrate, despite architectural isolation, creates the attack surface for UnTrustZone, allowing the researchers to bypass architectural controls by interacting directly with the device layer.

Key Findings

▶ Watch: Accelerating aging to 'burn-in' data into SRAM (3:00)

The central and most significant finding of the UnTrustZone research is that accelerated aging of SRAM cells can systematically expose on-chip secrets, effectively bypassing architectural security barriers like ARM TrustZone. This contradicts the common assumption that data in secure enclaves is sufficiently protected by architectural isolation and prompt erasure. The key discoveries and contributions are multifaceted:

Firstly, the researchers demonstrated that the incredibly slow process of natural transistor aging, which typically takes years or decades to manifest as a security concern, can be dramatically accelerated through the application of elevated voltage and temperature. By subjecting SRAM cells to these stressors, the physical biases that cause data remanence can be induced within a practical timeframe, making the attack feasible. This acceleration mechanism fundamentally changes the threat landscape for on-chip data.

Secondly, UnTrustZone proved that this accelerated aging allows for the exfiltration of sensitive data from secure memory regions, even after the system has attempted to erase or restrict access to that data. This was demonstrated across various attack scenarios, including:

  • Cryptographic assets: Successfully exfiltrating AES keys used by secure world applications, even after a full chip erase, with high accuracy.
  • Proprietary firmware: Retrieving proprietary firmware running from on-chip SRAM, achieving close to 90% accuracy on individual devices, and even higher accuracy when combining data from multiple devices running the same firmware version. This highlights a vulnerability for intellectual property protected by on-chip execution.
  • Cached data in complex systems: Even in sophisticated processors like the Cortex-A53 and Cortex-A72, data residing in both instruction (I-cache) and data (D-cache) caches could be recovered. The attack achieved a 20% error level in extracting I-cache data from a Cortex-A53, and a remarkable 93% accuracy from the D-cache of a Cortex-A72 without any post-processing.

Thirdly, a critical finding is the security attribute agnosticism of the attack. The research unequivocally shows that whether a cache line or SRAM block belongs to the secure world or the normal world is irrelevant to the attack's success. The data is absorbed into the analog layer of the SRAM cell through physical aging, rendering architectural tags meaningless. This implies that any data that resides in SRAM, regardless of its intended security context, is potentially vulnerable to this type of physical attack.

Finally, the research successfully addressed the complex technical challenges required to execute such an attack:

  • Overdriving SRAM power: The ability to overvolt specific SRAM memory blocks to induce accelerated aging.
  • Software interface for reading SRAM state: Exploiting ARM's co-processor interfaces and cache maintenance instructions to read the power-on state of SRAM cells.
  • Preventing CPU initialization: Developing methods to stop the CPU from initializing SRAM or caches before the attacker can read their raw power-on state, thus preserving the aging-induced biases.

These findings collectively present a paradigm shift, moving the focus from purely architectural security to the underlying physical properties of the hardware itself.

Technical Deep Dive

▶ Watch: Overcoming technical challenges to accelerate SRAM aging (6:00)

The technical foundation of UnTrustZone lies in manipulating the physical characteristics of SRAM cells through accelerated aging. An SRAM cell is a bistable circuit, typically comprising two cross-coupled inverters. During power-on, a race condition occurs between these inverters, causing the cell to settle randomly into either a logic '0' or a logic '1'. This randomness is due to manufacturing variations and thermal noise.

The core of the attack exploits transistor aging, specifically Negative Bias Temperature Instability (NBTI). When a P-MOS transistor is subjected to a negative gate-source voltage (i.e., it's turned 'on') and elevated temperature, a degradation mechanism occurs. Over time, charges accumulate at the gate oxide interface, increasing the transistor's threshold voltage and decreasing its drive current. In an SRAM cell, if a logic '1' is stored for an extended period, the P-MOS transistor (P1) in the inverter holding that '1' will be consistently 'on'. This prolonged stress causes P1 to slow down relative to the other transistors in the cell. When the cell subsequently powers on, this differential aging biases the race condition, making the cell more likely to settle into the state it previously held. This is the mechanism of data "burning in" to the analog layer of the silicon.

Natural aging, however, is too slow to be a practical attack vector. UnTrustZone accelerates this process by exploiting the known dependencies of NBTI on electric field strength and temperature. The rate of NBTI degradation is exponentially dependent on the vertical electric field across the gate oxide (which is directly proportional to the supply voltage) and also significantly increases with temperature. By exposing an SRAM block to elevated voltage (overvolting) and elevated temperature, the researchers compress years of aging into a short, actionable timeframe. This "baking" process quickly imprints the stored data into the physical characteristics of the SRAM cells.

To execute this attack on an ARM TrustZone-enabled device, the researchers had to overcome three critical technical challenges:

  1. Overdriving SRAM's Power Bus: The first challenge was to induce accelerated aging by overvolting specific SRAM memory blocks. This required manipulating the device's power supply mechanisms to selectively increase the voltage delivered to the target SRAM. The presentation shows a custom board for power management, indicating a hardware-level intervention to achieve this. By providing a higher-than-nominal voltage, the electric field across the transistor gates is increased, significantly accelerating the aging process.
  1. Reading SRAM State from Software Interface: After the accelerated aging, the attacker needs to read the raw power-on state of the SRAM cells before any software initialization corrupts this information. The researchers achieved this by exploiting ARM's co-processor interfaces and cache maintenance instructions. These low-level instructions provide a means to interact directly with the cache and memory system, allowing for inspection of the physical state of SRAM cells. This bypasses the normal architectural abstractions that would prevent direct access to raw memory states.
  1. Stopping CPU Initialization: A crucial step is to prevent the CPU or any system software from initializing the SRAM or cache lines before the attacker can read their power-on state. Typically, operating systems or bootloaders will write zeros or other patterns to memory upon startup to ensure a clean slate, which would erase the aging-induced data remnants. The UnTrustZone methodology involved disabling all cache writes immediately after the CPU releases control to external software. In more complex scenarios, such as the Cortex-A processor attacks, a "fake kernel" was introduced. This fake kernel's role was to stop the CPUs from initializing the cache lines by keeping them in an invalid state after boot. Subsequently, upon an external request, this fake kernel would dump the "invalid" (but physically biased) cache lines, representing the SRAM power-on state, to system RAM for further processing. This ensures that the physical biases from accelerated aging are preserved and readable.

The overarching threat model for UnTrustZone assumes an attacker has physical access to an ARM device with TrustZone enforced. Furthermore, it assumes that the victim device is configured to erase all security and privacy-critical data upon unauthorized access (e.g., through a secure boot or memory scrubbing routine). The attack demonstrates that even under these strong defensive assumptions, physical manipulation at the device layer can lead to secret exfiltration.

Demo / Proof of Concept

▶ Watch: Threat model and experimental setup overview (7:00)

The researchers conducted an extensive proof-of-concept demonstration, testing the UnTrustZone attack on a wide array of devices and scenarios. Their test system comprised a custom board for precise power management and to direct the target device into specific operational states. The setup allowed for controlled application of elevated voltage and temperature to accelerate the aging process. The attack was validated on more than a dozen devices from half a dozen manufacturers, encompassing a broad spectrum of ARM architectures, from small microcontrollers to full-fledged Cortex-A profile processors.

Three main attack scenarios, increasing in complexity, were presented:

  1. Exfiltrating Crypto Assets (AES Key):
  • Scenario: A normal world application requests cryptographic support (e.g., an AES key) from a secure world function, which is protected by TrustZone. Architecturally, the non-secure application should never receive any information about this key from the secure area.
  • Execution: The device was exposed to accelerated aging while the AES key was resident in SRAM. Subsequently, the entire chip was erased, simulating a secure wipe.
  • Result: UnTrustZone was able to exfiltrate the AES key from the secure area by analyzing the power-on states of the aged SRAM cells. This demonstrated a direct bypass of TrustZone's isolation for critical cryptographic material.
  1. Exfiltrating Proprietary Firmware from On-chip SRAM:
  • Scenario: This model was inspired by a 2016 Oakland paper that proposed executing sensitive software directly from on-chip SRAM instead of off-chip DRAM for enhanced security. The proprietary firmware is protected by TrustZone.
  • Execution: The device, running proprietary firmware from its on-chip SRAM, was subjected to accelerated aging.
  • Result: UnTrustZone successfully exfiltrated this proprietary firmware at close to 90% accuracy from individual devices. The accuracy significantly increased when data from multiple devices running the same firmware version was combined, indicating a robust and repeatable attack. This highlights a critical vulnerability for intellectual property and embedded system security.
  1. Complex Systems with Cache Access (Cortex-A Processors):
  • Scenario: This scenario focused on more complex systems where caches (which are SRAM-based) play a crucial role. A victim software runs from the cache of a multi-core Cortex-A53 processor (from Broadcom).
  • Execution: The device was exposed to accelerated aging. The attack's strength here is its security attribute agnosticism: the attack does not care whether a cache line belongs to the secure world or the normal world because the information is absorbed into the analog layer of the SRAM. A "fake kernel" was introduced to read the cache lines. This kernel prevented the CPUs from initializing the cache lines by keeping them invalid after boot. Once requested externally, it dumped these "invalid" (but aging-biased) cache lines (representing the power-on state of the SRAM) to system RAM for analysis.
  • Result (Cortex-A53): The researchers were able to extract I-cache data with a 20% error level, demonstrating feasibility even with system-level noise and cache complexities.
  • Unifying Attack Scenario (Cortex-A72): To further solidify the findings, a proof-of-concept victim software was developed that ran entirely from cache and executed AES encryption without using any external RAM. This was tested on another Broadcom device, a quad-core Cortex-A72.
  • Result (Cortex-A72): After accelerated aging, the researchers were able to exfiltrate 93% of the data from the D-cache on average for all four cores, without even requiring post-processing. This exceptionally high accuracy, even in a highly complex multi-core cache environment, dramatically underscores that if data resides in the cache, its architectural security attribute is irrelevant against this device-level attack. The data is physically burned into the analog layer, making it extremely difficult to mitigate without explicit defenses targeting this type of long-term data remanence.

Defensive Implications

▶ Watch: Demonstration: High-accuracy proprietary firmware exfiltration (8:40)

The UnTrustZone attack highlights a significant gap in current hardware security practices, demanding a re-evaluation of how on-chip secrets are protected. Architectural barriers alone are insufficient against device-level attacks that exploit physical phenomena like transistor aging. The researchers proposed several potential mitigation strategies, categorized by their approach:

  1. SRAM State Initialization:
  • Hardware-level Initialization: The most direct mitigation is to ensure that SRAM states are explicitly initialized by hardware upon power-on or before any secure operation. Currently, this is often not done comprehensively, relying on the inherent randomness of SRAM power-on. Implementing hardware-enforced initialization would directly counteract the aging-induced biases by forcing all cells to a known state (e.g., all zeros or a pseudo-random pattern) before any software can access them.
  • Software Mitigation: While software could theoretically initialize SRAM, this poses significant challenges. SRAM blocks can be quite large, and iterating through every byte or word to initialize them would introduce a substantial performance penalty, significantly increasing boot times or context switch latencies. This trade-off often makes software-only initialization impractical for large on-chip memories.
  • Built-in Self-Test (BIST) Engine: A more robust hardware-based solution involves utilizing an internal Built-in Self-Test (BIST) engine. BIST engines are typically used for memory testing but could be repurposed or enhanced to initialize SRAM states in a secure, hardware-controlled manner. This would make the power-on state entirely inaccessible from software, effectively eliminating the attack vector by ensuring a clean, unbiased state every time.
  1. Data Scrambling and Complementing at Runtime:
  • Principle: This mitigation aims to prevent the "burning effect" by ensuring that individual SRAM cells do not consistently store the same logic state for prolonged periods. By scrambling or complementing data at runtime, the average time a cell spends storing a '1' versus a '0' is balanced. This helps to equalize the device wear-out (aging) across the P-MOS and N-MOS transistors within the cell, preventing a significant bias from developing.
  • Limitations: This method has limitations, particularly when facing an attacker capable of overvolting the core. If the core voltage is driven significantly high, it can freeze software execution. In such extreme conditions, runtime scrambling mechanisms, which rely on active software or hardware logic, would cease to function, leaving the data vulnerable to burn-in. As the UnTrustZone attack explicitly involves driving up core voltage, this mitigation is less effective against the presented threat model.
  1. Preventing Aging Acceleration Altogether:
  • Voltage Acceleration Prevention: The most impactful factor in accelerating aging is elevated voltage, which increases the strong vertical electric field across the gate region. Therefore, preventing an attacker from overdriving the core voltage supply rail is a critical defense. This would mean that even if the power-on state remains accessible for legitimate system applications (e.g., as a True Random Number Generator (TRNG) or for counter-detection), the attack would require an impractically long time to manifest.
  • Implementation Difficulty: Implementing robust voltage acceleration prevention is challenging. Due to inherent manufacturing randomness and process variations in semiconductor devices, there must always be some margin in the supply voltage rail. An attacker might exploit this margin to slightly increase the voltage, even if a full overvolt is prevented, still accelerating aging to some extent. The goal would be to shrink this margin as much as possible to make any acceleration negligible.
  • Temperature Acceleration Prevention: While temperature also accelerates aging, its effect is generally much smaller compared to voltage. Preventing temperature acceleration (e.g., through active cooling or thermal monitoring) is possible but would be less effective than preventing voltage manipulation. Therefore, the primary focus for preventing burn-in should be on voltage acceleration prevention.

In summary, effective defenses against UnTrustZone-like attacks require a shift from purely architectural security to a deeper consideration of the physical layer. Hardware-enforced SRAM initialization, ideally via a BIST engine, and stringent prevention of voltage manipulation are the most promising avenues to mitigate this sophisticated class of physical attack.

Key Takeaways

  • Architectural Barriers are Insufficient: Hardware-backed isolation mechanisms like ARM TrustZone, while effective against software-based attacks, are not sufficient to protect on-chip secrets against sophisticated physical attacks that exploit the underlying device layer.
  • Accelerated Aging Enables Rapid Data Remanence: The natural, decades-long process of transistor aging in SRAM can be dramatically accelerated by applying elevated voltage and temperature, creating physical biases that cause cells to preferentially power on to previously stored states.
  • High-Accuracy Exfiltration of On-chip Secrets: UnTrustZone demonstrates the ability to exfiltrate critical data, including AES cryptographic keys, proprietary firmware, and cached data (both I-cache and D-cache), with high accuracy (e.g., 90% for firmware, 93% for D-cache data) from various ARM devices.
  • Security Attribute Agnosticism: The attack is oblivious to architectural security attributes (secure vs. normal world). Once data is physically "burned in" to the analog layer of SRAM cells, its original security tagging becomes irrelevant.
  • Hardware-Level Mitigations are Crucial: Effective defenses require hardware-based solutions such as explicit SRAM initialization (e.g., using a BIST engine) to erase physical biases, or robust mechanisms to prevent an attacker from accelerating aging, particularly through voltage manipulation.
  • New Paradigm for Physical Security: This research necessitates a fundamental re-evaluation of how on-chip memory is secured, shifting focus from purely architectural safeguards to understanding and mitigating vulnerabilities at the silicon's physical layer.

About the Speaker(s)

Jubayer Mahmod is a researcher who presented the UnTrustZone work. He is affiliated with Virginia Tech, where he collaborated on this project. His research focuses on physical security and hardware vulnerabilities.

Matthew Hicks is an advisor and collaborator on the UnTrustZone project. He is also affiliated with Virginia Tech, providing guidance and expertise in the domain of computer architecture and security research.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research introduces a groundbreaking physical attack, UnTrustZone, that leverages systematic accelerated transistor aging in SRAM to bypass hardware-backed security like ARM TrustZone. It demonstrates that on-chip secrets, even after architectural erasure, can be exfiltrated with high accuracy by manipulating the physical properties of memory cells, fundamentally challenging current hardware security assumptions.

Heather Calloway (CISO) — STRONG ACCEPT

This research systematically exposes a fundamental flaw in hardware-backed security, demonstrating that architectural isolation is insufficient against sophisticated physical attacks. It forces a critical re-evaluation of data protection assumptions for on-chip secrets and demands hardware-level accountability from device manufacturers.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024