YoVDO

Reflections on Trusting TrustZone

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Trustzone Courses Secure Coding Practices Courses Attack Surface Analysis Courses

Course Description

Overview

Explore the intricacies of TrustZone security in ARM devices through this Black Hat conference talk. Delve into a technical analysis of a major vendor's TrustZone kernel implementation, examining its vulnerabilities and exploitation techniques. Learn about the architecture, real-world applications, and prior work in TrustZone exploitation. Discover a previously undisclosed vulnerability, its exploitation process, and witness a live demonstration of unlocking an Android phone's bootloader. Gain insights into the implications of such vulnerabilities for mobile device security, covering topics like secure boot, DRM key storage, mobile payments, and kernel integrity validation.

Syllabus

Intro
What is TrustZone?
TrustZone Architecture
Real-World Uses
Prior Work
Motivation
Toolchain
Attack Surface
Attacker Assumptions
QSEE SCM Interface
SCM Call-by-Register Convention
SCM Command Structures
Structure Sanity Checking
Secure Memory Checking Pseudocode
Review: Integer Overflow
Integer Overflow Vulnerability
Pathological Command Buffer
What is Written to Response Header?
Sorcery!
Building Better Primitives
Choosing A New Write Primitive
SMC Handler Table
SMC Table Extension Attack
Arbitrary TZ Code Execution
Lessons Learned


Taught by

Black Hat

Related Courses

0-Days and Mitigations - Roadways to Exploit and Secure Connected BMW Cars
Black Hat via YouTube
Ways to Die in Mobile OAuth
Black Hat via YouTube
Ways to Bypass Your macOS Privacy Mechanisms
Black Hat via YouTube
Electronegativity - A Study of Electron Security
Black Hat via YouTube
A Titan M Odyssey
Black Hat via YouTube