Device Tree Binary Monitoring via Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT devices are vulnerable to security breaches and lack effective mechanisms for early detection and prevention of cyberattacks, which can lead to unauthorized access and resource utilization.
Innovation Solution
A method and system that store a golden copy of a device tree binary in a trusted execution environment, compare it with a running copy, and perform corrective actions such as quarantining or notifying users if discrepancies are found, using a timer to detect potential attacks and decrypting the device tree binary to monitor hardware components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing prevention techniques are used to authenticate and control IoT devices, then device authentication is improved, but security against cyberattacks is insufficient
Solution Approach 1:
The system performs preliminary actions by creating a golden copy of the device tree binary before runtime and storing it in a trusted execution environment. This pre-established reference is then used to detect attacks during operation, allowing the system to identify unauthorized modifications before they can cause significant harm.
Solution Approach 2:
The trusted execution environment acts as an intermediary between the device tree binary and the rest of the system. It securely stores the golden copy and performs cryptographic comparisons, mediating the security verification process and isolating the sensitive authentication operations from potential attacks.
2Difficulty of detecting and measuring
If device tree binary monitoring is implemented to detect attacks, then attack detection capability is improved, but system complexity increases
Solution Approach 1:
The system creates a copy of the device tree binary (the golden copy) and stores it in a trusted execution environment. This copying approach enables comparison-based detection of unauthorized modifications without requiring complex analysis of the original binary, simplifying the detection mechanism while maintaining effectiveness.
Solution Approach 2:
The security verification functionality is extracted into a separate trusted execution environment, isolating the complex cryptographic operations and golden copy management from the main system. This extraction reduces the complexity burden on the primary system while maintaining robust attack detection capabilities.
3Reliability
If cryptographic verification of device tree binary is performed, then security integrity is improved, but processing time increases
Solution Approach 1:
The golden copy of the device tree binary is prepared and stored in the trusted execution environment before the system enters runtime. This preliminary preparation eliminates the need for time-consuming cryptographic setup during operation, allowing rapid comparison-based verification when attacks need to be detected.
Data Source
AI summary
A method includes storing a golden copy of a device tree binary of a system in a trusted execution environment, identifying whether one or more parameters of a running copy of a device tree binary of the system are different from corresponding parameters of the golden copy by comparing the running copy with the golden copy, and performing a corrective action responsive to an indication that at least one of the one or more parameters of the running copy are different from the corresponding parameters of the golden copy.

