{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:24:15Z","timestamp":1750307055816,"version":"3.41.0"},"reference-count":29,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,9,1]],"date-time":"2012-09-01T00:00:00Z","timestamp":1346457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0720110"],"award-info":[{"award-number":["CNS-0720110"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2012,9]]},"abstract":"<jats:p>Many information security attacks exploit vulnerabilities in \u201ctrusted\u201d and privileged software executing on the system, such as the operating system (OS). On the other hand, most security mechanisms provide no immunity to security-critical user applications if vulnerabilities are present in the underlying OS. While technologies have been proposed that facilitate isolation of security-critical software, they require either significant computational resources and are hence not applicable to many resource-constrained embedded systems, or necessitate extensive redesign of the underlying processors and hardware.<\/jats:p>\n          <jats:p>In this work, we propose INVISIOS: a lightweight, minimally intrusive hardware-software architecture to make the execution of security-critical software invisible to the OS, and hence protected from its vulnerabilities. The INVISIOS software architecture encapsulates the security-critical software into a self-contained software module. While this module is part of the kernel and is run with kernel-level privileges, its code, data, and execution are transparent to and protected from the rest of the kernel. The INVISIOS hardware architecture consists of simple add-on hardware components that are responsible for bootstrapping the secure core, ensuring that it is exercised by applications in only permitted ways, and enforcing the isolation of its code and data. We implemented INVISIOS by enhancing a full-system emulator and Linux to model the proposed software and hardware enhancements, and applied it to protect a commercial cryptographic library. Our experiments demonstrate that INVISIOS is capable of facilitating secure execution at very small overheads, making it suitable for resource-constrained embedded systems and systems-on-chip.<\/jats:p>","DOI":"10.1145\/2345770.2345772","type":"journal-article","created":{"date-parts":[[2012,10,2]],"date-time":"2012-10-02T13:50:00Z","timestamp":1349185800000},"page":"1-20","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["INVISIOS"],"prefix":"10.1145","volume":"11","author":[{"given":"Divya","family":"Arora","sequence":"first","affiliation":[{"name":"Intel Corporation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Najwa","family":"Aaraj","sequence":"additional","affiliation":[{"name":"Booz Allen Hamilton"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anand","family":"Raghunathan","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niraj K.","family":"Jha","sequence":"additional","affiliation":[{"name":"Princeton University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,9]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_4"},{"key":"e_1_2_1_2_1","unstructured":"ARM. 2004. ARM TrustZone technology overview. http:\/\/www.arm.com\/products\/processors\/technologies\/trustzone.php. ARM. 2004. ARM TrustZone technology overview. http:\/\/www.arm.com\/products\/processors\/technologies\/trustzone.php."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/DATE.2005.266"},{"volume-title":"Proceedings of the IEEE International Conference on E-Commerce. 111--119","author":"Atallah M. J.","key":"e_1_2_1_4_1"},{"volume-title":"Proceedings of the USENIX Security Symposium. 57--72","author":"Brumley D.","key":"e_1_2_1_5_1"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1181309.1181316"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346284"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1086297.1086308"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.955100"},{"key":"e_1_2_1_10_1","unstructured":"FIPS186. Federal information processing standards publication 186-2. FIPS186. Federal information processing standards publication 186-2."},{"volume-title":"Computer Architecture: A Quantitative Approach. Morgan Kaufmann, 445--447.","year":"2003","author":"Hennessy J.","key":"e_1_2_1_11_1"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/605397.605409"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.14"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/378993.379237"},{"volume-title":"May","year":"2006","key":"e_1_2_1_15_1"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.27"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352592.1352625"},{"volume-title":"Proceedings of the International Conference on Information Technology: Research and Education. 243--250","author":"McGregor J. P.","key":"e_1_2_1_18_1"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium. 181--195","author":"Newsome J.","key":"e_1_2_1_19_1"},{"volume-title":"Proceedings of the Conference on Design, Automation and Test in Europe. 18--23","author":"Potlapally N. R.","key":"e_1_2_1_20_1"},{"key":"e_1_2_1_21_1","unstructured":"QEMU. QEMU open source processor emulator. http:\/\/wiki.qemu.org\/MainPage. QEMU. QEMU open source processor emulator. http:\/\/wiki.qemu.org\/MainPage."},{"volume-title":"Proceedings of the USENIX Security Symposium. 223--238","author":"Sailer R.","key":"e_1_2_1_22_1"},{"volume-title":"Applied Cryptography: Protocols, Algorithms and Source Code in C","year":"1996","author":"Schneier B.","key":"e_1_2_1_23_1"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/324119.324128"},{"volume-title":"Cryptography and Network Security: Principles and Practice","author":"Stallings W.","key":"e_1_2_1_25_1"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/782814.782838"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation. 279--292","author":"Ta-Min R.","key":"e_1_2_1_28_1"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1086297.1086305"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2345770.2345772","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2345770.2345772","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:21:11Z","timestamp":1750238471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2345770.2345772"}},"subtitle":["A Lightweight, Minimally Intrusive Secure Execution Environment"],"short-title":[],"issued":{"date-parts":[[2012,9]]},"references-count":29,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,9]]}},"alternative-id":["10.1145\/2345770.2345772"],"URL":"https:\/\/doi.org\/10.1145\/2345770.2345772","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2012,9]]},"assertion":[{"value":"2009-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-09-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}