{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T09:20:26Z","timestamp":1773998426205,"version":"3.50.1"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2020,9,26]],"date-time":"2020-09-26T00:00:00Z","timestamp":1601078400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Serene-IoT Penta"},{"DOI":"10.13039\/501100005304","name":"Agence Nationale de la Recherche","doi-asserted-by":"publisher","award":["ANR-15-IDEX-02"],"award-info":[{"award-number":["ANR-15-IDEX-02"]}],"id":[{"id":"10.13039\/501100005304","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014718","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1615890"],"award-info":[{"award-number":["CNS-1615890"]}],"id":[{"id":"10.13039\/100014718","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2020,9,30]]},"abstract":"<jats:p>This article addresses the challenges of memory safety in life-critical medical devices. Since the last decade, healthcare manufacturers have embraced the Internet of Things, pushing technological innovations to increase market share. Medical devices, including the most critical ones, tend to be increasingly connected to the Internet. Unfortunately, as critical devices often rely on unsafe programming languages such as C, they are no exception to memory safety issues. Given a memory vulnerability, a skillful attacker can take over a system and perform remote code execution. Combined with the fact that medical devices directly impact the safety of their users, a security vulnerability can lead to disastrous scenarios. To address this issue, this article presents TrustFlow-X, a novel hardware\/software co-designed framework that provides efficient fine-grained control-flow integrity protection against memory-based attacks. The TrustFlow-X framework is composed of an LLVM-based compiler toolchain that generates a secure code. This secure code is then executed on an extended RISC-V processor that keeps track of sensitive data using a trusted memory. The obtained results show that the contribution is practical, providing a high level of trust in life-critical embedded systems.<\/jats:p>","DOI":"10.1145\/3398327","type":"journal-article","created":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T12:39:02Z","timestamp":1594125542000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["TrustFlow-X"],"prefix":"10.1145","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3027-0151","authenticated-orcid":false,"given":"Cyril","family":"Bresch","sequence":"first","affiliation":[{"name":"LCIS Grenoble Alpes University, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"H\u00e9ly","sequence":"additional","affiliation":[{"name":"LCIS Grenoble Alpes University, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5000-0848","authenticated-orcid":false,"given":"Roman","family":"Lysecky","sequence":"additional","affiliation":[{"name":"University of Arizona, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"St\u00e9phanie","family":"Chollet","sequence":"additional","affiliation":[{"name":"LCIS Grenoble Alpes University, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ioannis","family":"Parissis","sequence":"additional","affiliation":[{"name":"LCIS Grenoble Alpes University, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,9,26]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MEMCOD.2016.7797764"},{"key":"e_1_2_1_4_1","unstructured":"ARM. 2015. Mbed TLS. Retrieved from https:\/\/tls.mbed.org\/.  ARM. 2015. Mbed TLS. Retrieved from https:\/\/tls.mbed.org\/."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2018.8569579"},{"key":"e_1_2_1_7_1","unstructured":"Alex Bradbury Gavin Ferris and Robert Mullins. 2014. Tagged memory and minion cores in the lowRISC SoC Tagged memory and minion cores in the lowRISC SoC. Retrieved from https:\/\/www.lowrisc.org\/downloads\/lowRISC-memo-2014-001.pdf.  Alex Bradbury Gavin Ferris and Robert Mullins. 2014. Tagged memory and minion cores in the lowRISC SoC Tagged memory and minion cores in the lowRISC SoC. Retrieved from https:\/\/www.lowrisc.org\/downloads\/lowRISC-memo-2014-001.pdf."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIOT.2018.00027"},{"key":"e_1_2_1_9_1","volume-title":"SecPump: A connected open source infusion pump for security research purposes","author":"Bresch Cyril","year":"2020","unstructured":"Cyril Bresch , David Hely , Stephanie Chollet , and Roman Lysecky . 2020. SecPump: A connected open source infusion pump for security research purposes . IEEE Embed. Syst. Lett . 0663, c ( 2020 ), 1--1. DOI:https:\/\/doi.org\/10.1109\/les.2020.2979595 10.1109\/les.2020.2979595 Cyril Bresch, David Hely, Stephanie Chollet, and Roman Lysecky. 2020. SecPump: A connected open source infusion pump for security research purposes. IEEE Embed. Syst. Lett. 0663, c (2020), 1--1. DOI:https:\/\/doi.org\/10.1109\/les.2020.2979595"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2019.00063"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2018.2819983"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/IVSW.2017.8031545"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914)","author":"Carlini Nicholas","year":"2014","unstructured":"Nicholas Carlini , David Wagner , and Nicholas Carlini . 2014 . ROP is still dangerous: Breaking modern defenses ROP is still dangerous: Breaking modern defenses . In Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914) . 385--399. Nicholas Carlini, David Wagner, and Nicholas Carlini. 2014. ROP is still dangerous: Breaking modern defenses ROP is still dangerous: Breaking modern defenses. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914). 385--399."},{"key":"e_1_2_1_14_1","unstructured":"Stephen Cass. 2017. IEEE Spectrum\u2014The 2017 Top Programming Languages. Retrieved from https:\/\/spectrum.ieee.org\/computing\/software\/the-2017-top-programming-languages.  Stephen Cass. 2017. IEEE Spectrum\u2014The 2017 Top Programming Languages. Retrieved from https:\/\/spectrum.ieee.org\/computing\/software\/the-2017-top-programming-languages."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298470"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866370"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857722"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security. 555--566","author":"Thurston H.","unstructured":"Thurston H. Y. Dang and David Wagner. 2015. The performance cost of shadow stacks and stack canaries time of check to time of use . In Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security. 555--566 . Thurston H. Y. Dang and David Wagner. 2015. The performance cost of shadow stacks and stack canaries time of check to time of use. In Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security. 555--566."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2744847"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.23919\/DATE.2019.8714980"},{"key":"e_1_2_1_21_1","volume-title":"Exploring CoreMark\u2014A benchmark maximizing simplicity and efficacy","author":"Markus Levy Shay","unstructured":"Shay Gal-on and Markus Levy . 2012. Exploring CoreMark\u2014A benchmark maximizing simplicity and efficacy . The Embedded Microprocessor Benchmark Consortium (EEMBC\u2019 12). Retrieved from www.eembc.org. Shay Gal-on and Markus Levy. 2012. Exploring CoreMark\u2014A benchmark maximizing simplicity and efficacy. The Embedded Microprocessor Benchmark Consortium (EEMBC\u201912). Retrieved from www.eembc.org."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1186736.1186737"},{"key":"e_1_2_1_23_1","first-page":"89","article-title":"The power of ten\u2014Rules for developing safety-critical code","volume":"42","author":"Holzmann Gerard J.","year":"2007","unstructured":"Gerard J. Holzmann . 2007 . The power of ten\u2014Rules for developing safety-critical code . ACM SIGPLAN Not. 42 , 6 (2007), 89 -- 100 . Gerard J. Holzmann. 2007. The power of ten\u2014Rules for developing safety-critical code. ACM SIGPLAN Not. 42, 6 (2007), 89--100.","journal-title":"ACM SIGPLAN Not."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2012.269"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/977395.977673"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2849859"},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 48--62","author":"Mathias Szekeres","year":"2013","unstructured":"Szekeres Mathias , Payer Tao , and Wei Dawn . 2013 . SoK: Eternal war in memory . In Proceedings of the IEEE Symposium on Security and Privacy. 48--62 . Szekeres Mathias, Payer Tao, and Wei Dawn. 2013. SoK: Eternal war in memory. In Proceedings of the IEEE Symposium on Security and Privacy. 48--62."},{"key":"e_1_2_1_30_1","unstructured":"McAfee. 2016. 2017 Threats Predictions. Technical Report. Retrieved from https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-threats-predictions-2017.pdf.  McAfee. 2016. 2017 Threats Predictions. Technical Report. Retrieved from https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-threats-predictions-2017.pdf."},{"key":"e_1_2_1_31_1","volume-title":"Hardware and Architectural Support for Security and Privacy","author":"Menon Arjun","unstructured":"Arjun Menon , Subadra Murugan , Chester Rebeiro , Neel Gala , and Kamakoti Veezhinathan . 2017. Shakti-T: A RISC-V processor with light weight security extensions Shakti-T: A RISC-V processor with light weight security extensions . In Hardware and Architectural Support for Security and Privacy . ACM , New York, NY . DOI:https:\/\/doi.org\/10.1145\/3092627.3092629 10.1145\/3092627.3092629 Arjun Menon, Subadra Murugan, Chester Rebeiro, Neel Gala, and Kamakoti Veezhinathan. 2017. Shakti-T: A RISC-V processor with light weight security extensions Shakti-T: A RISC-V processor with light weight security extensions. In Hardware and Architectural Support for Security and Privacy. ACM, New York, NY. DOI:https:\/\/doi.org\/10.1145\/3092627.3092629"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250746"},{"key":"e_1_2_1_34_1","unstructured":"NSA. 2015. Hardware Control Flow Integrity for an IT Ecosystem. Retrieved from https:\/\/github.com\/iadgov\/Control-Flow-Integrity\/ tree\/master\/paper.  NSA. 2015. Hardware Control Flow Integrity for an IT Ecosystem. Retrieved from https:\/\/github.com\/iadgov\/Control-Flow-Integrity\/ tree\/master\/paper."},{"key":"e_1_2_1_35_1","volume-title":"Intel MPX explained. arXiv preprint arXiv:1702.00719","author":"Oleksenko Oleksii","year":"2017","unstructured":"Oleksii Oleksenko and Dmitrii Kuvaiskii . 2017. Intel MPX explained. arXiv preprint arXiv:1702.00719 ( 2017 ). Oleksii Oleksenko and Dmitrii Kuvaiskii. 2017. Intel MPX explained. arXiv preprint arXiv:1702.00719 (2017)."},{"key":"e_1_2_1_36_1","volume-title":"Smashing the stack for fun and profit. Phrack 49","author":"One Aleph","year":"1996","unstructured":"Aleph One . 1996. Smashing the stack for fun and profit. Phrack 49 ( 1996 ). Aleph One. 1996. Smashing the stack for fun and profit. Phrack 49 (1996)."},{"key":"e_1_2_1_37_1","unstructured":"Qualcomm Security. 2017. Pointer Authentication on ARMv8. Retrieved from https:\/\/www.qualcomm.com\/media\/documents\/files\/whitepaper-pointer-authentication-on-armv8-3.pdf.  Qualcomm Security. 2017. Pointer Authentication on ARMv8. Retrieved from https:\/\/www.qualcomm.com\/media\/documents\/files\/whitepaper-pointer-authentication-on-armv8-3.pdf."},{"key":"e_1_2_1_38_1","unstructured":"UC Berkeley Architecture Research. 2015. The RISC-V Instruction Set Architecture. Retrieved from http:\/\/riscv.org\/.  UC Berkeley Architecture Research. 2015. The RISC-V Instruction Set Architecture. Retrieved from http:\/\/riscv.org\/."},{"key":"e_1_2_1_39_1","unstructured":"Gayou Scott. 2017. Remote Code Execution on the Smiths Medical Medfusion 4000. Retrieved from https:\/\/github.com\/sgayou\/medfusion-4000-research\/blob\/master\/doc\/README.md.  Gayou Scott. 2017. Remote Code Execution on the Smiths Medical Medfusion 4000. Retrieved from https:\/\/github.com\/sgayou\/medfusion-4000-research\/blob\/master\/doc\/README.md."},{"key":"e_1_2_1_40_1","volume-title":"Hospira Multiple Products Buffer Overflow Vulnerability.","author":"Department of Homeland Security. 2016.","unstructured":"Department of Homeland Security. 2016. Hospira Multiple Products Buffer Overflow Vulnerability. Retrieved from https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-15-337-02. Department of Homeland Security. 2016. Hospira Multiple Products Buffer Overflow Vulnerability. Retrieved from https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-15-337-02."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.45"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.9"},{"key":"e_1_2_1_43_1","unstructured":"Shirley Tay. 2019. A serious shortage of cybersecurity experts could cost companies hundreds of millions of dollars. CNBC. Retrieved from https:\/\/www.cnbc.com\/2019\/03\/06\/cybersecurity-expert-shortage-may-cost-companies-hundreds-of-millions.html.  Shirley Tay. 2019. A serious shortage of cybersecurity experts could cost companies hundreds of millions of dollars. CNBC. Retrieved from https:\/\/www.cnbc.com\/2019\/03\/06\/cybersecurity-expert-shortage-may-cost-companies-hundreds-of-millions.html."},{"key":"e_1_2_1_44_1","volume-title":"Proceedings of the GCC Developers Summit. 243--255","author":"Wagle Perry","year":"2003","unstructured":"Perry Wagle and Crispin Cowa . 2003 . Stackguard: Simple stack smash protection for GCC . In Proceedings of the GCC Developers Summit. 243--255 . Perry Wagle and Crispin Cowa. 2003. Stackguard: Simple stack smash protection for GCC. In Proceedings of the GCC Developers Summit. 243--255."},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the Usenix Enigma Conference. DOI:https:\/\/doi.org\/10","author":"Wetzels Jos","year":"2017","unstructured":"Jos Wetzels and Ali Abbasi . 2017 . Ghost in the machine . In Proceedings of the Usenix Enigma Conference. DOI:https:\/\/doi.org\/10 .1038\/482562a. 10.1038\/482562a Jos Wetzels and Ali Abbasi. 2017. Ghost in the machine. In Proceedings of the Usenix Enigma Conference. DOI:https:\/\/doi.org\/10.1038\/482562a."},{"key":"#cr-split#-e_1_2_1_46_1.1","doi-asserted-by":"crossref","unstructured":"B. Wijnen E. J. Hunt G. C. Anzalone and J. M. Pearce. 2014. Open-source syringe pump library. PLoS ONE 9 9 (2014). DOI:https:\/\/doi.org\/10.1371\/journal.pone.0107216. 10.1371\/journal.pone.0107216","DOI":"10.1371\/journal.pone.0107216"},{"key":"#cr-split#-e_1_2_1_46_1.2","doi-asserted-by":"crossref","unstructured":"B. Wijnen E. J. Hunt G. C. Anzalone and J. M. Pearce. 2014. Open-source syringe pump library. PLoS ONE 9 9 (2014). DOI:https:\/\/doi.org\/10.1371\/journal.pone.0107216.","DOI":"10.1371\/journal.pone.0107216"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 27th Annual Computer Security Applications Conference. ACM, 41--50","author":"Wilander John","unstructured":"John Wilander , Nick Nikiforakis , Yves Youan , Mariam Kamkar , and Wouter Joosen .2011. RIPE : Runtime intrusion prevention evaluator . In Proceedings of the 27th Annual Computer Security Applications Conference. ACM, 41--50 . John Wilander, Nick Nikiforakis, Yves Youan, Mariam Kamkar, and Wouter Joosen.2011. RIPE: Runtime intrusion prevention evaluator. In Proceedings of the 27th Annual Computer Security Applications Conference. ACM, 41--50."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3398327","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3398327","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:53Z","timestamp":1750199933000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3398327"}},"subtitle":["A Practical Framework for Fine-grained Control-flow Integrity in Critical Systems"],"short-title":[],"issued":{"date-parts":[[2020,9,26]]},"references-count":46,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2020,9,30]]}},"alternative-id":["10.1145\/3398327"],"URL":"https:\/\/doi.org\/10.1145\/3398327","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,26]]},"assertion":[{"value":"2019-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}