In the last two decades, the computing landscape has undergone a significant transformation. The proliferation of connected devices in critical domains such as automotive, defense, and industrial networks has created an urgent demand for secure computing solutions in resource-constrained embedded systems. Historically, security relied on the Operating System (OS) and hardware features like the Memory Management Unit (MMU) to guarantee isolation. However, embedded systems were largely left behind by this paradigm, often lacking the expensive hardware resources required for virtualization while simultaneously becoming primary targets for network-based attacks. Existing solutions either rely on custom hardware extensions (e.g., ARM TrustZone) or lack the determinism required for soft real-time applications. This thesis presents RTEE (Real-Time Trusted Execution Environment), a lightweight, software-partitioned security framework designed for constrained RISC-V devices. RTEE leverages native architectural features such as Machine-mode (M-mode) and the Physical Memory Protection (PMP) unit to enforce strict spatial and temporal isolation without the need for an MMU. The system is built around a Real-Time Security Monitor (RTSM) that manages the enclave lifecycle and enforces timer-based preemption, ensuring that secure enclaves cannot monopolize CPU resources. The solution was implemented and validated on both QEMU and VexRiscv FPGA hardware, demonstrating successful integration with FreeRTOS and Zephyr. Experimental results confirm that RTEE effectively blocks unauthorized memory access and maintains deterministic behavior, providing a viable path for securing critical embedded systems without relying on custom silicon.

Negli ultimi due decenni, il panorama informatico ha subito una trasformazione significativa. La proliferazione di dispositivi connessi in domini critici come l'automotive, la difesa e l'industria ha creato una domanda urgente di soluzioni informatiche sicure per sistemi embedded con risorse limitate. Storicamente, la sicurezza si è affidata al Sistema Operativo (OS) e a funzionalità hardware come la Memory Management Unit (MMU) per garantire l'isolamento. Tuttavia, i sistemi embedded sono stati in gran parte lasciati indietro da questo paradigma, mancando spesso delle costose risorse hardware richieste per la virtualizzazione, pur diventando contemporaneamente bersagli per attacchi informatici. Le soluzioni esistenti si affidano spesso a estensioni hardware personalizzate (es. ARM TrustZone) o mancano delle caratteristiche di determinismo richiesto per le applicazioni soft real-time. Questa tesi presenta RTEE (Real-Time Trusted Execution Environment), un framework di sicurezza leggero software-based, progettato per dispositivi embedded basati su RISC-V. RTEE sfrutta le funzionalità architetturali native come la Machine-mode (M-mode) e la Physical Memory Protection (PMP) per imporre un rigoroso isolamento spaziale e temporale senza la necessità di una MMU. Il sistema è costruito attorno a un Real-Time Security Monitor (RTSM) che gestisce il ciclo di vita delle enclave e impone la preemption basata su timer, assicurando che le enclave non possano monopolizzare le risorse della CPU. La soluzione è stata implementata e validata sia su QEMU che su FPGA VexRiscv, dimostrando un'integrazione efficace con FreeRTOS e Zephyr. I risultati sperimentali confermano che RTEE blocca efficacemente l'accesso non autorizzato alla memoria e mantiene un comportamento deterministico, fornendo un percorso praticabile per la messa in sicurezza di sistemi embedded critici senza affidarsi a hardware proprietario.

A lightweight, soft real-time trusted execution environment for constrained RISC-V systems

Fullin, Edoardo
2024/2025

Abstract

In the last two decades, the computing landscape has undergone a significant transformation. The proliferation of connected devices in critical domains such as automotive, defense, and industrial networks has created an urgent demand for secure computing solutions in resource-constrained embedded systems. Historically, security relied on the Operating System (OS) and hardware features like the Memory Management Unit (MMU) to guarantee isolation. However, embedded systems were largely left behind by this paradigm, often lacking the expensive hardware resources required for virtualization while simultaneously becoming primary targets for network-based attacks. Existing solutions either rely on custom hardware extensions (e.g., ARM TrustZone) or lack the determinism required for soft real-time applications. This thesis presents RTEE (Real-Time Trusted Execution Environment), a lightweight, software-partitioned security framework designed for constrained RISC-V devices. RTEE leverages native architectural features such as Machine-mode (M-mode) and the Physical Memory Protection (PMP) unit to enforce strict spatial and temporal isolation without the need for an MMU. The system is built around a Real-Time Security Monitor (RTSM) that manages the enclave lifecycle and enforces timer-based preemption, ensuring that secure enclaves cannot monopolize CPU resources. The solution was implemented and validated on both QEMU and VexRiscv FPGA hardware, demonstrating successful integration with FreeRTOS and Zephyr. Experimental results confirm that RTEE effectively blocks unauthorized memory access and maintains deterministic behavior, providing a viable path for securing critical embedded systems without relying on custom silicon.
ING - Scuola di Ingegneria Industriale e dell'Informazione
26-mar-2026
2024/2025
Negli ultimi due decenni, il panorama informatico ha subito una trasformazione significativa. La proliferazione di dispositivi connessi in domini critici come l'automotive, la difesa e l'industria ha creato una domanda urgente di soluzioni informatiche sicure per sistemi embedded con risorse limitate. Storicamente, la sicurezza si è affidata al Sistema Operativo (OS) e a funzionalità hardware come la Memory Management Unit (MMU) per garantire l'isolamento. Tuttavia, i sistemi embedded sono stati in gran parte lasciati indietro da questo paradigma, mancando spesso delle costose risorse hardware richieste per la virtualizzazione, pur diventando contemporaneamente bersagli per attacchi informatici. Le soluzioni esistenti si affidano spesso a estensioni hardware personalizzate (es. ARM TrustZone) o mancano delle caratteristiche di determinismo richiesto per le applicazioni soft real-time. Questa tesi presenta RTEE (Real-Time Trusted Execution Environment), un framework di sicurezza leggero software-based, progettato per dispositivi embedded basati su RISC-V. RTEE sfrutta le funzionalità architetturali native come la Machine-mode (M-mode) e la Physical Memory Protection (PMP) per imporre un rigoroso isolamento spaziale e temporale senza la necessità di una MMU. Il sistema è costruito attorno a un Real-Time Security Monitor (RTSM) che gestisce il ciclo di vita delle enclave e impone la preemption basata su timer, assicurando che le enclave non possano monopolizzare le risorse della CPU. La soluzione è stata implementata e validata sia su QEMU che su FPGA VexRiscv, dimostrando un'integrazione efficace con FreeRTOS e Zephyr. I risultati sperimentali confermano che RTEE blocca efficacemente l'accesso non autorizzato alla memoria e mantiene un comportamento deterministico, fornendo un percorso praticabile per la messa in sicurezza di sistemi embedded critici senza affidarsi a hardware proprietario.
File allegati
File Dimensione Formato  
2026_03_Fullin.pdf

solo utenti autorizzati a partire dal 22/02/2027

Descrizione: Tesi Fullin
Dimensione 3.53 MB
Formato Adobe PDF
3.53 MB Adobe PDF   Visualizza/Apri
2026_03_Fullin_Executive Summary.pdf

solo utenti autorizzati a partire dal 22/02/2027

Descrizione: Executive Summary Fullin
Dimensione 387.77 kB
Formato Adobe PDF
387.77 kB Adobe PDF   Visualizza/Apri

I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10589/252442