HPCCFA: Leveraging Hardware Performance Counters for Control Flow Attestation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pott, Claudius, Wilke, Luca, Wichelmann, Jan, Eisenbarth, Thomas
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914435289841664
author Pott, Claudius
Wilke, Luca
Wichelmann, Jan
Eisenbarth, Thomas
author_facet Pott, Claudius
Wilke, Luca
Wichelmann, Jan
Eisenbarth, Thomas
contents Trusted Execution Environments (TEEs) allow the secure execution of code on remote systems without the need to trust their operators. They use static attestation as a central mechanism for establishing trust, allowing remote parties to verify that their code is executed unmodified in an isolated environment. However, this form of attestation does not cover runtime attacks, where an attacker exploits vulnerabilities in the software inside the TEE. Control Flow Attestation (CFA), a form of runtime attestation, is designed to detect such attacks. In this work, we present a method to extend TEEs with CFA and discuss how it can prevent exploitation in the event of detected control flow violations. Furthermore, we introduce HPCCFA, a mechanism that uses HPCs for CFA purposes, enabling hardware-backed trace generation on commodity CPUs. We demonstrate the feasibility of HPCCFA on a proof-of-concept implementation for Keystone on RISC-V. Our evaluation investigates the interplay of the number of measurement points and runtime protection, and reveals a trade-off between detection reliability and performance overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2603_29749
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle HPCCFA: Leveraging Hardware Performance Counters for Control Flow Attestation
Pott, Claudius
Wilke, Luca
Wichelmann, Jan
Eisenbarth, Thomas
Cryptography and Security
Trusted Execution Environments (TEEs) allow the secure execution of code on remote systems without the need to trust their operators. They use static attestation as a central mechanism for establishing trust, allowing remote parties to verify that their code is executed unmodified in an isolated environment. However, this form of attestation does not cover runtime attacks, where an attacker exploits vulnerabilities in the software inside the TEE. Control Flow Attestation (CFA), a form of runtime attestation, is designed to detect such attacks. In this work, we present a method to extend TEEs with CFA and discuss how it can prevent exploitation in the event of detected control flow violations. Furthermore, we introduce HPCCFA, a mechanism that uses HPCs for CFA purposes, enabling hardware-backed trace generation on commodity CPUs. We demonstrate the feasibility of HPCCFA on a proof-of-concept implementation for Keystone on RISC-V. Our evaluation investigates the interplay of the number of measurement points and runtime protection, and reveals a trade-off between detection reliability and performance overhead.
title HPCCFA: Leveraging Hardware Performance Counters for Control Flow Attestation
topic Cryptography and Security
url https://arxiv.org/abs/2603.29749