Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ta: add warning about TA parameter checking
Fixes potential future security vulnerabilites by highlighting the importance of verifying expected parameter types in Trusted Applications, as discussed in the GlobalConfusion paper [1] by Marcel Busch et al. Note that a proposed fix (and a proof of concept using OP-TEE) is suggested in the same paper, which involves requiring TA writers to register expected function parameters. However, this change has not yet been added to any GlobalPlatform specifications (there is a discussion ongoing). Link: [1] https://hexhive.epfl.ch/publications/files/24SEC4.pdf Signed-off-by: Joakim Bech <[email protected]> Reviewed-by: Etienne Carriere <[email protected]>
- Loading branch information