eMPAC: Unlocking Full Potential of Pointer Authentication in Microcontrollers with Fat Pointers
- ESORICS'26European Symposium on Research in Computer Security (ESORICS), 2026
Abstract
The Pointer Authentication (PA) extension introduced in ARMv8.3-A has significantly raised the bar for exploiting memory errors with hardware-accelerated pointer integrity. Unfortunately, its adaptation to the M-profile ARM architecture arrived with significantly reduced feature sets. As a result, existing works on PA-based system hardening do not apply to ARM-based MCU systems. In this paper, we present the eMPAC architecture, which extends the M-profile PA with an ABI extension to unlock its full potential. The key idea is to construct a compiler-defined extended architecture that embraces the fat pointer design. We show that the eMPAC architecture enables the existing PA-based security measures developed for A-profile processors to be applied to M-profile processors with moderate overhead.