eMPAC: Unlocking Full Potential of Pointer Authentication in Microcontrollers with Fat Pointers

  1. ESORICS'26
    Sungsoo Kim, Jihoon Kim, Kyuwon Cho, Hojoon Lee
    European Symposium on Research in Computer Security (ESORICS), 2026

Abstract

The Pointer Authentication (PA) extension introduced in ARMv8.3-A has significantly raised the bar for exploiting memory errors with hardware-accelerated pointer integrity. Unfortunately, its adaptation to the M-profile ARM architecture arrived with significantly reduced feature sets. As a result, existing works on PA-based system hardening do not apply to ARM-based MCU systems. In this paper, we present the eMPAC architecture, which extends the M-profile PA with an ABI extension to unlock its full potential. The key idea is to construct a compiler-defined extended architecture that embraces the fat pointer design. We show that the eMPAC architecture enables the existing PA-based security measures developed for A-profile processors to be applied to M-profile processors with moderate overhead.