Pointer Authentication

Also known as:PAC

Pointer Authentication: ARM hardware feature that cryptographically signs pointers to detect tampered jump targets. PAC raises the cost of ROPReturn-Oriented ProgrammingExploit technique that chains existing code fragments instead of injecting new code. chains by protecting the integrity of code and data pointers.

How it works and where it fits

From ARMv8.3 onward, instructions sign a pointer with a device-internal key and a modifier (pacia) and verify it again before use (autia). Because 64-bit pointers do not use all their bits, the short authentication code is stored in the unused upper bits. The modifier carries context — a stack address or a type identifier, for example — and thereby binds the signature to a particular location. A failed check raises a fault instead of taking the jump.

Practical security relevance

PAC’s security rests on two assumptions that frequently break in practice. A constant modifier makes every signature valid everywhere and removes the context binding. And a signing oracle — an interface that signs unvalidated values — hands the attacker valid signatures without any key ever leaving the chip. PAC also only protects the checked register value: if a pointer is reloaded from memory after verification, a race conditionRace ConditionError where the result depends on the timing or sequence of parallel processes. remains exploitable.

  • Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.
  • Return-Oriented ProgrammingReturn-Oriented ProgrammingExploit technique that chains existing code fragments instead of injecting new code.: Exploit technique that chains existing code fragments instead of injecting new code.
  • HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.
  • Digital SignatureDigital SignatureCryptographic proof of the authenticity and integrity of digital data.: Cryptographic proof of the authenticity and integrity of digital data.