Secure Rule Based Scripting in Constrained IoT Actuators: A Micro VM Approach
Abstract
Abstract : Industrial IoT actuators operating in oil refineries, water grids, and micro manufacturing cells often require in field reconfiguration while withstanding hostile networks. Conventional firmware updates incur downtime and pose integrity risks. This paper introduces SentinelVM, a 4 kB micro virtual machine that enforces fine grained policy scripts written in a subset of Lua— Lua Lite—augmented with mandatory access controls and heap safe byte code verification. We detail a formal threat model encompassing flash bribery, script injection, and timing side channel exfiltration. SentinelVM’s type aware sandbox intercepts device driver syscalls, permitting dynamic control policy uploads without root firmware replacement. Benchmarks across twelve STM32F0 based valve controllers show sub millisecond policy evaluation and 0.9?% overhead versus native C logic, while thwarting 100?% of synthetic exploit attempts in a red team exercise. The architecture demonstrates a pragmatic fusion of VM isolation and declarative policy languages to secure critical IoT actuators within their stringent resource envelopes.
Keywords: Micro VM, policy scripting, IoT security, Lua, runtime verification
Full Text:
PDF 44 - 58Refbacks
- There are currently no refbacks.