Score
Designs, builds, and evaluates implementations of Trusted Execution Environments (TEEs), including the hardware and software components that create isolated secure execution contexts and enforce memory, resource, and privilege separation. Implements and analyzes attestation and key-provisioning mechanisms, secure boot and lifecycle management, enclave runtimes and APIs, and mitigations against software and side‑channel attacks and host integration issues.
Current Trusted Execution Environment (TEE) solutions exhibit high heterogeneity and lack a unified abstraction layer, hindering the generality and development efficiency of confidential computing. Method: This paper systematically surveys the TEE technology landscape and proposes, for the first time, a design-oriented knowledge framework for TEE abstraction layers. Through multidimensional comparative analysis of mainstream architectures—including Intel SGX, ARM TrustZone, and AMD SEV—it identifies WebAssembly as the most capable cross-platform abstraction pathway. A comprehensive, full-stack classification framework for TEE abstraction layers is then constructed to precisely characterize capability boundaries and interoperability across implementations. Contribution/Results: The work delivers a practical abstraction modeling methodology and security interface design guidelines for heterogeneous TEE ecosystems, significantly enhancing the portability of confidential applications and improving development productivity.
AMD SEV lacks formal verification of its core security properties, including confidentiality, integrity, and availability. This work presents the first systematic formal framework for rigorously verifying these critical security attributes by introducing design-level and property-level abstractions of the SEV architecture, combined with formal modeling and model checking techniques. By establishing a mathematically grounded analysis of SEV’s security guarantees, the study addresses a significant gap in the trusted execution environment literature, where prior evaluations have largely relied on informal or empirical methods. The proposed approach substantially enhances the reliability and trustworthiness of SEV as a confidential computing platform in cloud environments, providing a foundation for future formal analyses of hardware-based security mechanisms.
Prior assumptions about Trusted Execution Environment (TEE) application distribution and security maturity lack empirical validation, particularly for IoT security and AI model protection. Method: We conduct the first large-scale empirical study of 241 open-source TEE applications—spanning Intel SGX and ARM TrustZone—employing a hybrid approach combining manual code review with customized static analysis to assess SDK usage patterns, cryptographic implementations, and input validation practices. Contribution/Results: Our analysis reveals that 32.4% of projects redundantly reimplement cryptographic logic, 25.3% embed hardcoded cryptographic keys—a critical vulnerability—and 61 applications exhibit severe security flaws. Notably, 30% of applications target IoT security and 12% focus on AI model protection, exposing significant gaps between real-world deployment scenarios and prior academic assumptions. These findings fundamentally challenge existing perceptions of TEE adoption and security readiness, providing rigorous, evidence-based guidance for improving TEE SDK usability and developer support tooling.
为解决TEE中的缓存侧信道攻击问题,本文提出HermiCache,一种针对RISC-V核心设计的缓存替换策略,提供细粒度配置与确定性保护。
TEE containers face systemic security risks—including information leakage, rollback attacks, denial-of-service (DoS), and Iago attacks—due to ambiguously defined trust boundaries and isolation failures. This paper introduces the first automated boundary identification framework that jointly leverages static and dynamic analysis to reverse-engineer and formally verify isolation policies of mainstream TEE containers (e.g., SCONE, Gramine). Our analysis uncovers critical trust boundary misalignments in multiple production-deployed containers, empirically reproduces four classes of high-severity attacks, and quantifies their exploitability and impact scope. The work establishes a reusable trust boundary modeling paradigm and provides concrete hardening guidelines for TEE middleware design. By enabling rigorous, artifact-based boundary validation, it advances trusted execution environments from opaque “black-box” encapsulation toward verifiable, architecture-aware isolation.
This study addresses the risk of tampering by untrusted applications at Trusted Execution Environment (TEE) interaction boundaries by proposing the PRA-TLS protocol. For the first time, this work extends remote attestation to the client application layer, employing a customized Attester Daemon to perform runtime measurements of both host and application states. This approach establishes an end-to-end chain of trust, ensuring that only legitimate environments can invoke enclaves. A prototype implementation is developed using Intel SGX, accompanied by comprehensive performance evaluations. Furthermore, the protocol’s security properties are formally verified using the Tamarin Prover. The results demonstrate that the proposed scheme achieves rigorous security guarantees and effectively defends against input and output tampering attacks.
This work addresses critical security vulnerabilities in Trusted Execution Environment (TEE) applications—such as data leakage and code injection—caused by improper partitioning, for which automated repair mechanisms have been lacking. The paper introduces TEERepair, the first framework capable of automatically repairing TEE partitioning errors. It encodes security repair patterns using a domain-specific language (DSL) and leverages large language models (LLMs) to understand the semantics of underlying C code, thereby generating context-aware repair patches and automatically constructing validation test clients. This approach overcomes key challenges including semantic extraction difficulty, absence of development guidelines, and insufficient verification methods. Evaluated on the PartitioningE-Bench benchmark, TEERepair achieves an 87.6% repair success rate and has contributed five pull requests to real-world TEE projects, two of which have already been merged.
This study addresses the challenge of remote attestation for proprietary software within Trusted Execution Environments (TEEs), where closed-source code impedes verification. To overcome this, we propose a disclosure-free attribute proof architecture that introduces a novel "provable auditing" paradigm. By leveraging hardware-endorsed zero-knowledge proof chains, this approach cryptographically binds automated auditing conclusions—derived from static analysis and fuzz testing—to TEE measurement values. We implement an end-to-end workflow using technology stacks including Intel SGX and Gramine, validating its feasibility in Python-based scenarios. The proposed framework enables verifiers to confidently ascertain that running artifacts satisfy established security properties without requiring trust in third parties or access to the underlying source code.
This study addresses the vulnerability of AI models on edge devices to OS-level attacks and the difficulty of porting them to Trusted Execution Environments (TEEs). To overcome these challenges, this work proposes a WebAssembly-based, port-free secure execution framework. By leveraging WAMR and OP-TEE, the approach enables unmodified native AI models to execute directly within Arm TrustZone, thereby protecting intellectual property. Furthermore, a hardware fuse-based encrypted distribution mechanism is integrated to enhance security. Experimental results demonstrate that, compared with manual porting solutions, the proposed framework incurs only a 22% increase in system overhead and a 6% rise in inference latency. This work significantly lowers development barriers while achieving efficient and reliable model protection for edge AI deployments.
为解决TEE中内存安全和性能问题,本文提出PRISM架构,利用棱镜能力创建用户空间隔离区,实现高效的所有权建立、域转换及远程证明。