arrow
Return

TeeDFuzzer: Fuzzing Trusted Execution Environment

delete2025-04-21
delete0
delete
OA
AI
S
Sheng Wen
X
Xu, Liam
L
Liwei Tian
S
Suping Liu
Y
Yong Ding *
DOI:10.3390/electronics14081674delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The Trusted Execution Environment (TEE) is crucial for safeguarding the ecosystem of embedded systems. It uses isolation to minimize the TCB (Trusted Computing Base) and protect sensitive software. It is vital because devices handle vast, potentially sensitive data. Leveraging ARM TrustZone, widely used in mobile and IoT for TEEs, it ensures hardware protection via security extensions, though needing firmware and software stack support. Despite the reputation of TEEs for high security, TrustZone-aided ones have vulnerabilities. Fuzzing, as a practical bug-finding technique, has seen limited research in the context of TEE. The unique software architecture of TrustZone-assisted TEE complicates the direct application of traditional fuzzing methods. Moreover, simplistic approaches, such as feeding random input values into TEE through the API functions of the rich operating system, fail to uncover deeper, latent bugs within the TEE code. In this paper, we present a fuzzing strategy for TrustZone-assisted TEE that utilizes inferred dependencies between Trusted Kernel system calls to uncover deep-seated TEE bugs. We implemented our approach on OP-TEE, where it successfully identified 17 crashes, including one previously undetected kernel bug.
Keywords:
trusted execution environment
fuzz testing
security
static analysis
dynamic graph

Journal

Electronics cover
Electronics
IF:
2.6
Papers:
9.3K
Citations:
4.7W

Organization

G
Guangdong Univ Sci & Technol
Scholars:
39
Papers: 20
Citations: 7
H
hong kong coll technol
Scholars:
2
Papers: 1
Citations: 0