面向可信执行环境内核API的模糊测试方案
首发时间:2024-04-01
摘要:当前,可信执行环境技术的发展为应用程序提供了一个安全的执行空间,有效保护了应用敏感信息,但其本身也存在安全漏洞。最新的相关研究使用模糊测试技术检测可信执行环境的漏洞,但是,现有的研究缺乏针对通用接口的设计方案。为解决上述问题,本文提出一种面向TEE内核API接口的模糊测试方法。该方法针对可信执行环境中的标准API接口设计实现模糊测试框架,同时针对难以收集和解密可信应用程序用于依赖分析和种子生成的问题,设计实现了基于GlobalPlatform的TEEInternalCoreAPI接口规范的种子生成方法。
关键词: 计算机科学技术基础学科 可信执行环境 模糊测试
For information in English, please click here
Fuzz testing solution for trusted execution environment kernel API
Abstract:Currently, the development of Trusted Execution Environment (TEE) technology provides a secure execution space for applications, effectively safeguarding sensitive information. However, TEE itself is susceptible to security vulnerabilities. Recent studies have utilized fuzz testing techniques to detect vulnerabilities in TEEs, yet existing research lacks design schemes for generic interfaces. To address these issues, this paper proposes a fuzz testing method targeting TEE kernel API interfaces. This method designs and implements a fuzz testing framework for standard API interfaces within the Trusted Execution Environment. Additionally, to tackle the challenges of collecting and decrypting trusted applications for dependency analysis and seed generation, a seed generation method based on the Global Platform\'s TEE Internal Core API interface specification is devised and implemented.
Keywords: Basic disciplines of Computer Science and Technology Trusted Execution Environment Fuzzing
基金:
引用
No.****
同行评议
勘误表
面向可信执行环境内核API的模糊测试方案
评论
全部评论