Aug 2026· Formal Aspects of Computing· 0 citations· 15 references
TL;DR
A formal specification for TEE APIs using Maude focuses on the Trusted Storage API and the Cryptographic Operations API, both foundational to mobile and IoT applications and applies a state-space reduction technique based on invisible transitions to mitigate the state explosion problem.
Abstract
Trusted execution environments (TEEs) have emerged as a key technology in cybersecurity, providing isolated environments where sensitive computations can be executed securely. Trusted applications running in a TEE are developed using standardized APIs to which many TEE hardware platforms conform. However, formal executable models tailored to these standard TEE APIs have not been well developed. In this paper, we present a formal specification for TEE APIs using Maude. We focus on the Trusted Storage API and the Cryptographic Operations API, both foundational to mobile and IoT applications. To support the formal analysis of trusted applications, we also model the broader TEE infrastructure. In addition, we apply a state-space reduction technique based on invisible transitions to mitigate the state explosion problem. We demonstrate the effectiveness of our approach through the formal analysis of MQT-TZ, an open-source TEE application for IoT. Our formal analysis reveals a security vulnerability in the implementation of MQT-TZ. We patch the implementation and verify its correctness using model checking.
The Signal protocol is a prominent messaging protocol that secures communication for billions of users. It powers WhatsApp, the most widely used messaging application worldwide, and the Signal app, popular among privacy-conscious users. Extensive research in the computational and Dolev-Yao settings provides strong form...
Moustafa Said, Aurora Naska, Kevin Morio et al.· 0 citations
Experimental results show that CRTAMS enables trusted-application migration across heterogeneous TEEs with low refactoring cost and moderate execution overhead in the evaluated workloads, while reducing the amount of platform-specific code that developers must write manually.
Di Lu, Qing-Wen Zhang, Yujia Liu et al.· Journal of networking and ne...· 0 citations
The findings show that kernel-level data-transport and synchronization choices directly influence the classes of concurrency and memory-sharing defects exposed by each TEE architecture.
This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.
A. Krishna, Farzana Zahid· Pragmatic Cybersecurity· 0 citations
This work is building an executable formal semantics for eBPF in F* that explicitly distinguishes cross-platform and platform-specific behaviors and envision this semantics as a practical foundation for a uniform, trustworthy eBPF across platforms.
Yan-Ze Li, Reto Achermann, Ivan Beschastnikh et al.· Proceedings of the 4th Works...· 0 citations
This work develops a new methodology for verifying cryptographic software and extends SymCrypt with experimental optimizations and implementations of algorithms such as FrodoKEM, ML-DSA, and HPKE to explore the scalability of writing, adapting, and verifying cryptographic code.
Ho Son, C. Fournet, Jonathan Protzenko et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.