DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ma, Chengyan, Han, Ruidong, Shi, Jieke, Liu, Ye, Niu, Yuqing, Lu, Di, Tian, Chuang, Ma, Jianfeng, Gao, Debin, Lo, David
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912473305579520
author Ma, Chengyan
Han, Ruidong
Shi, Jieke
Liu, Ye
Niu, Yuqing
Lu, Di
Tian, Chuang
Ma, Jianfeng
Gao, Debin
Lo, David
author_facet Ma, Chengyan
Han, Ruidong
Shi, Jieke
Liu, Ye
Niu, Yuqing
Lu, Di
Tian, Chuang
Ma, Jianfeng
Gao, Debin
Lo, David
contents Trusted Execution Environment (TEE) enhances the security of mobile applications and cloud services by isolating sensitive code in the secure world from the non-secure normal world. However, TEE applications are still confronted with vulnerabilities stemming from bad partitioning. Bad partitioning can lead to critical security problems of TEE, such as leaking sensitive data to the normal world or being adversely affected by malicious inputs from the normal world. To address this, we propose an approach to detect partitioning issues in TEE applications. First, we conducted a survey of TEE vulnerabilities caused by bad partitioning and found that the parameters exchanged between the secure and normal worlds often contain insecure usage with bad partitioning implementation. Second, we developed a tool named DITING that can analyze data-flows of these parameters and identify their violations of security rules we defined to find bad partitioning issues. Different from existing research that only focuses on malicious input to TEE, we assess the partitioning issues more comprehensively through input/output and shared memory. Finally, we created the first benchmark targeting bad partitioning, consisting of 110 test cases. Experiments demonstrate that DITING achieves an F1 score of 0.90 in identifying bad partitioning issues.
format Preprint
id arxiv_https___arxiv_org_abs_2502_15281
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
Ma, Chengyan
Han, Ruidong
Shi, Jieke
Liu, Ye
Niu, Yuqing
Lu, Di
Tian, Chuang
Ma, Jianfeng
Gao, Debin
Lo, David
Cryptography and Security
Software Engineering
Trusted Execution Environment (TEE) enhances the security of mobile applications and cloud services by isolating sensitive code in the secure world from the non-secure normal world. However, TEE applications are still confronted with vulnerabilities stemming from bad partitioning. Bad partitioning can lead to critical security problems of TEE, such as leaking sensitive data to the normal world or being adversely affected by malicious inputs from the normal world. To address this, we propose an approach to detect partitioning issues in TEE applications. First, we conducted a survey of TEE vulnerabilities caused by bad partitioning and found that the parameters exchanged between the secure and normal worlds often contain insecure usage with bad partitioning implementation. Second, we developed a tool named DITING that can analyze data-flows of these parameters and identify their violations of security rules we defined to find bad partitioning issues. Different from existing research that only focuses on malicious input to TEE, we assess the partitioning issues more comprehensively through input/output and shared memory. Finally, we created the first benchmark targeting bad partitioning, consisting of 110 test cases. Experiments demonstrate that DITING achieves an F1 score of 0.90 in identifying bad partitioning issues.
title DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2502.15281