USENIX Security2020Top-tier venue
PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation
Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, Michael Grace
Abstract
ARM's TrustZone technology is the basis for security of billions of devices worldwide, including Android smartphones and IoT devices. Because TrustZone has access to sensitive information such as cryptographic keys, access to TrustZone has been locked down on real-world devices: only code that is authenticated by a trusted party can run in TrustZone. A side-effect is that TrustZone software cannot be instrumented or monitored. Thus, recent advances in dynamic analysis techniques such as feedback-driven fuzz testing have not been applied to TrustZone software. To address the above problem, this work builds an emulator that runs four widely-used, real-world TrustZone operating systems (TZOSes) -Qualcomm's QSEE, Trustonic's Kinibi, Samsung's TEEGRIS, and Linaro's OP-TEE -and the trusted applications (TAs) that run on them. The traditional challenge for this approach is that the emulation effort required is often impractical. However, we find that TZOSes depend only on a limited subset of hardware and software components. By carefully choosing a subset of components to emulate, we find we are able to make the effort practical. We implement our emulation on PARTEMU, a modular framework we develop on QEMU and PANDA. We show the utility of PARTEMU by integrating feedback-driven fuzz-testing using AFL and use it to perform a large-scale study of 194 unique TAs from 12 different Android smartphone vendors and a leading IoT vendor, finding previously unknown vulnerabilities in 48 TAs, several of which are exploitable. We identify patterns of developer mistakes unique to TrustZone development that cause some of these vulnerabilities, highlighting the need for TrustZone-specific developer education. We also demonstrate using PARTEMU to test the QSEE TZOS itself, finding crashes in code paths that would not normally be exercised on a real device. Our work shows that dynamic analysis of real-world TrustZone software through emulation is both feasible and beneficial.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1025c3fd-5cdd-46da-824f-199ac53ec974Cited by top-tier papers18
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun et al.USENIX ATC 2020 · 83 citations
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 81 citations
- ECMO: Peripheral Transplantation to Rehost Embedded Linux KernelsMuhui Jiang, Lin Ma, Yajin Zhou, Qiang Liu et al.CCS 2021 · 11 citations
- EL3XIR: Fuzzing COTS Secure MonitorsChristian Lindenmeier, Mathias Payer, Marcel BuschUSENIX Security 2024 · 10 citations
- MetaEmu: An Architecture Agnostic Rehosting Framework for Automotive FirmwareZitai Chen, Sam L. Thomas, Flavio D. GarciaCCS 2022 · 9 citations
Builds on7
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar et al.NDSS 2017 · 700 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile SystemsSeyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang et al.USENIX Security 2018 · 81 citations
Related papers
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- TEEzz: Fuzzing Trusted Applications on COTS Android DevicesMarcel Busch, Aravind Machiry, Chad Spensky, Giovanni Vigna et al.S&P 2023
- ReZone: Disarming TrustZone with TEE Privilege ReductionDavid Cerdeira, José Martins, Nuno Santos, Sandro PintoUSENIX Security 2022
- TÄMU: Emulating Trusted Applications at the (GlobalPlatform)-API LayerPhilipp Mao, Li Shi, Marcel Busch, Mathias PayerS&P 2026 · 1 citation
- SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT DevicesQinying Wang, Boyu Chang, Shouling Ji, Yuan Tian et al.S&P 2024 · 19 citations
