USENIX Security2024Top-tier venue
EL3XIR: Fuzzing COTS Secure Monitors
Christian Lindenmeier, Mathias Payer, Marcel Busch
Abstract
ARM TrustZone forms the security backbone of mobile devices. TrustZone-based Trusted Execution Environments (TEEs) facilitate security-sensitive tasks like user authentication, disk encryption, and digital rights management (DRM). As such, bugs in the TEE software stack may compromise the entire system's integrity. EL3XIR introduces a framework to effectively rehost and fuzz the secure monitor firmware layer of proprietary TrustZone-based TEEs. While other approaches have focused on naively rehosting or fuzzing Trusted Applications (EL0) or the TEE OS (EL1), EL3XIR targets the highly-privileged but unexplored secure monitor (EL3) and its unique challenges. Secure monitors expose complex functionality dependent on multiple peripherals through diverse secure monitor calls. In our evaluation, we demonstrate that state-of-the-art fuzzing approaches are insufficient to effectively fuzz COTS secure monitors. While naive fuzzing appears to achieve reasonable coverage it fails to overcome coverage walls due to missing peripheral emulation and is limited in the capability to trigger bugs due to the large input space and low quality of inputs. We followed responsible disclosure procedures and reported a total of 34 bugs, out of which 17 were classified as security critical. Affected vendors confirmed 14 of these bugs, and as a result, EL3XIR was assigned six CVEs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 290ba3e8-6d8c-4b4e-bee0-b40ddfa55f32Cited by top-tier papers3
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 4 citations
- NASS: Fuzzing All Native Android System Services with Interface Awareness and CoveragePhilipp Mao, Marcel Busch, Mathias PayerUSENIX Security 2025
- Dorami: Privilege Separating Security Monitor on RISC-V TEEsMark Kuhne, Stavros Volos, Shweta ShindeUSENIX Security 2025
Builds on21
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- BOOMERANG: Exploiting the Semantic Gap in Trusted Execution EnvironmentsAravind Machiry, Eric Gustafson, Chad Spensky, Christopher Salls et al.NDSS 2017 · 119 citations
Related papers
- PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using EmulationLee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen et al.USENIX Security 2020
- SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT DevicesQinying Wang, Boyu Chang, Shouling Ji, Yuan Tian et al.S&P 2024 · 19 citations
- ReZone: Disarming TrustZone with TEE Privilege ReductionDavid Cerdeira, José Martins, Nuno Santos, Sandro PintoUSENIX Security 2022
- TEEzz: Fuzzing Trusted Applications on COTS Android DevicesMarcel Busch, Aravind Machiry, Chad Spensky, Giovanni Vigna et al.S&P 2023
- FPGA-TrustZone: Security Extension of TrustZone to FPGA for SoC-FPGA Heterogeneous ArchitectureShupeng Wang, Xindong Fan, Xiao Xu, Shuchen Wang et al.DAC 2025 · 1 citation
