Skip to content

A Code-Refactoring-Based Migration Scheme for Trusted Applications across Heterogeneous TEEs

2026 · Journal of networking and network applications · Vol 6, pp. 97-110 · 0 citations · 35 references

TL;DR

Experimental results show that CRTAMS enables trusted-application migration across heterogeneous TEEs with low refactoring cost and moderate execution overhead in the evaluated workloads, while reducing the amount of platform-specific code that developers must write manually.

Abstract

Trusted execution environments (TEEs) have become a key building block for privacy-preserving and confidential computing because they protect sensitive code and data through hardware-assisted isolation. However, the current TEE ecosystem remains highly fragmented. Different platforms expose different execution abstractions, programming interfaces, build procedures, and deployment models, making trusted applications difficult to migrate and costly to adapt. This paper presents CRTAMS, a code-refactoring-based migration scheme for trusted applications across heterogeneous TEEs. CRTAMS introduces an integrated programming model that uses Clang Attributes to express TEE boundary annotations, named CATBA, so that developers can describe trusted and untrusted code boundaries in a platform-neutral form. Based on the annotated source code, CRTAMS converts the program into LLVM intermediate representation, extracts annotation metadata, refactors the code according to the selected target platform, and automatically generates a target-platform-compliant trusted-application project structure and auxiliary build files. We implement a prototype and evaluate it on three categories of heterogeneous TEE hardware, including ARM TrustZone, Intel SGX/TDX, and AMD SEV. Experimental results show that CRTAMS enables trusted-application migration across heterogeneous TEEs with low refactoring cost and moderate execution overhead in the evaluated workloads, while reducing the amount of platform-specific code that developers must write manually.

View source

Similar papers

Open access Sep 2026

On-Premise CodeBERT-Driven Model for Vulnerability Detection in Source Code

Security vulnerabilities in software systems remain a major concern in modern computing, especially as applications grow in complexity and are increasingly integrated into critical infrastructures. Traditional vulnerability detection methods such as static code analysis tools and manual inspection face limitations i...

D. Sako · 0 citations
Open access Aug 2026

Formal Specification of Trusted Execution Environment APIs and Model Checking of Trusted Applications

Trusted execution environments (TEEs) have emerged as a key technology in cybersecurity, providing isolated environments where sensitive computations can be executed securely. Trusted applications running in a TEE are developed using standardized APIs to which many TEE hardware platforms conform. However, formal execut...

Geunyeol Yu, Seunghyun Chae, Kyungmin Bae et al. · 0 citations
Review Open access Sep 2026

CodeMergeR: A Shiny‐Based Application for Codelist Integration

ABSTRACT Objective To describe CodeMergeR, an open‐source R shiny application developed within the VAC4EU network for the standardization, cleaning, and integration of individual concept codelists into a master file for real‐world evidence (RWE) studies. Materials and Methods CodeMergeR was designed to process codelist...

V. Hoxhaj, J. Riera-Arnau, Sima Mohammadi et al. · 0 citations
#software testing Open access Sep 2026

LLM-Assisted Porting of Security-Critical C Libraries to Idiomatic Rust: A Multi-Model Empirical Study

Differential fuzzing reveals complementary bugs in the manual and LLM porting of security-critical C libraries to idiomatic Rust and translates these findings into concrete practical guidance for teams planning a similar migration.

Marco Parrillo, Marco Grassi, Luigi Laura · 0 citations
Open access Aug 2026

Response-Level Identification of Cloud API Misconfigurations Using Large Language Models †

This study investigates the use of Large Language Models to detect security misconfigurations directly from cloud API response data and evaluates each model’s capability to accurately determine the number of misconfigurations and generate clear, actionable security explanations.

A. Krishna, Farzana Zahid · 0 citations
Book Open access Sep 2026

Unifying eBPF across Platforms: Formal Semantics, Conformance Testing, and Specifications

This work is building an executable formal semantics for eBPF in F* that explicitly distinguishes cross-platform and platform-specific behaviors and envision this semantics as a practical foundation for a uniform, trustworthy eBPF across platforms.

Yan-Ze Li, Reto Achermann, Ivan Beschastnikh et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.