EDBT 2026 Demo / reviewers in the wild / expert
Shiqi Liu 0006
dblp:136/9439-6
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2025
0000-0002-9164-8069ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MaTEE: Efficiently Bridging the Semantic Gap in TrustZone via Arm Pointer AuthenticationabstractTrusted Execution Environments (TEEs) employ hardware-based isolation mechanisms to safeguard the confidentiality and integrity of sensitive code and data. One such prevalent implementation is Arm TrustZone, which partitions the system into the secure and normal (non-secure) worlds. However, this partitioning results in the secure world having very limited visibility into the operating information of the normal world, creating a semantic gap between these two worlds. Specifically, the secure world lacks an effective user identity authentication when receiving data requests from the normal world. Consequently, malicious Client Applications (CAs) in the normal world can deceive Trusted Applications (TAs) in the secure world by utilizing elaborate request parameters, compromising the sensitive data stored by other CAs. We systematically classify these Semantic Gap Vulnerabilities (SGVs) and propose a mate system for the TEE calledMaTEEto defend against SGVs.MaTEEutilizes Arm Pointer Authentication (PA) to bind each request to the corresponding CA's identity and then verifies the identity when the CA accesses sensitive data, thereby preventing malicious request forgery. In particular,MaTEEisolates sensitive data of different CAs without modifying existing CAs and TAs. Our evaluation demonstrates thatMaTEEsuccessfully defends against SGVs with a minimal runtime overhead (2.19%). Shiqi Liu 0006, Xiang Li 0166, Jie Wang 0138, Yongpeng Gao, Jiajin Hu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | More Granular, Less Trust: Enforcing Intra-Process Isolation With Arm CCA in an Untrusted Management EnvironmentabstractWith the increasing adoption of confidential computing, security-sensitive applications are often deployed in confidential virtual machines (CVMs), which reduce reliance on third-party cloud providers. However, privilege attacks originating from the OS remain a significant threat in these environments. Existing finer-grained isolation schemes, such as SHELTER (USENIX SEC’23), provide process-level protection but are still vulnerable to intra-process attacks and potential collusion between the OS and intra-process adversaries. Many current intra-process isolation techniques continue to depend on the OS to manage and enforce isolation domains, leading to a large Trusted Computing Base (TCB). This gap highlights the need for more granular, less trust-dependent confidential computing solutions. In this paper, we present CCAegis, a system that extends the Arm Confidential Compute Architecture (CCA) to enforce intra-process isolation of sensitive data and operations, safeguarding them from both intra-process adversaries and the OS. We employ static analysis to track the flow of sensitive data and identify functions that handle such data. Permission-switching instructions are inserted at the function call and return points, adjusting permissions via the Granule Protection Table (GPT) to ensure that only designated functions can access the isolated data. Notably, CCAegis places trust solely in the Secure Monitor, which configures the GPTs and manages domain switching, thereby minimizing the TCB. We implemented CCAegis on both an official emulator and a real development board to assess its performance. Our experimental results show that CCAegis effectively isolates sensitive data and operations, with performance overheads ranging from 1.01× to 1.43× compared to the original version across real-world cryptographic workloads. Shiqi Liu 0006, Zhouqi Jiang, Jie Wang 0138, Kun Sun 0001, Yulai Xie 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |