EDBT 2026 Demo / reviewers in the wild / expert
Shuangquan Pan
dblp:420/8652
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Hardware security and side channels · 62% Systems and software security · 38% | |
| Software engineering, system software, and programming languages
1 paper |
Program verification · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels
trusted execution environments |
0.9 | 1 | 2025 | Tacco: A Framework for Ensuring the Security of Real-World TEEs via Formal Verification · IEEE Trans. Dependable Secur. Comput. 2025 |
Program verification
theorem proving |
0.9 | 1 | 2025 | Tacco: A Framework for Ensuring the Security of Real-World TEEs via Formal Verification · IEEE Trans. Dependable Secur. Comput. 2025 |
Systems and software security › security engineering › security certification
common criteria |
0.3 | 1 | 2025 | Tacco: A Framework for Ensuring the Security of Real-World TEEs via Formal Verification · IEEE Trans. Dependable Secur. Comput. 2025 |
Systems and software security › security engineering
security certification |
0.3 | 1 | 2025 | Tacco: A Framework for Ensuring the Security of Real-World TEEs via Formal Verification · IEEE Trans. Dependable Secur. Comput. 2025 |
Methods — techniques the papers use, named apart from their topics
theorem proving · 1.7Isabelle/HOL · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Tacco: A Framework for Ensuring the Security of Real-World TEEs via Formal VerificationabstractTrusted Execution Environment (TEE) provides isolation for sensitive data in electronic devices and its compromise can lead to enormous losses. TEE's information-flow security is essential and can be robustly ensured by formal methods. Nevertheless, the cross-domain API invocation of TEE is intricate for information-flow analysis, and the service provider on the TEE, i.e., trusted application, brings complexity to the TEE specification and verification. Existing research seldom delves into general TEEs that are compliant with GlobalPlatform (GP), which is an important and universal TEE standard. Furthermore, they do not align with the requirements for Common Criteria certification. In this paper, we propose a TEE-applicable and Common Criteria-oriented framework to specify and verify the information-flow security of GP TEE, which is applied to the verification of the real-world commercial MiTEE. Firstly, we present a framework for TEE that aligns with the requirements of Common Criteria's highest assurance level (EAL 7). It incorporates a domainswitch based mechanism to model the cross-domain TEE API invocation and a parameterized modeling approach to handle trusted applications. Secondly, we model GlobalPlatform-compliant TEE with the framework as GP TEE security model layer and function layer, which are reusable for all GP TEEs. Thirdly, we specify MiTEE as the MiTEE design layer that refines GP TEE model. Lastly, we verify the information-flow security of GP TEE and MiTEE via theorem proving and uncover four critical vulnerabilities in MiTEE. This work contributes to MiTEE's acquirement of an EAL 5+ certificate. All works are carried out in Isabelle/HOL, with nearly 32000 lines of code. Jilin Hu, Yongwang Zhao, Shuangquan Pan, Zuohua Ding, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |