Multi-Interface Analysis-Based Fuzzing Scheme for OPTEE System Kernel

Yidong Zhang, Baojiang Cui · 2025

The complexity of the ARM Trusted Execution Environment (TEE) architecture and various commercial factors make it difficult to directly and effectively apply vulnerability discovery techniques designed for conventional binary programs and operating system kernels to the vulnerability mining of trusted operating system kernels. Existing vulnerability discovery schemes for the ARM TEE often focus only on individual components within the architecture or partial functionalities of the trusted operating system kernel, making it challenging to achieve comprehensive and automated testing coverage across most interfaces. This paper proposes a vulnerability discovery technique for the ARM TEE based on multi-interface analysis to address the security analysis challenges of the ARM TEE. The main contributions of this work include:(1) Innovatively proposing a fuzz testing framework that constructs multi-interface combinations from the Client Application (CA) layer and the Trusted Application (TA) layer. This shifts the testing target from individual components or partial kernel functionalities to the entire call process, aiming to achieve more comprehensive and complete testing results.(2) Innovatively proposing a sample generation strategy based on the xtest testing component and multi-level interface tracing. By adding tracing logic to the libteec library and the trusted operating system, high-quality initial samples are generated in conjunction with the xtest testing component.(3) Integrating AFL (American Fuzzy Lop) into this fuzz testing framework and combining it with static instrumentation to enable comprehensive and effective automated testing of the trusted operating system kernel in a full-system simulation environment.

Read the paper · More papers on PaperTik