{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:10:16Z","timestamp":1783613416982,"version":"3.55.0"},"reference-count":75,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Institute of Information & communications Technology Planning & Evaluation"},{"name":"Government (MSIT)"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.3006703","type":"journal-article","created":{"date-parts":[[2020,7,2]],"date-time":"2020-07-02T20:27:41Z","timestamp":1593721661000},"page":"121874-121888","source":"Crossref","is-referenced-by-count":18,"title":["SofTEE: Software-Based Trusted Execution Environment for User Applications"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1081-9899","authenticated-orcid":false,"given":"Unsung","family":"Lee","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chanik","family":"Park","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","first-page":"267","article-title":"Shielding applications from an untrusted cloud with haven","author":"baumann","year":"2014","journal-title":"Proc of USENIX Symp on Operating Systems Design and Implementation (OSDI)"},{"key":"ref72","first-page":"645","article-title":"Graphene-SGX: A practical library OS for unmodified applications on SGX","author":"tsai","year":"2017","journal-title":"Proc USENIX Annu Tech Conf (ATC)"},{"key":"ref71","first-page":"383","article-title":"Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms","author":"hund","year":"2009","journal-title":"Proc 14th USENIX Secur Symp (USENIX Secur )"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"ref74","first-page":"689","article-title":"SCONE: Secure Linux Containers with Intel SGX","author":"arnautov","year":"2016","journal-title":"Proc of USENIX Symp on Operating Systems Design and Implementation (OSDI)"},{"key":"ref39","first-page":"1","article-title":"Subverting windows $7\\times64$\n kernel with DMA attacks","author":"aumaitre","year":"2010","journal-title":"Proc Hack in the Box Security Conf"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23068"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2007.912030"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2731186.2731188"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050750"},{"key":"ref31","first-page":"165","article-title":"Ironclad apps: End-to-end security via automated fullsystem verification","volume":"2014","author":"hawblitzel","year":"0","journal-title":"11th USENIX Symp Operating Syst Design Implement (OSDI) Broomfield CO USA"},{"key":"ref30","article-title":"Cache timing attacks","author":"banescu","year":"2011"},{"key":"ref37","year":"2017","journal-title":"CVE-2017-5691"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.25"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/2103656.2103678"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23009"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/1655008.1655019"},{"key":"ref61","first-page":"189","article-title":"STEALTHMEM: System-level protection against cache-based side channel attacks in the cloud","author":"kim","year":"2012","journal-title":"Proc 21st USENIX Secur Symp (USENIX Security)"},{"key":"ref63","first-page":"459","article-title":"kGuard: Lightweight kernel protection against returnto-user attacks","author":"kemerlis","year":"2012","journal-title":"Proc 21st USENIX Secur Symp (USENIX Security)"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"ref64","first-page":"957","article-title":"ret2dir: Rethinking kernel isolation","author":"kemerlis","year":"2014","journal-title":"Proc 23rd USENIX Secur Symp (USENIX Secur )"},{"key":"ref27","first-page":"367","article-title":"Shuffler: Fast and deployable continuous code re-randomization","author":"williams-king","year":"2016","journal-title":"Proc of USENIX Symp on Operating Systems Design and Implementation (OSDI)"},{"key":"ref65","author":"george","year":"2011","journal-title":"Technology Insight IntelNext Generation Microarchitecture Codename Ivy Bridge"},{"key":"ref66","year":"2013","journal-title":"64 and IA-32 Architectures Software Developer's Manual"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062267"},{"key":"ref67","year":"2012","journal-title":"ARM Architecture Reference Manual"},{"key":"ref68","year":"2016","journal-title":"ARM Architecture Reference Manual Supplement"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23024"},{"key":"ref2","year":"2020","journal-title":"Trusted Execution Environment (TEE) 101 A Primer"},{"key":"ref1","year":"2020","journal-title":"Device-side Security Samsung Pay TrustZone and the TEE"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224075"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050752"},{"key":"ref21","first-page":"1","article-title":"Mach: A new kernel foundation for UNIX development","author":"accetta","year":"1986","journal-title":"Proc Usenix Conf"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857726"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813691"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23173"},{"key":"ref25","first-page":"40","article-title":"Enhanced operating system security through efficient and fine-grained address space randomization","author":"giuffrida","year":"2012","journal-title":"Proc 21st USENIX Secur Symp (USENIX Security)"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.11"},{"key":"ref51","first-page":"857","article-title":"Sanctum: Minimal hardware extensions for strong software isolation","author":"costan","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref59","first-page":"549","article-title":"ARMageddon: Cache attacks on mobile devices","author":"lipp","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897885"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.34"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363205"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363219"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354252"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23448"},{"key":"ref52","year":"2012","journal-title":"ARM System Memory Management Unit"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451146"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1346256.1346267"},{"key":"ref40","first-page":"21","article-title":"Understanding DMA Malware","author":"stewin","year":"2012","journal-title":"Proc Int'l Conf Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA)"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346284"},{"key":"ref13","article-title":"Tamper-resistant execution in an untrusted operating system using a virtual machine monitor","author":"chen","year":"2007"},{"key":"ref14","first-page":"565","article-title":"Hardware-assisted on-demand hypervisor activation for efficient security critical code execution on mobile devices","author":"cho","year":"2016","journal-title":"Proc USENIX Annu Tech Conf (ATC)"},{"key":"ref15","first-page":"841","article-title":"fTPM: A software-only implementation of a TPM chip","author":"raj","year":"2016","journal-title":"Proc 25th USENIX Secur Symp (USENIX Secur )"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132782"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541986"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224077"},{"key":"ref4","year":"2020","journal-title":"HYPRES"},{"key":"ref3","year":"2020","journal-title":"WiDEVINE DRM Architecture Overview"},{"key":"ref6","year":"2014","journal-title":"Software Guard Extensions Programming Reference"},{"key":"ref5","year":"2009","journal-title":"Security technology building a secure system using trustzone technology (white paper)"},{"key":"ref8","year":"2020","journal-title":"Raspberry Pi 3 Board Reference"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2014.25"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1519144.1519145"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081349"},{"key":"ref46","first-page":"541","article-title":"vTZ: Virtualizing ARM TrustZone","author":"hua","year":"2017","journal-title":"Proc 26th USENIX Conf Secur Symp Secur"},{"key":"ref45","first-page":"23","article-title":"Lmbench: Portable tools for performance analysis","author":"mcvoy","year":"1996","journal-title":"Proc Annu Conf USENIX Annu Tech Conf (ATEC)"},{"key":"ref48","first-page":"2","article-title":"The BSD packet filter: A new architecture for user-level packet capture","author":"mccanne","year":"1993","journal-title":"Proc Usenix Winter Conf"},{"key":"ref47","article-title":"Cache-attacks on the ARM TrustZone implementations of AES-256 and AES-256-GCM via GPU-based analysis","author":"lapid","year":"2018","journal-title":"Proc Selected Areas Cryptography"},{"key":"ref42","year":"2020","journal-title":"ARM Architecture Reference Manual"},{"key":"ref41","first-page":"1441","article-title":"Shielding software from privileged side-channel attacks","author":"dong","year":"2018","journal-title":"Proc 7th USENIX Secur Symp (USENIX Secur )"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694380"},{"key":"ref43","year":"2020","journal-title":"Linux TPM2 & TSS Software"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09131703.pdf?arnumber=9131703","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T19:53:06Z","timestamp":1639770786000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9131703\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":75,"URL":"https:\/\/doi.org\/10.1109\/access.2020.3006703","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}