{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:20:46Z","timestamp":1780586446124,"version":"3.54.1"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput."],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1109\/tc.2024.3449105","type":"journal-article","created":{"date-parts":[[2024,8,23]],"date-time":"2024-08-23T17:45:41Z","timestamp":1724435141000},"page":"2722-2733","source":"Crossref","is-referenced-by-count":4,"title":["ROLoad-PMP: Securing Sensitive Operations for Kernels and Bare-Metal Firmware"],"prefix":"10.1109","volume":"73","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7823-7441","authenticated-orcid":false,"given":"Wende","family":"Tan","sequence":"first","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6406-9360","authenticated-orcid":false,"given":"Chenyang","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Computer Science and Technology, Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9891-5610","authenticated-orcid":false,"given":"Yangyu","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Computer Science, Chongqing University, Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7990-8676","authenticated-orcid":false,"given":"Yuan","family":"Li","sequence":"additional","affiliation":[{"name":"Zhongguancun Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7894-8828","authenticated-orcid":false,"given":"Chao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute for Network Science and Cyberspace, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianping","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.51"},{"key":"ref2","first-page":"161","article-title":"Control-flow bending: On the effectiveness of control-flow integrity","volume-title":"Proc. 24th USENIX Secur. Symp. (USENIX Secur. 15)","author":"Carlini","year":"2015"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243739"},{"key":"ref4","first-page":"1","article-title":"Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software","volume-title":"Proc. 12th Netw. Distrib. Syst. Secur. Symp.","author":"Newsome","year":"2005"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23339"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2610384.2610407"},{"key":"ref7","first-page":"147","article-title":"Code-pointer integrity","volume-title":"Proc. 11th USENIX Symp. Operating Syst. Des. Implementation (OSDI 14)","author":"Kuznetsov","year":"2014"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"ref9","first-page":"63","article-title":"StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks","volume-title":"Proc. 7th Conf. USENIX Secur. Symp.","volume":"7","author":"Cowan","year":"1998"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2013.44"},{"key":"ref13","first-page":"337","article-title":"Control flow integrity for COTS binaries","volume-title":"Proc. 22nd USENIX Secur. Symp. (USENIX Secur. 13)","author":"Zhang","year":"2013"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"ref15","first-page":"177","article-title":"PAC it up: Towards pointer integrity using ARM pointer authentication","volume-title":"Proc. 28th USENIX Secur. Symp. (USENIX Secur. 19)","author":"Liljestrand","year":"2019"},{"key":"ref16","article-title":"Improved control flow integrity (KCFI) implementation submitted for Linux 6.1","author":"Larabel","year":"2023"},{"key":"ref17","article-title":"Intel(r) memory protection extensions enabling guide","year":"2023"},{"key":"ref18","article-title":"Delivering enhanced security through memory tagging extension","author":"Mitsunami","year":"2023"},{"key":"ref19","article-title":"Intel(r) 64 and IA-32 architectures software developer manuals","year":"2023"},{"key":"ref20","first-page":"241","article-title":"libmpk: Software abstraction for Intel memory protection keys (intel MPK)","volume-title":"Proc. USENIX Annu. Tech. Conf. (USENIX ATC 19)","author":"Park","year":"2019"},{"key":"ref21","article-title":"DACR, domain access control register","year":"2023"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.9"},{"key":"ref23","first-page":"83","article-title":"IMIX: In-process memory isolation extension","volume-title":"Proc. 27th USENIX Secur. Symp. (USENIX Secur. 18)","author":"Frassetto","year":"2018"},{"key":"ref24","article-title":"Arm architecture reference manual for A-profile architecture","year":"2023"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3337167.3337175"},{"key":"ref26","article-title":"Branch target identification","year":"2023"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586274"},{"key":"ref28","article-title":"Memory protection unit","year":"2023"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853210"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"ref31","first-page":"973","article-title":"Meltdown: Reading kernel memory from user space","volume-title":"Proc. 27th USENIX Secur. Symp. (USENIX Secur. 18)","author":"Lipp","year":"2018"},{"key":"ref32","article-title":"MDS: Microarchitectural data sampling","year":"2020"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/DAC56929.2023.10247657"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23099"},{"key":"ref35","article-title":"Data execution prevention","year":"2023"},{"key":"ref36","first-page":"147","article-title":"Securing software by enforcing data-flow integrity","volume-title":"Proc. 7th Symp. Operating Syst. Des. Implementation (OSDI \u201906)","author":"Castro","year":"2006"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"ref39","article-title":"Memory tagging and how it improves C\/C++ memory safety","author":"Serebryany","year":"2018"},{"key":"ref40","first-page":"1221","article-title":"ERIM: Secure, efficient in-process isolation with protection keys (MPK)","volume-title":"Proc. 28th USENIX Secur. Symp. (USENIX Secur. 19)","author":"Vahldiek-Oberwagner","year":"2019"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00087"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623206"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.46586\/tosc.v2017.i1.4-44"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304037"},{"key":"ref45","first-page":"231","article-title":"uXOM: Efficient execute-only memory on ARM Cortex-M","volume-title":"Proc. 28th USENIX Secur. Symp. (USENIX Secur. 19)","author":"Kwon","year":"2019"}],"container-title":["IEEE Transactions on Computers"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/12\/10746886\/10644110.pdf?arnumber=10644110","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T00:32:06Z","timestamp":1732667526000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10644110\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12]]},"references-count":45,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tc.2024.3449105","relation":{},"ISSN":["0018-9340","1557-9956","2326-3814"],"issn-type":[{"value":"0018-9340","type":"print"},{"value":"1557-9956","type":"electronic"},{"value":"2326-3814","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12]]}}}