{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T16:37:33Z","timestamp":1781973453811,"version":"3.54.5"},"reference-count":46,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572432"],"award-info":[{"award-number":["62572432"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62532012"],"award-info":[{"award-number":["62532012"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1109\/tdsc.2025.3632885","type":"journal-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:52:25Z","timestamp":1763146345000},"page":"3131-3146","source":"Crossref","is-referenced-by-count":1,"title":["M1Pecker: A Dynamic Analysis Framework for Pointer Authentication in Apple M1 Chips"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-4288-4590","authenticated-orcid":false,"given":"Jiaxun","family":"Zhu","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zechao","family":"Cai","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2899-6121","authenticated-orcid":false,"given":"Wenbo","family":"Shen","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2899-0117","authenticated-orcid":false,"given":"Yutian","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0178-0171","authenticated-orcid":false,"given":"Rui","family":"Chang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Arm architecture reference manual for A-profile architecture","year":"2020"},{"key":"ref2","article-title":"Preparing your app to work with pointer authentication","year":"2022"},{"key":"ref3","article-title":"Examining pointer authentication on the iphone XS","author":"Zero","year":"2019"},{"key":"ref4","article-title":"iOS kernel PAC, one year later","volume-title":"Proc. Black Hat USA","author":"Azad","year":"2020"},{"key":"ref5","article-title":"Attacking iPhone XS max","volume-title":"Proc. Black Hat USA","author":"Wang","year":"2019"},{"key":"ref6","article-title":"2PAC 2Furious: Envisioning an iOS compromise in 2019","volume-title":"Proc. Infiltrate","author":"Grassi","year":"2019"},{"key":"ref7","article-title":"Fugu14 - Untethered iOS 14 jailbreak","author":"Henze","year":"2021"},{"key":"ref8","article-title":"Everything has changed in iOS 14, but jailbreak is eternal","volume-title":"Proc. BlackHat-USA","author":"Fan","year":"2021"},{"key":"ref9","article-title":"HW: Arm system registers","year":"2022"},{"key":"ref10","article-title":"Kernel debugging on apple silicon","author":"MacLachlan","year":"2021"},{"key":"ref11","article-title":"An overview of Macos Kernel debugging","year":"2021"},{"key":"ref12","article-title":"MacOS two-machine kernel debugging","year":"2022"},{"key":"ref13","first-page":"2833","article-title":"Demystifying pointer authentication on apple m1","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Cai","year":"2023"},{"key":"ref14","article-title":"Apple PAC, four years later: Reverse engineering the customized pointer authentication hardware implementation on apple M1","volume-title":"Proc. BlackHat-USA","author":"Cai","year":"2023"},{"key":"ref15","article-title":"M1N1: An experimentation playground for apple silicon","year":"2021"},{"key":"ref16","article-title":"SCTLR_El1, System control register (El1)","year":"2021"},{"key":"ref17","article-title":"Qarma","author":"Avanzi","year":"2016"},{"key":"ref18","article-title":"Pointerauthentication.rst","year":"2019"},{"key":"ref20","article-title":"Re: [Patch] ARMv8: Fix TCR 64-bit writes","author":"Kettenis","year":"2022"},{"key":"ref21","article-title":"Asahi Linux","year":"2020"},{"key":"ref22","article-title":"M1N1 feature support overview","year":"2021"},{"key":"ref23","article-title":"Progress report: January \/ february 2021","year":"2021"},{"key":"ref24","volume-title":"Research Design: Qualitative, Quantitative, and Mixed Methods Approaches","author":"Creswell","year":"2017"},{"issue":"RFC 2104","key":"ref25","article-title":"HMAC: Keyed-hashing for message authentication","author":"Krawczyk","year":"1997"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39799-X_41"},{"key":"ref27","article-title":"FUGU15 - The journey to jailbreaking iOS 15.4.1","author":"Henze","year":"2022"},{"key":"ref28","article-title":"A deep dive into an NSO zero-click imessage exploit: Remote code execution","author":"Zero","year":"2021"},{"key":"ref29","article-title":"KTRW: The journey to build a debuggable iphone","author":"Zero","year":"2019"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3470496.3527429"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"ref32","article-title":"US secure hash algorithms (SHA and SHA-based HMAC and HKDF)","author":"Hansen","year":"2011"},{"key":"ref34","article-title":"Behind the scenes of iOS and MAC security","volume-title":"Proc. Black Hat USA","author":"Krstic","year":"2019"},{"key":"ref35","article-title":"About the security content of iOS 16.4 and iPadOS 16.4","year":"2023"},{"key":"ref36","article-title":"About the security content of WatchOS 9.4","year":"2023"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3322469"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833570"},{"key":"ref39","article-title":"Reverse engineering the M1","volume-title":"Proc. Black Hat USA","author":"Skowronek","year":"2021"},{"key":"ref40","article-title":"Apple silicon hardware secrets: SPRR and guarded exception levels (GXF)","author":"Peter","year":"2021"},{"key":"ref41","first-page":"89","article-title":"In-kernel control-flow integrity on commodity OSes using ARM pointer authentication","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Yoo","year":"2022"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3334268"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218535"},{"key":"ref44","first-page":"177","article-title":"PAC it up: Towards pointer integrity using ARM pointer authentication","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Liljestrand","year":"2019"},{"key":"ref45","first-page":"3717","article-title":"Tightly seal your sensitive pointers with PACTight","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Ismail","year":"2022"},{"key":"ref46","first-page":"1037","article-title":"PTAuth: Temporal memory safety via robust points-to authentication","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"farkhani","year":"2021"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560598"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24026"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11434575\/11248954.pdf?arnumber=11248954","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:16:02Z","timestamp":1773710162000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11248954\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":46,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3632885","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}