3 papers
cs.CR2026
"Operator, can you hear me?" A Faithful Line into the UNISOC Baseband
Eduard Vlad, Philipp Mao, Marcel Busch +3
Baseband processors are reachable over the radio at all times. Their most security-relevant logic runs deep inside protocol state machines: the control-plane handlers that gate reg…
cs.CR2026
TÃMU: Emulating Trusted Applications at the (GlobalPlatform)-API Layer
Philipp Mao, Li Shi, Marcel Busch +1
Mobile devices rely on Trusted Execution Environments (TEEs) to execute security-critical code and protect sensitive assets. This security-critical code is modularized in component…
cs.CR2024
EmbedFuzz: High Speed Fuzzing Through Transplantation
Florian Hofhammer, Qinying Wang, Atri Bhattacharyya +5
Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruc…