Skip to content

A Code-Refactoring-Based Migration Scheme for Trusted Applications across Heterogeneous TEEs

2026 · Journal of networking and network applications · 0 citations · 35 references

Abstract

Trusted execution environments (TEEs) have become a key building block for privacy-preserving and confidential computing because they protect sensitive code and data through hardware-assisted isolation. However, the current TEE ecosystem remains highly fragmented. Different platforms expose different execution abstractions, programming interfaces, build procedures, and deployment models, making trusted applications difficult to migrate and costly to adapt. This paper presents CRTAMS, a code-refactoring-based migration scheme for trusted applications across heterogeneous TEEs. CRTAMS introduces an integrated programming model that uses Clang Attributes to express TEE boundary annotations, named CATBA, so that developers can describe trusted and untrusted code boundaries in a platform-neutral form. Based on the annotated source code, CRTAMS converts the program into LLVM intermediate representation, extracts annotation metadata, refactors the code according to the selected target platform, and automatically generates a target-platform-compliant trusted-application project structure and auxiliary build files. We implement a prototype and evaluate it on three categories of heterogeneous TEE hardware, including ARM TrustZone, Intel SGX/TDX, and AMD SEV. Experimental results show that CRTAMS enables trusted-application migration across heterogeneous TEEs with low refactoring cost and moderate execution overhead in the evaluated workloads, while reducing the amount of platform-specific code that developers must write manually.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.