{"id":"https://openalex.org/W7124904351","doi":"https://doi.org/10.1109/cloudcom67567.2025.11331499","title":"The Twilight of SGX, but Not its Tests: An In-Depth Study of Testing in SGX Projects","display_name":"The Twilight of SGX, but Not its Tests: An In-Depth Study of Testing in SGX Projects","publication_year":2025,"publication_date":"2025-11-14","ids":{"openalex":"https://openalex.org/W7124904351","doi":"https://doi.org/10.1109/cloudcom67567.2025.11331499"},"language":null,"primary_location":{"id":"doi:10.1109/cloudcom67567.2025.11331499","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cloudcom67567.2025.11331499","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 lEEE International Conference on Cloud Computing Technology and Science (CloudCom)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5085100368","display_name":"Jiapei Deng","orcid":null},"institutions":[{"id":"https://openalex.org/I37796252","display_name":"Beijing University of Technology","ror":"https://ror.org/037b1pp87","country_code":"CN","type":"education","lineage":["https://openalex.org/I37796252"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jiapei Deng","raw_affiliation_strings":["College of Computer Science, Beijing University of Technology,Beijing,China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science, Beijing University of Technology,Beijing,China","institution_ids":["https://openalex.org/I37796252"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100411657","display_name":"Yin Liu","orcid":"https://orcid.org/0000-0002-0637-4471"},"institutions":[{"id":"https://openalex.org/I37796252","display_name":"Beijing University of Technology","ror":"https://ror.org/037b1pp87","country_code":"CN","type":"education","lineage":["https://openalex.org/I37796252"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yin Liu","raw_affiliation_strings":["College of Computer Science, Beijing University of Technology,Beijing,China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science, Beijing University of Technology,Beijing,China","institution_ids":["https://openalex.org/I37796252"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5085100368"],"corresponding_institution_ids":["https://openalex.org/I37796252"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.83231014,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.7922000288963318,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.7922000288963318,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.08529999852180481,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.03280000016093254,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/test","display_name":"Test (biology)","score":0.7343000173568726},{"id":"https://openalex.org/keywords/guard","display_name":"Guard (computer science)","score":0.7088000178337097},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.5936999917030334},{"id":"https://openalex.org/keywords/status-quo","display_name":"Status quo","score":0.5454999804496765},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.43939998745918274},{"id":"https://openalex.org/keywords/test-case","display_name":"Test case","score":0.32170000672340393},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.30230000615119934}],"concepts":[{"id":"https://openalex.org/C2777267654","wikidata":"https://www.wikidata.org/wiki/Q3519023","display_name":"Test (biology)","level":2,"score":0.7343000173568726},{"id":"https://openalex.org/C141141315","wikidata":"https://www.wikidata.org/wiki/Q2379942","display_name":"Guard (computer science)","level":2,"score":0.7088000178337097},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6366999745368958},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.5936999917030334},{"id":"https://openalex.org/C2776748549","wikidata":"https://www.wikidata.org/wiki/Q201610","display_name":"Status quo","level":2,"score":0.5454999804496765},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5246000289916992},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.43939998745918274},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.328000009059906},{"id":"https://openalex.org/C128942645","wikidata":"https://www.wikidata.org/wiki/Q1568346","display_name":"Test case","level":3,"score":0.32170000672340393},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3176000118255615},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.30230000615119934},{"id":"https://openalex.org/C2777298776","wikidata":"https://www.wikidata.org/wiki/Q164160","display_name":"Twilight","level":2,"score":0.2969000041484833},{"id":"https://openalex.org/C199519371","wikidata":"https://www.wikidata.org/wiki/Q942695","display_name":"Source lines of code","level":3,"score":0.29019999504089355},{"id":"https://openalex.org/C16910744","wikidata":"https://www.wikidata.org/wiki/Q7705759","display_name":"Test data","level":2,"score":0.289900004863739},{"id":"https://openalex.org/C165347436","wikidata":"https://www.wikidata.org/wiki/Q1514547","display_name":"Project commissioning","level":3,"score":0.27390000224113464},{"id":"https://openalex.org/C89505385","wikidata":"https://www.wikidata.org/wiki/Q47146","display_name":"User interface","level":2,"score":0.2648000121116638},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2646999955177307},{"id":"https://openalex.org/C151719136","wikidata":"https://www.wikidata.org/wiki/Q3972943","display_name":"Publishing","level":2,"score":0.26420000195503235},{"id":"https://openalex.org/C107284991","wikidata":"https://www.wikidata.org/wiki/Q79757","display_name":"Barometer","level":2,"score":0.25459998846054077}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cloudcom67567.2025.11331499","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cloudcom67567.2025.11331499","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 lEEE International Conference on Cloud Computing Technology and Science (CloudCom)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.45846882462501526,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G2527288406","display_name":null,"funder_award_id":"4232019","funder_id":"https://openalex.org/F4320322919","funder_display_name":"Natural Science Foundation of Beijing Municipality"}],"funders":[{"id":"https://openalex.org/F4320322919","display_name":"Natural Science Foundation of Beijing Municipality","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W2903166669","https://openalex.org/W3105893486","https://openalex.org/W3107583352","https://openalex.org/W3113852572","https://openalex.org/W3180257170","https://openalex.org/W4283688839","https://openalex.org/W4311165856","https://openalex.org/W4366087617","https://openalex.org/W4385412316","https://openalex.org/W4387298278","https://openalex.org/W4391724745","https://openalex.org/W4394768861","https://openalex.org/W4394769335","https://openalex.org/W4402263683","https://openalex.org/W4407857966","https://openalex.org/W4409074430"],"related_works":[],"abstract_inverted_index":{"The":[0],"Software":[1],"Guard":[2],"Extensions":[3],"(SGX)":[4],"is":[5,37,99],"a":[6,72,162,208,212,217,222],"Trusted":[7],"Execution":[8],"Environment":[9],"(TEE)":[10],"solution":[11],"that":[12,38,128,164],"has":[13],"transitioned":[14],"from":[15,147,156,190],"Intel's":[16,157],"processor":[17],"lineup":[18],"for":[19,33,115,255,262],"desktops":[20],"and":[21,44,84,113,169,173,196,216,234,246,267],"laptops":[22],"to":[23,26,48,93,239,272],"being":[24],"exclusive":[25],"cloud":[27,87,192,268],"servers.":[28],"We":[29],"believe":[30],"one":[31],"reason":[32],"this":[34,68,201],"forced":[35],"shift":[36],"SGX-based":[39,256],"applications":[40],"lack":[41],"comprehensive":[42],"testing":[43,64,232,275],"may":[45],"be":[46],"vulnerable":[47],"security":[49],"attacks.":[50],"Although":[51],"there":[52],"have":[53],"been":[54],"numerous":[55],"studies":[56],"on":[57,62,137,184,270],"SGX,":[58],"research":[59,96],"focused":[60],"specifically":[61],"SGX's":[63],"remains":[65],"limited.":[66],"In":[67],"paper,":[69],"we":[70,203,224],"take":[71],"first":[73],"step":[74],"in":[75,124,180,250],"studying":[76],"SGX-related":[77,143],"test":[78,80,82,106,111,122,144,153,209,213,253],"code,":[79],"scenarios,":[81],"oracles,":[83],"users'":[85,177],"SGX":[86,105,123,178,240],"practices.":[88],"Specifically,":[89],"our":[90,130],"study":[91,131],"seeks":[92],"answer":[94],"three":[95,205,226],"questions:":[97],"what":[98,108],"the":[100,104,110,125,134,181,197],"current":[101],"status":[102,135],"of":[103,142,229],"code?":[107],"are":[109],"scenarios":[112,154],"oracles":[114],"SGX?":[116],"how":[117,271],"do":[118],"users":[119],"utilize":[120],"or":[121],"cloud?":[126],"To":[127],"end,":[129],"(1)":[132],"analyzes":[133],"quo":[136],"over":[138],"9,000":[139],"valid":[140,186,252],"lines":[141],"code":[145,210],"extracted":[146],"real-world":[148],"projects,":[149,257],"(2)":[150],"develops":[151],"43":[152],"identified":[155,225],"official":[158],"documentation,":[159],"along":[160],"with":[161],"formalization":[163],"clearly":[165],"expresses":[166],"each":[167],"scenario":[168,214],"its":[170],"connected":[171],"oracle,":[172],"(3)":[174],"investigates":[175],"into":[176],"practices":[179],"cloud,":[182],"based":[183],"16":[185],"user":[187,218],"feedback":[188,219],"gathered":[189],"leading":[191],"vendors'":[193],"web":[194],"sites":[195],"StackExchange":[198],"network.":[199],"From":[200],"work,":[202],"established":[204],"corresponding":[206],"datasets:":[207],"set,":[211,215],"set.":[220],"As":[221],"result,":[223],"critical":[227],"pieces":[228],"guidance,":[230],"four":[231],"principles,":[233],"five":[235],"key":[236],"findings":[237],"related":[238],"testing.":[241],"These":[242],"insights":[243],"can":[244],"guide":[245],"inspire":[247],"software":[248],"testers":[249],"creating":[251],"cases":[254],"while":[258],"also":[259],"offering":[260],"suggestions":[261],"Intel,":[263],"other":[264],"TEE":[265],"vendors,":[266],"providers":[269],"improve":[273],"their":[274],"solutions.":[276]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2026-01-21T00:00:00"}
