IP Library Granted Patent US 12,493,685
Granted Patent B2
US 12,493,685 · App. 17/689,988 · Granted Dec 9, 2025

Method and apparatus for testing a device under test

Inventors: Fabiano Anemone (Stuttgart, DE); Alexei Karpov (Stuttgart, DE); Cederic Laumen (Stuttgart, DE); Stefan Rabin (Stuttgart, DE); Geoffrey Van Den Berge (Stuttgart, DE); Simon Gillet (Stuttgart, DE)
Assignee: SONY GROUP CORPORATION
G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,685
App. No.
17/689,988
Granted
Dec 9, 2025
Kind
B2
Abstract

A method for testing a Device Under Test (DUT) is provided. The method includes emulating a Trusted Execution Environment (TEE) of the DUT by means of a software emulator in order to provide an emulated TEE. The method further comprises intercepting at the DUT a call from a Rich Execution Environment (REE) of the DUT into the TEE of the DUT. In addition, the method includes transmitting the call to the emulated TEE such that the call is processed by the emulated TEE. The method includes transmitting a response of the emulated TEE to the REE. The response is based on the call.

Claims (52)

1 . A method for testing a Device Under Test (DUT), the method comprising:

emulating a Trusted Execution Environment (TEE) of the DUT by means of a software emulator running on a device separate from the DUT in order to provide an emulated TEE;

intercepting, at the DUT, a call from a Rich Execution Environment (REE) of the DUT directed to and intended for the TEE of the DUT, the intercepting including augmenting a behavior of an OS, of one or more applications, of one or more functions, of one or more routines, or of another software component of the REE;

redirecting the call from the DUT to the emulated TEE running on the device separate from the DUT such that the call is processed by the emulated TEE; and

transmitting a response of the emulated TEE from the device separate from the DUT to the REE of the DUT, the response being based on the call.

2 . The method of claim 1 , wherein the emulated TEE running on the device separate from the DUT is based on extracted code of the TEE.

3 . The method of claim 2 , wherein the extracted code of the TEE is compiled code.

4 . The method of claim 1 , wherein the call is intercepted at the DUT by hooking.

5 . The method of claim 1 , wherein redirecting the call from the DUT to the emulated TEE running on the device separate from the DUT comprises:

receiving the call from the REE;

parsing the call in order to obtain input data in a predefined data format for the emulated TEE running on the device separate from the DUT; and

sending the input data to the emulated TEE running on the device separate from the DUT.

6 . The method of claim 5 , wherein redirecting the call from the DUT to the emulated TEE running on the device separate from the DUT further comprises:

packing the input data prior to sending the input data to the emulated TEE.

7 . The method of claim 1 , wherein transmitting the response of the emulated TEE from the device separate from the DUT to the REE of the DUT comprises:

receiving, from the emulated TEE running on the device separate from the DUT, output data related to the response in a predefined data format;

parsing the output data in order to obtain the response in a data format used by the REE; and

sending the response in the data format used by the REE to the REE.

8 . The method of claim 7 , wherein

the output data received from the emulated TEE running on the device separate from the DUT is packed, and

transmitting the response of the emulated TEE from the device separate from the DUT to the REE of the DUT further comprises:

unpacking the output data prior to parsing the output data.

9 . The method of claim 1 , wherein

the emulated TEE running on the device separate from the DUT emulates hardware of the TEE, and

the method further comprises:

monitoring a state of at least part of the emulated hardware of the TEE while the call is processed by the emulated TEE running on the device separate from the DUT.

10 . The method of claim 1 , wherein

the emulated TEE running on the device separate from the DUT emulates code of the TEE, and

the method further comprises:

modifying the emulated code of the TEE based on a user input such that the response is generated by processing the call with the modified emulated code; and

monitoring a state of the DUT in response to receiving the response of the emulated TEE running on the device separate from the DUT.

11 . The method of claim 10 , wherein modifying the emulated code of the TEE comprises hooking one or more functions of the emulated code.

12 . The method of claim 10 , wherein modifying the emulated code of the TEE comprises debugging the emulated code.

13 . The method of claim 10 , wherein modifying the emulated code of the TEE comprises introducing an artificial error into the emulated code of the TEE.

14 . A non-transitory machine-readable medium having stored thereon a program having a program code for performing the method according to claim 1 when the program is executed on a processor or a programmable hardware.

15 . An apparatus for testing a Device Under Test (DUT), the apparatus comprising:

interface circuitry that is separate from the DUT and that is for coupling to the DUT; and

processing circuitry that separate from the DUT, that is coupled to the interface circuitry, and that is configured to:

execute a software emulator for emulating a Trusted Execution Environment (TEE) of the DUT in order to provide an emulated TEE;

receive, via the interface circuitry, a call from a Rich Execution Environment (REE) of the DUT directed to and intended for the TEE of the DUT, the call having been intercepted at the DUT and redirected from the DUT to the interface circuitry, and the interception including augmenting a behavior of an OS, of one or more applications, of one or more functions, of one or more routines, or of another software component of the REE;

process the intercepted and redirected call by the emulated TEE; and

control the interface circuitry to transmit a response of the emulated TEE to the REE of the DUT, the response being based on the intercepted call.

16 . The apparatus of claim 15 , wherein the emulated TEE is based on extracted code of the TEE.

17 . The apparatus of claim 15 , wherein the call is intercepted at the DUT by hooking.

18 . The apparatus of claim 15 , wherein

the emulated TEE emulates hardware of the TEE, and

the processing circuitry is further configured to:

monitor a state of at least part of the emulated hardware of the TEE while the call is processed by the emulated TEE.

19 . The apparatus of claim 15 , wherein

the emulated TEE emulates code of the TEE, and

the processing circuitry is further configured to:

modify the emulated code of the TEE based on a user input such that the response is generated by processing the call with the modified emulated code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: ANEMONE, FABIANO; KARPOV, ALEXEI; LAUMEN, CEDERIC; RABIN, STEFAN; VAN DEN BERGE, GEOFFREY; GILLET, SIMON
To: SONY GROUP CORPORATION
Reel/Frame 059475/0757 →
Priority Claims (1)
EP 21162788 · Mar 16, 2021 · regional
Continuity (1)
Related Publication 20220300604A1 · Sep 22, 2022
References Cited (36)
US 7707019B1 · Ballagh · 2010 [cited by examiner]
US 8060876B2 · Smith · 2011 [cited by examiner]
US 9768893B1 · Wank · 2017 [cited by examiner]
US 10534906B1 · Paithane et al. · 2020 [cited by applicant]
US 10791459B1 · Hu · 2020 [cited by examiner]
US 11226370B1 · Mendelson · 2022 [cited by examiner]
US 20030105606A1 · Poley · 2003 [cited by examiner]
US 20040072591A1 · Andreini · 2004 [cited by examiner]
US 20050131671A1 · Kashyap · 2005 [cited by examiner]
US 20050138370A1 · Goud · 2005 [cited by examiner]
US 20090165117A1 · Brutch · 2009 [cited by examiner]
US 20090169020A1 · Sakthikumar · 2009 [cited by examiner]
US 20100082315A1 · Hall · 2010 [cited by examiner]
US 20110320816A1 · Yao · 2011 [cited by examiner]
US 20120108294A1 · Kaul · 2012 [cited by examiner]
US 20130155083A1 · McKenzie · 2013 [cited by examiner]
US 20130219508A1 · Lee et al. · 2013 [cited by applicant]
US 20170024500A1 · Sebastian · 2017 [cited by examiner]
US 20170277891A1 · Keppler · 2017 [cited by examiner]
US 20180082065A1 · Liu · 2018 [cited by examiner]
US 20180203713A1 · Elfering · 2018 [cited by examiner]
US 20180225446A1 · Liu et al. · 2018 [cited by applicant]
US 20180330081A1 · Hua · 2018 [cited by examiner]
US 20190087245A1 · Yamaura · 2019 [cited by applicant]
US 20190108116A1 · Benes · 2019 [cited by examiner]
US 20200143041A1 · Jung · 2020 [cited by examiner]
US 20200183903A1 · Wilkinson · 2020 [cited by examiner]
US 20200366653A1 · Caceres · 2020 [cited by examiner]
US 20210157712A1 · Kalbac · 2021 [cited by examiner]
US 20230115278A1 · Turner · 2023 [cited by examiner]
CN 110008125A · 2019 [cited by examiner]
KR 101595064B1 · 2016 [cited by applicant]
Paithane et al., “Detection Efficacy of Virtual Machine-based Analysis with Application Specific Events”, Retrieved on: Dec. 29, 2020, 2 pages. [cited by applicant]
Lee et al., “Method and Apparatus for Outputting Content in Portable Terminal Supporting Secure Execution Environment”, Retrieved on: Dec. 29, 2020, 1 page. [cited by applicant]
Yamaura, “Notification Control Device, Notification Control Method, and Computer Program Product”, Retrieved on: Dec. 29, 2020, 2 pages. [cited by applicant]
Liu et al., “Processor Trace-Based Enforcement of Control Flow Integrity of a Computer System”, Retrieved on: Dec. 29, 2020, 2 pages. [cited by applicant]