Deterministic Client: Enforcing Determinism on Untrusted Machine Code
Zachary Yedidia, Geoffrey Ramseyer, David Mazières
Abstract
This paper presents Deterministic Client (DeCl), a softwarebased sandboxing system for enforcing deterministic behavior on untrusted machine code, either x86-64 or Arm64. DeCl adapts techniques from Software Fault Isolation (SFI) traditionally used to guarantee memory isolation to instead enforce the stronger property of determinism. By using a simple and efficient machine code verifier that can guarantee that a program behaves deterministically, DeCl does not rely on a trusted compiler/interpreter for correctness. This allows the use of LLVM without compromising the size of the trusted code base. We also describe how to implement two efficient metering mechanisms that enforce deterministic preemption of sandboxed programs, and how DeCl can be implemented in combination with traditional software-based isolation, by making the sandboxed code position-oblivious. DeCl is able to combine and improve upon the benefits of both interpreters and JIT compilers at once, with low CPU overhead, fast startup time, and strong security via a small trusted code base. We evaluate DeCl's effectiveness on general-purpose CPU benchmarks, as well as in an application-specific context by integrating with the Groundhog smart contract engine, and using DeCl for zero-knowledge-proof verification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Remora: Scale-out Deterministic Execution for Smart ContractsZhengqing Liu, Alberto Sonnino, Igor Zablotchi, Eleftherios Kokoris-Kogias et al.VLDB 2026 · 1 citation
- Fix: externalizing network I/O in serverless computingYuhan Deng, Akshay Srivatsan, Sebastian Ingino, Francis Chua et al.EuroSys 2026
Builds on9
- A Transactional Perspective on Execute-order-validate BlockchainsPingcheng Ruan, Dumitrel Loghin, Quang-Trung Ta, Meihui Zhang et al.SIGMOD 2020 · 117 citations
- Block-STM: Scaling Blockchain Execution by Turning Ordering Curse to a Performance BlessingRati Gelashvili, Alexander Spiegelman, Zhuolun Xiang, George Danezis et al.PPoPP 2023 · 49 citations
- Handling Highly Contended OLTP Workloads Using Fast Dynamic PartitioningGuna Prasaad, Alvin Cheung, Dan SuciuSIGMOD 2020 · 34 citations
- Forerunner: Constraint-based Speculative Transaction Execution for EthereumYang Chen, Zhongxin Guo, Runhuai Li, Shuo Chen et al.SOSP 2021 · 18 citations
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 17 citations
Related papers
- Isolation without taxation: near-zero-cost transitions for WebAssembly and SFIMatthew Kolosick, Shravan Narayan, Evan Johnson, Conrad Watt et al.POPL 2022 · 14 citations
- Provably-Safe Multilingual Software Sandboxing using WebAssemblyJay Bosamiya, Wen Shih Lim, Bryan ParnoUSENIX Security 2022
- The high-level benefits of low-level sandboxingMichael Sammler, Deepak Garg, Derek Dreyer, Tadeusz LitakPOPL 2020 · 26 citations
- TRust: A Compilation Framework for In-process Isolation to Protect Safe Rust against Untrusted CodeInyoung Bang, Martin Kayondo, Hyungon Moon, Yunheung PaekUSENIX Security 2023
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek et al.ASPLOS 2023 · 27 citations
