Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution Environments
Shubham Mishra, João Gonçalves, Chawinphat Tankuranand, Natacha Crooks, Neil Giridharan, Heidi Howard, Chris Jensen
Abstract
Distributed ledgers are increasingly relied upon by industry to provide trustworthy accountability, strong integrityprotection, and high availability for critical data without centralizing trust. Recently, distributed append-only logs are opting for a layered approach, combining crash-fault-tolerant (CFT) consensus with hardware-based Trusted Execution Environments (TEEs) for greater resiliency. Unfortunately, hardware TEEs can be subject to (rare) attacks, undermining the very guarantees that distributed ledgers are carefully designed to achieve. In response, we present Pirateship, a new distributed consensus protocol that cautiously trusts the guarantees of TEEs. Pirateship carefully embeds a Byzantine fault-tolerant (BFT) protocol inside of a CFT protocol with no additional messages. This is made possible through careful refactoring of both the CFT and BFT protocols such that their structure aligns. Pirateship achieves performance in line with regular TEE-enabled consensus protocols, while guaranteeing integrity in the face of TEE platform compromises.
• Security and privacy → Distributed systems security; • Computer systems organization → Dependable and fault-tolerant systems and networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5fe3174a-59a4-499b-9cc6-95bfed663dc1Builds on25
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Narwhal and Tusk: a DAG-based mempool and efficient BFT consensusGeorge Danezis, Lefteris Kokoris-Kogias, Alberto Sonnino, Alexander SpiegelmanEuroSys 2022 · 259 citations
- Bullshark: DAG BFT Protocols Made PracticalAlexander Spiegelman, Neil Giridharan, Alberto Sonnino, Lefteris Kokoris-KogiasCCS 2022 · 132 citations
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li et al.USENIX Security 2021 · 130 citations
- Flexible Byzantine Fault ToleranceDahlia Malkhi, Kartik Nayak, Ling RenCCS 2019 · 122 citations
Related papers
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter et al.CCS 2022 · 19 citations
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted ComponentsShaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu et al.VLDB 2026 · 8 citations
- IA-CCF: Individual Accountability for Permissioned LedgersAlex Shamis, Peter R. Pietzuch, Burcu Canakci, Miguel Castro et al.NSDI 2022 · 3 citations
- Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient RecoveryJianyu Niu, Xiaoqing Wen, Guanlong Wu, Shengqi Liu et al.EuroSys 2025 · 4 citations
