Lune

SOSP2026Top-tier venue

Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution Environments

Shubham Mishra, João Gonçalves, Chawinphat Tankuranand, Natacha Crooks, Neil Giridharan, Heidi Howard, Chris Jensen

2026Year

Abstract

Distributed ledgers are increasingly relied upon by industry to provide trustworthy accountability, strong integrityprotection, and high availability for critical data without centralizing trust. Recently, distributed append-only logs are opting for a layered approach, combining crash-fault-tolerant (CFT) consensus with hardware-based Trusted Execution Environments (TEEs) for greater resiliency. Unfortunately, hardware TEEs can be subject to (rare) attacks, undermining the very guarantees that distributed ledgers are carefully designed to achieve. In response, we present Pirateship, a new distributed consensus protocol that cautiously trusts the guarantees of TEEs. Pirateship carefully embeds a Byzantine fault-tolerant (BFT) protocol inside of a CFT protocol with no additional messages. This is made possible through careful refactoring of both the CFT and BFT protocols such that their structure aligns. Pirateship achieves performance in line with regular TEE-enabled consensus protocols, while guaranteeing integrity in the face of TEE platform compromises.

• Security and privacy → Distributed systems security; • Computer systems organization → Dependable and fault-tolerant systems and networks.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 5fe3174a-59a4-499b-9cc6-95bfed663dc1

Builds on25

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines