It's a Feature, Not a Bug: Secure and Auditable State Rollback for Confidential Cloud Applications
Quinn Burke, Anjo Vahldiek-Oberwagner, Michael Swift, Patrick D. McDaniel
Abstract
Replay and rollback attacks threaten cloud application integrity by reintroducing authentic yet stale data through an untrusted storage interface to compromise application decision-making. Prior security frameworks mitigate these attacks by enforcing forward-only state transitions (state continuity) with hardware-backed mechanisms, but they categorically treat all rollback as malicious and thus preclude legitimate rollbacks used for operational recovery from corruption or misconfiguration. We present Rebound, a general-purpose security framework that preserves rollback protection while enabling policy-authorized legitimate rollbacks of application binaries, configuration, and data. Key to Rebound is a reference monitor that mediates state transitions, enforces authorization policy, guarantees atomicity of state updates and rollbacks, and emits a tamper-evident log that provides transparency to applications and auditors. We analyze Rebound's security properties and show through an application case study -- with software deployment workflows in GitLab CI -- that it enables robust control over binary, configuration, and raw data versioning with low end-to-end overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 94de0f60-ad5b-4ee3-823b-a4060a6140e0Builds on14
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- Runtime Analysis of Whole-System ProvenanceThomas F. J.-M. Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates et al.CCS 2018 · 112 citations
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 107 citations
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola et al.USENIX Security 2019 · 98 citations
- HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit DeviceAdil Ahmad, Sangho Lee, Marcus PeinadoS&P 2022 · 46 citations
Related papers
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks et al.SIGMOD 2026 · 6 citations
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen et al.VLDB 2026
- Vive la Différence: Practical Diff Testing of Stateful ApplicationsKexin Zhu, Michael Whittaker, Srdjan Petrovic, Robert Grandl et al.VLDB 2025 · 1 citation
- Forensic Analysis in Access Control: Foundations and a Case-Study from PracticeNahid Juma, Xiaowei Huang, Mahesh TripunitaraCCS 2020 · 2 citations
- Nimble: Rollback Protection for Confidential Cloud ServicesSebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger et al.OSDI 2023 · 28 citations
