NARRATOR: Secure and Practical State Continuity for Trusted Execution in the Cloud
Jianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian Zhang
Abstract
Public cloud platforms have leveraged Trusted Execution Environment (TEE) technology to provide confidential computing services. However, TEE-protected applications still suffer from rollback or forking attacks, in which their states could be rolled back to a stale version or be forked into multiple versions, resulting in state continuity violations. Existing solutions against these attacks either rely on weak threat models based on centralized trust (e.g., trusted server) or suffer from large performance overheads (e.g., tens of state updates per second). In this paper, we propose Narrator, a secure and practical system, (1) that relies on a blockchain (i.e., decentralized trust) and TEEs, and ( 2 ) that provides high-performance state continuity protection like unlimited and fast state updates for applications in cloud TEEs. The intuition behind our design is simple. Our design uses the blockchain to initialize a distributed system of TEEs, laying down the decentralized trust base with a small interaction overhead, while the distributed system provides performant state continuity protection. Our distributed system adopts a customized version of the consistent broadcast protocol and leverages advanced techniques to make state updates processed with one round trip delay on average. We build a proof-of-concept of Narrator on Intel SGX (i.e., a representative design of TEEs) and do extensive experiments to evaluate its performance. Our evaluation results show that in a LAN environment with 5 nodes, Narrator can support about 6k state updates per second, meanwhile keeping the latency as low as 3 -8ms. The throughput is 30× larger than that in ROTE and 70× larger than using a TPM counter. CCS CONCEPTS • Security and privacy → Security in hardware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9f0e7d60-2fe9-4ab1-9bef-3fee06f4265cCited by top-tier papers11
- Nimble: Rollback Protection for Confidential Cloud ServicesSebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger et al.OSDI 2023 · 28 citations
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou et al.VLDB 2024 · 22 citations
- Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted ComponentsShaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu et al.VLDB 2026 · 8 citations
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks et al.SIGMOD 2026 · 6 citations
- Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy BudgetJiankai Jin, Chitchanok Chuengsatiansup, Toby Murray, Benjamin I. P. Rubinstein et al.CCS 2024 · 4 citations
Builds on12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Strong and Efficient Cache Side-Channel Protection using Hardware Transactional MemoryDaniel Gruss, Julian Lettner, Felix Schuster, Olga Ohrimenko et al.USENIX Security 2017 · 254 citations
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- Solidus: Confidential Distributed Ledger Transactions via PVORMEthan Cecchetti, Fan Zhang, Yan Ji, Ahmed E. Kosba et al.CCS 2017 · 128 citations
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 107 citations
Related papers
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- The Forking Way: When TEEs Meet ConsensusAnnika Wilde, Tim Niklas Gruel, Claudio Soriente, Ghassan KarameNDSS 2025
- Towards Formal Verification of State Continuity for Enclave ProgramsMohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang LinUSENIX Security 2021 · 18 citations
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen et al.VLDB 2026
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter et al.CCS 2022 · 19 citations
