Token Weaver: Privacy Preserving and Post-Compromise Secure Attestation
Cas Cremers, Gal Horowitz, Charlie Jacomme, Eyal Ronen
Abstract
Modern attestation based on Trusted Execution Environments (TEEs) can significantly reduce the risk of secret compromise, allowing users to securely perform sensitive computations such as running cryptographic protocols for authentication across security critical services. However, this has made TEEs a high-value target, driving an arms race between novel compromise attacks and continuous TEEs updates. Ideally, we want to achieve Post-Compromise Security (PCS): even after a TEE compromise, we can update it back into a secure state. However, at the same time, we would like to guarantee the privacy of users, in particular preventing providers (such as Intel, Google, or Samsung) or services from tracking users across services. This requires unlinkability, which seems incompatible with standard PCS healing mechanisms. In this work, we develop TokenWeaver, the first privacy-preserving post-compromise secure attestation method with automated formal proofs for its core properties. Our construction weaves together two types of token chains, one of which is linkable and the other is unlinkable. We provide the formal models based on the Tamarin and DeepSec provers, including protocol, security properties, and proofs for reproducibility, as well as a proof-of-concept implementation in python that shows the simplicity and applicability of our solution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 3 citations
- 3PaaS: Privacy-Preserving Post-Compromise Security as a ServiceCas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal RonenCCS 2026
Builds on17
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp et al.S&P 2020 · 275 citations
Related papers
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng et al.NDSS 2026 · 2 citations
- The Forking Way: When TEEs Meet ConsensusAnnika Wilde, Tim Niklas Gruel, Claudio Soriente, Ghassan KarameNDSS 2025
- Attest the Whole, Verify Incrementally: Whole-Program Integrity via Lazy Verification in Trusted Execution EnvironmentsZhen Huang, Junhong Cheng, Yijia Ma, Guoxing Chen et al.CCS 2026
- Towards Formal Verification of State Continuity for Enclave ProgramsMohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang LinUSENIX Security 2021 · 18 citations
- 'They don't care about this': A Systematic Study of TEE Build Reproducibility in the WildAnnika Wilde, Marco Gutfleisch, Felix Reichmann, Anirban Chakraborty et al.CCS 2026
