USENIX Security2024Top-tier venue
ACAI: Protecting Accelerator Execution with Arm Confidential Computing Architecture
Supraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne, Fabio Aliberti, Shweta Shinde
Abstract
Trusted execution environments in several existing and upcoming CPUs demonstrate the success of confidential computing, with the caveat that tenants cannot securely use accelerators such as GPUs and FPGAs. In this paper, we reconsider the Arm Confidential Computing Architecture (CCA) design, an upcoming TEE feature in Armv9-A, to address this gap. We observe that CCA offers the right abstraction and mechanisms to allow confidential VMs to use accelerators as a first-class abstraction. We build ACAI, a CCA-based solution, with a principled approach of extending CCA security invariants to device-side access to address several critical security gaps. Our experimental results on GPU and FPGA demonstrate the feasibility of ACAI while maintaining security guarantees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ba1a87d0-3a45-433e-bd5b-af65eb964334Cited by top-tier papers9
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng et al.NDSS 2026 · 2 citations
- SCRUTINIZER: Towards Secure Forensics on Compromised TrustZoneYiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou et al.NDSS 2025
- ASGARD: Protecting On-Device Deep Neural Networks with Virtualization-Based Trusted Execution EnvironmentsMyungsuk Moon, Minhee Kim, Joonkyo Jung, Dokyung SongNDSS 2025
- Understanding the Security Boundary of Obfuscation-based On-Device LLM ProtectionHanyi Zhou, Chenyang Li, Yuanzhe Pang, Ke Xu et al.CCS 2026
- MOLE: Breaking GPU TEE with GPU-Embedded MCUHongyi Lu, Yunjie Deng, J. Sukarno Mertoguno, Shuai Wang et al.CCS 2025
Builds on15
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- SANCTUARY: ARMing TrustZone with User-space EnclavesFerdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi et al.NDSS 2019 · 191 citations
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig et al.USENIX Security 2021 · 150 citations
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
Related papers
- CAGE: Complementing Arm CCA with GPU ExtensionsChenxu Wang, Fengwei Zhang, Yunjie Deng, Kevin Leach et al.NDSS 2024
- Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution EnvironmentJianping Zhu, Rui Hou, XiaoFeng Wang, Wenhao Wang et al.S&P 2020 · 95 citations
- StrongBox: A GPU TEE on Arm EndpointsYunjie Deng, Chenxu Wang, Shunchang Yu, Shiqing Liu et al.CCS 2022 · 37 citations
- FPGA-TrustZone: Security Extension of TrustZone to FPGA for SoC-FPGA Heterogeneous ArchitectureShupeng Wang, Xindong Fan, Xiao Xu, Shuchen Wang et al.DAC 2025 · 1 citation
- AccShield: a New Trusted Execution Environment with Machine-Learning AcceleratorsWei Ren, William Kozlowski, Sandhya Koteshwara, Mengmei Ye et al.DAC 2023 · 11 citations
