HarborMaster: Rollback Detection for Trusted Distributed Computing
Shubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen, Natacha Crooks, John Kubiatowicz
Abstract
Trusted Execution Environments (TEEs) provide strong confidentiality and integrity guarantees to distributed data processing. Developers are increasingly using clusters of TEE-enabled workers for these applications. However, TEEs do not protect persistent state: a rollback attack may replace the current persistent state with a stale version. Conventional rollback detection systems interfere with the application's steady-state performance either by adding high coordination overhead or log amplification. Our key insight is Rollback attacks violate causality. Rollback attacks can be efficiently detected by causal logging, avoiding the coordination and log amplification overheads of prior solutions. We build HarborMaster, a high-performance rollback detection system for the TEE-based distributed computing clusters. HarborMaster offloads the job of rollback detection to a specialized auditing service that efficiently checks for rollback attacks using violations of causality in the TEE-based distributed computing workers. Running in AMD SEV-SNP Confidential VMs, HarborMaster only imposes 8–35% logging overhead and preserves the linear scaling properties of an unprotected distributed application.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bce12aff-414c-4d2c-8e4a-7a1e7472e115Builds on17
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 107 citations
- CacheWarp: Software-based Fault Injection using Selective State ResetRuiyi Zhang, Lukas Gerlach, Daniel Weber, Lorenz Hetterich et al.USENIX Security 2024 · 36 citations
- Clonos: Consistent Causal Recovery for Highly-Available Streaming DataflowsPedro F. Silvestre, Marios Fragkoulis, Diomidis Spinellis, Asterios KatsifodimosSIGMOD 2021 · 24 citations
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou et al.VLDB 2024 · 22 citations
Related papers
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks et al.SIGMOD 2026 · 6 citations
- Nimble: Rollback Protection for Confidential Cloud ServicesSebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger et al.OSDI 2023 · 28 citations
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
- NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudJianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian ZhangCCS 2022 · 21 citations
