Nimble: Rollback Protection for Confidential Cloud Services
Sebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger, Stella Lau, Srinath T. V. Setty, Sudheesh Singanamalla
Abstract
This paper introduces Nimble, a cloud service that helps applications running in trusted execution environments (TEEs) to detect rollback attacks (i.e., detect whether a data item retrieved from persistent storage is the latest version). To achieve this, Nimble realizes an append-only ledger service by employing a simple state machine running in a TEE in conjunction with a crash fault-tolerant storage service. Nimble then replicates this trusted state machine to ensure the system is available even if a minority of state machines crash. A salient aspect of Nimble is a new reconfiguration protocol that allows a cloud provider to replace the set of nodes running the trusted state machine whenever it wishes-without affecting safety. We have formally verified Nimble's core protocol in Dafny, and have implemented Nimble such that its trusted state machine runs in multiple TEE platforms (Intel SGX and AMD SNP-SEV). Our results show that a deployment of Nimble on machines running in different availability zones can achieve from tens of thousands of requests/sec with an end-to-end latency of under 3.2 ms (based on an in-memory key-value store) to several thousands of requests/sec with a latency of 30ms (based on Azure Table).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dce75a77-2c40-4d52-8868-2655a62e288aCited by top-tier papers16
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou et al.VLDB 2024 · 22 citations
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman et al.OSDI 2024 · 19 citations
- Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted ComponentsShaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu et al.VLDB 2026 · 8 citations
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks et al.SIGMOD 2026 · 6 citations
- Flock: A Framework for Deploying On-Demand Distributed TrustDarya Kaviani, Sijun Tan, Pravein Govindan Kannan, Raluca Ada PopaOSDI 2024 · 5 citations
Builds on16
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
Related papers
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudJianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian ZhangCCS 2022 · 21 citations
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen et al.VLDB 2026
- Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient RecoveryJianyu Niu, Xiaoqing Wen, Guanlong Wu, Shengqi Liu et al.EuroSys 2025 · 4 citations
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
