USENIX Security2026Top-tier venue
Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKs
Zhongjing Wei, Osaid Muhammad Ameer, Yupeng Zhang, Nikita Borisov
Abstract
Modernizing the security of operational technology systems that control critical infrastructure has become a pressing challenge. Because edge devices have limited capabilities, modernization has relied on application gateways that interface with identity management systems and enforce access policies. These gateways are powerful enough to perform complex authorization decisions and support zero-trust architectures but create major deployment and management burdens: they must be collocated with remote, distributed edge devices, kept up to date with security patches, and managed with minimal downtime.
We propose Provable Remote Execution of Zero-Trust Authorization (PREZTA), an architecture that eliminates these gateways by evaluating policies within a zero-knowledge virtual machine (zkVM) running on the client. The zkVM produces a succinct proof of authorization that edge devices can verify efficiently, extending the zero-trust security envelope to the edge. Policies and identity management schemes can evolve without updating edge devices.
To demonstrate the feasibility of PREZTA, we implement a prototype, built using the RISC Zero zkVM, that supports XACML 3.0 policies and JWT identity claims. While zkVMs introduce substantial proof overhead, we mitigate this by compiling policies to Rust code and pre-compiling regular expressions. Combined with optimized signature verification and JWT parsing, these measures reduce prover time by more than an order of magnitude. Our compiler correctly implements 83% of the XACML 3.0 conformance suite, with proof generation completing in tens of seconds on a desktop. Verification, by contrast, takes only tens of milliseconds-fast enough for even resource-constrained edge devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dd289b7f-0166-4784-b62c-bc6f62c42877Builds on12
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- The SPHINCS+ Signature FrameworkDaniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen et al.CCS 2019 · 385 citations
- xJsnark: A Framework for Efficient Verifiable ComputationAhmed E. Kosba, Charalampos Papamanthou, Elaine ShiS&P 2018 · 121 citations
- zkLogin: Privacy-Preserving Blockchain Authentication with Existing CredentialsFoteini Baldimtsi, Konstantinos Kryptos Chalkias, Yan Ji, Jonas Lindstrøm et al.CCS 2024 · 21 citations
- Reef: Fast Succinct Non-Interactive Zero-Knowledge Regex ProofsSebastian Angel, Eleftherios Ioannidis, Elizabeth Margolin, Srinath T. V. Setty et al.USENIX Security 2024 · 12 citations
Related papers
- Evaluating Compiler Optimization Impacts on zkVM PerformanceThomas Gassmann, Stefanos Chaliasos, Thodoris Sotiropoulos, Zhendong SuASPLOS 2026 · 2 citations
- C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareTigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg et al.CCS 2016 · 311 citations
- Zombie: Middleboxes that Don't SnoopCollin Zhang, Zachary DeStefano, Arasu Arun, Joseph Bonneau et al.NSDI 2024 · 26 citations
- Arguzz: Testing zkVMs for Soundness and Completeness BugsChristoph Hochrainer, Valentin Wüstholz, Maria ChristakisUSENIX Security 2026 · 2 citations
- OAT: Attesting Operation Integrity of Embedded DevicesZhichuang Sun, Bo Feng, Long Lu, Somesh JhaS&P 2020 · 89 citations
