RR: A Fault Model for Efficient TEE Replication
Baltasar Dinis, Peter Druschel, Rodrigo Rodrigues
摘要
—Trusted Execution Environments (TEEs) ensure the confidentiality and integrity of computations in hardware. Subject to the TEE’s threat model, the hardware shields a computation from most externally induced fault behavior except crashes. As a result, a crash-fault tolerant (CFT) replication protocol should be sufficient when replicating trusted code inside TEEs. However, TEEs do not provide efficient and general means of ensuring the freshness of external, persistent state. Therefore, CFT replication is insufficient for TEE computations with external state, as this state could be rolled back to an earlier version when a TEE restarts. Furthermore, using BFT protocols in this setting is too conservative, because these protocols are designed to tolerate arbitrary behavior, not just rollback during a restart. In this paper, we propose the restart-rollback (RR) fault model for replicating TEEs, which precisely captures the possible fault behaviors of TEEs with external state. Then, we show that existing replication protocols can be easily adapted to this fault model with few changes, while retaining their original performance. We adapted two widely used crash fault tolerant protocols — the ABD [6] read/write register protocol and the Paxos [34] consensus protocol — to the RR model. Furthermore, we leverage these protocols to build a replicated metadata service called TEEMS , and then show that it can be used to add TEE-grade confidentiality, integrity, and freshness to untrusted cloud storage services. Our evaluation shows that our protocols perform significantly better than their BFT counterparts (between 1 . 25 and 55 × better throughput), while performing identically to the CFT versions, which do not protect against rollback attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Nimble: Rollback Protection for Confidential Cloud ServicesSebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger 等OSDI 2023 · 被引用 28 次
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman 等OSDI 2024 · 被引用 19 次
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks 等SIGMOD 2026 · 被引用 6 次
- Pallas and Aegis: Rollback Resilience in TEE-Aided Blockchain ConsensusJérémie Decouchant, David Kozhaya, Vincent Rahli, Jiangshan YuNDSS 2026 · 被引用 1 次
- TriHaRd: Higher Resilience for TEE Trusted TimeMatthieu Bettinger, Sonia Ben Mokhtar, Pascal Felber, Etienne Rivière 等INFOCOM 2026
它引用的顶会 Paper4
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar 等USENIX Security 2017 · 被引用 249 次
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 被引用 107 次
- Avocado: A Secure In-Memory Distributed Storage SystemMaurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc 等USENIX ATC 2021 · 被引用 39 次
- Gryff: Unifying Consensus and Shared RegistersMatthew Burke, Audrey Cheng, Wyatt LloydNSDI 2020 · 被引用 29 次
相关 Paper
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter 等CCS 2022 · 被引用 19 次
- NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudJianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian ZhangCCS 2022 · 被引用 21 次
- Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient RecoveryJianyu Niu, Xiaoqing Wen, Guanlong Wu, Shengqi Liu 等EuroSys 2025 · 被引用 4 次
- Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution EnvironmentsShubham Mishra, João Gonçalves, Chawinphat Tankuranand, Natacha Crooks 等SOSP 2026
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen 等VLDB 2026
