NARRATOR: Secure and Practical State Continuity for Trusted Execution in the Cloud
Jianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian Zhang
摘要
Public cloud platforms have leveraged Trusted Execution Environment (TEE) technology to provide confidential computing services. However, TEE-protected applications still suffer from rollback or forking attacks, in which their states could be rolled back to a stale version or be forked into multiple versions, resulting in state continuity violations. Existing solutions against these attacks either rely on weak threat models based on centralized trust (e.g., trusted server) or suffer from large performance overheads (e.g., tens of state updates per second). In this paper, we propose Narrator, a secure and practical system, (1) that relies on a blockchain (i.e., decentralized trust) and TEEs, and ( 2 ) that provides high-performance state continuity protection like unlimited and fast state updates for applications in cloud TEEs. The intuition behind our design is simple. Our design uses the blockchain to initialize a distributed system of TEEs, laying down the decentralized trust base with a small interaction overhead, while the distributed system provides performant state continuity protection. Our distributed system adopts a customized version of the consistent broadcast protocol and leverages advanced techniques to make state updates processed with one round trip delay on average. We build a proof-of-concept of Narrator on Intel SGX (i.e., a representative design of TEEs) and do extensive experiments to evaluate its performance. Our evaluation results show that in a LAN environment with 5 nodes, Narrator can support about 6k state updates per second, meanwhile keeping the latency as low as 3 -8ms. The throughput is 30× larger than that in ROTE and 70× larger than using a TPM counter. CCS CONCEPTS • Security and privacy → Security in hardware.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Nimble: Rollback Protection for Confidential Cloud ServicesSebastian Angel, Aditya Basu, Weidong Cui, Trent Jaeger 等OSDI 2023 · 被引用 28 次
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou 等VLDB 2024 · 被引用 22 次
- Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted ComponentsShaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu 等VLDB 2026 · 被引用 8 次
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks 等SIGMOD 2026 · 被引用 6 次
- Elephants Do Not Forget: Differential Privacy with State Continuity for Privacy BudgetJiankai Jin, Chitchanok Chuengsatiansup, Toby Murray, Benjamin I. P. Rubinstein 等CCS 2024 · 被引用 4 次
它引用的顶会 Paper12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Strong and Efficient Cache Side-Channel Protection using Hardware Transactional MemoryDaniel Gruss, Julian Lettner, Felix Schuster, Olga Ohrimenko 等USENIX Security 2017 · 被引用 254 次
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar 等USENIX Security 2017 · 被引用 249 次
- Solidus: Confidential Distributed Ledger Transactions via PVORMEthan Cecchetti, Fan Zhang, Yan Ji, Ahmed E. Kosba 等CCS 2017 · 被引用 128 次
- Ariadne: A Minimal Approach to State ContinuityRaoul Strackx, Frank PiessensUSENIX Security 2016 · 被引用 107 次
相关 Paper
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- The Forking Way: When TEEs Meet ConsensusAnnika Wilde, Tim Niklas Gruel, Claudio Soriente, Ghassan KarameNDSS 2025
- Towards Formal Verification of State Continuity for Enclave ProgramsMohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang LinUSENIX Security 2021 · 被引用 18 次
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen 等VLDB 2026
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter 等CCS 2022 · 被引用 19 次
