Know Thy Neighbor: Cross-TEE Mutual Attestation

📅 2026-07-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing bidirectional remote attestation mechanisms across heterogeneous trusted execution environments (TEEs) require each TEE to deploy the attestation stacks of all other TEEs, resulting in high complexity and poor efficiency. This work proposes Hema, the first formally designed and verified generic cross-TEE mutual attestation protocol that enables efficient mutual recognition of trusted application instances across diverse TEEs such as Intel SGX and ARM TrustZone. By leveraging the hardware root of trust and native attestation primitives inherent to each TEE, Hema eliminates the redundant overhead of conventional approaches and achieves significant improvements in both security and performance. The protocol provides a scalable solution for secure collaboration among heterogeneous trusted components in cloud environments.
📝 Abstract
Cloud services are composed of multiple heterogeneous distributed components and instances that communicate with one another. This occurs both in applications and services running in traditional execution environments and in trusted applications (TAs) running in trusted execution environments (TEEs). TA instances use attestation before exchanging information to ensure all parties meet the expected security conditions. The straightforward solution to mutually attesting two TA instances that are willing to communicate is employing remote attestation mechanisms in both directions. This is typically the case when the two TA instances are running on TEEs of the same type. In order to support cross-TEE attestation, such an approach, that is, using remote attestation in both directions, would require each TEE type (e.g., SGX, TrustZone) to support the attestation software stack of all other TEE types with which it needs to interact. A dedicated cross-TEE mutual attestation solution has multiple benefits in terms of efficiency and security. This paper presents the Heterogeneous Mutual Attestation (Hema) protocol, a formally-verified protocol for the mutual attestation of TA instances running on the same TEE type or on different TEE types.
Problem

Research questions and friction points this paper is trying to address.

cross-TEE
mutual attestation
trusted execution environment
heterogeneous TEEs
secure communication
Innovation

Methods, ideas, or system contributions that make the work stand out.

cross-TEE
mutual attestation
trusted execution environment
Hema protocol
formal verification
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
D
Daniel Andrade
INESC-ID, Instituto Superior Técnico, Universidade de Lisboa
J
João N. Silva
INESC-ID, Instituto Superior Técnico, Universidade de Lisboa
M
Miguel P. Correia
INESC-ID, Instituto Superior Técnico, Universidade de Lisboa