PRA-TLS: Attestation of a Client Application for TEE

πŸ“… 2026-10-05
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the risk of tampering by untrusted applications at Trusted Execution Environment (TEE) interaction boundaries by proposing the PRA-TLS protocol. For the first time, this work extends remote attestation to the client application layer, employing a customized Attester Daemon to perform runtime measurements of both host and application states. This approach establishes an end-to-end chain of trust, ensuring that only legitimate environments can invoke enclaves. A prototype implementation is developed using Intel SGX, accompanied by comprehensive performance evaluations. Furthermore, the protocol’s security properties are formally verified using the Tamarin Prover. The results demonstrate that the proposed scheme achieves rigorous security guarantees and effectively defends against input and output tampering attacks.
πŸ“ Abstract
Trusted Execution Environments (TEEs) are secure foundations for protecting sensitive information and executing computations over confidential data. Processing in an isolated execution environment (enclave) is invoked by an untrusted application in the Rich Execution Environment (REE). Then the enclave returns the execution results to the untrusted application. Even if the enclave has been attested, the boundary between the enclave and the untrusted application poses risks, such as tampering with input arguments or return values and manipulating the order in which the application invokes functions. Therefore, it is necessary to establish the authenticity and integrity of not only the enclave itself but also the application and its execution environment. In this study, we propose an attestation protocol, Portable Remote Attestation TLS (PRA-TLS), for a client application that invokes an enclave. We introduce a daemon that acts as an attester. PRA-TLS uses a trusted Attester Daemon to measure the state of the host environment and application code at runtime, providing these measurements as attestation evidence for verification by a remote Verifier. This mechanism allows the enclave to proceed only when the software environment is in the expected state and the application code is verified as legitimate. We define attack models and security requirements for the proposed protocol and formally evaluate its security using the Tamarin Prover. Furthermore, we implement a prototype of PRA-TLS using Intel SGX and evaluate its performance.
Problem

Research questions and friction points this paper is trying to address.

Trusted Execution Environment
Remote Attestation
Client Application Integrity
Enclave Security
Rich Execution Environment
Innovation

Methods, ideas, or system contributions that make the work stand out.

Remote Attestation
Trusted Execution Environment
TLS Protocol
Formal Verification
Intel SGX
πŸ”Ž Similar Papers
No similar papers found.