Score
Designs, builds, and analyzes attestation protocols and implementations that let a remote verifier cryptographically assess and verify a target platform’s identity and runtime or persistent state, including secure attestation anchored in trusted hardware (TPM/TEE), and module-specific flows such as vsim attestation. Integrates those protocols into provisioning and onboarding flows, specifying message formats, key management and privacy-preserving measures to prevent replay, spoofing, or unwanted linkability while producing verifiable device-state proofs.
Existing remote attestation mechanisms suffer from limited coverage and are vulnerable to manipulation by powerful adversaries, potentially misleading relying parties. This work proposes a hierarchical attestation architecture that incrementally gathers evidence from critical system components while enforcing architectural constraints to ensure that only trusted components influence the trust decision, thereby achieving end-to-end resilience against strong adversaries. Leveraging TPM, Linux/SELinux, and AMD SEV-SNP, we present the first structured and scalable remote attestation framework on commodity hardware and software platforms. Experimental evaluation demonstrates the scheme’s effectiveness under both standard and enhanced adversary models, with a performance overhead of only approximately 1.3%. Furthermore, our analysis identifies two key improvement pathways to address more sophisticated attacks.
Current CVM threat models exhibit a critical disconnect from real-world deployments: their remote attestation mechanisms are not bound to specific cloud providers, preventing users from verifying whether trusted execution environments (TEEs) operate on physically trusted infrastructure. Consequently, physical attack risks remain unquantifiable, and end-to-end security guarantees cannot be established. This paper identifies and systematically analyzes this fundamental flaw for the first time. We propose a cross-vendor verifiable attestation extension framework grounded in the Protected Platform Identifier (PPID), which abstracts and standardizes attestation workflows and interfaces to anchor trust at the physical layer. Our portable verification framework supports major TEE platforms—including Intel TDX and AMD SEV-SNP—significantly enhancing the assessability of physical attack risks and deployment trustworthiness for external users. It further enables decentralized attestation and facilitates secure cross-cloud workload migration.
Hardware-secured remote attestation is essential to establishing trust in the integrity of confidential virtual machines (cVMs), but is difficult to use in practice because verifying attestation evidence requires the use of hardware-specific cryptographic logic. This increases both maintenance costs and the verifiers'trusted computing base. We introduce the concept of self-verifying remote attestation evidence. Each attestation bundle includes verification logic as a WebAssembly component signed by a trusted party. This approach transforms evidence verification into a standard code-signing problem: the verifier checks the signature on the embedded logic and then executes it to validate the evidence. As a result, verifiers can validate attestation evidence without any platform-specific knowledge. We implement this concept as TrustMee, a platform-agnostic verification driver for the Trustee framework. We demonstrate its functionality with self-verifying evidence for AMD SEV-SNP and Intel TDX attestations, producing attestation claims in the standard EAT Attestation Result (EAR) format.
This work addresses the challenge of ensuring availability and tamper resistance in evidence-collection infrastructures for continuous physical processes—such as authorship verification—even when the prover controls the environment. We propose the first continuous-process attestation architecture based on Trusted Execution Environments (TEEs), which leverages hardware isolation to defend against “trust inversion” attacks. The design includes a resilient evidence-chain protocol to handle TEE crashes, network partitions, and enclave migration, along with a tiered input assurance mechanism (Tier 1–3) and fast sealed-state recovery. Our implementation on Intel SGX demonstrates that per-checkpoint CPU overhead remains below 25% (under 0.3% at 30-second intervals), Monte Carlo simulations show evidence-chain availability exceeding 99.5%, and state recovery completes in under 200 milliseconds.
Existing remote attestation mechanisms cannot verify whether confidential virtual machines (CVMs) execute on physically trusted TEE platforms, causing CVM deployment to diverge from established TEE threat models (e.g., Intel TDX). This work proposes Datacenter Execution Assurance (DCEA), the first framework to tightly bind vTPM-anchored measurements to physical platform identity, enabling unified verification of CVM boot evidence and chassis-level hardware identity. DCEA integrates vTPM, discrete TPM, Intel TDX, and TXT within a cloud provider–controlled software stack to establish an end-to-end trusted boot and remote attestation pipeline, effectively mitigating replay and proxy attacks. We implement and evaluate DCEA on Google Cloud with Intel TDX, demonstrating verifiable proofs of both CVM physical provenance and runtime integrity. DCEA delivers the first deployment solution for high-assurance confidential computing in low-trust environments that fully aligns with TEE threat models.
Existing bidirectional remote attestation mechanisms across heterogeneous trusted execution environments (TEEs) require each TEE to deploy the attestation stacks of all other TEEs, resulting in high complexity and poor efficiency. This work proposes Hema, the first formally designed and verified generic cross-TEE mutual attestation protocol that enables efficient mutual recognition of trusted application instances across diverse TEEs such as Intel SGX and ARM TrustZone. By leveraging the hardware root of trust and native attestation primitives inherent to each TEE, Hema eliminates the redundant overhead of conventional approaches and achieves significant improvements in both security and performance. The protocol provides a scalable solution for secure collaboration among heterogeneous trusted components in cloud environments.
AMD SEV lacks formal verification of its core security properties, including confidentiality, integrity, and availability. This work presents the first systematic formal framework for rigorously verifying these critical security attributes by introducing design-level and property-level abstractions of the SEV architecture, combined with formal modeling and model checking techniques. By establishing a mathematically grounded analysis of SEV’s security guarantees, the study addresses a significant gap in the trusted execution environment literature, where prior evaluations have largely relied on informal or empirical methods. The proposed approach substantially enhances the reliability and trustworthiness of SEV as a confidential computing platform in cloud environments, providing a foundation for future formal analyses of hardware-based security mechanisms.
This work addresses the vulnerability of enterprise software supply chains to infrastructure-level attacks and the limitations of traditional verification approaches that rely on consumers re-executing builds and tests—a process that incurs significant bottlenecks and erodes trust. To overcome these challenges, the paper proposes an evidence-driven, trustworthy CI pipeline protocol that, for the first time, integrates deterministic builds (based on Nix) with remote attestation from Intel TDX trusted execution environments (TEEs). The authors formally define the evidence lifecycle and introduce lightweight cryptographic signing and policy validation mechanisms. This approach provides strong cryptographic guarantees of integrity, authenticity, and provability for CI artifacts without requiring consumer-side re-execution, substantially improving verification efficiency and system scalability while effectively amortizing the initial overhead introduced by TEEs.