Score
Designs, builds, and evaluates verification methods, tests, and tooling for Trusted Execution Environments (TEEs) and secure enclaves that ensure cryptographic operations and key material are correctly isolated and executed locally inside the enclave. Implements and analyzes deterministic, constant-time cryptographic arithmetic (e.g., Ed25519) and develops mitigations and tests for implementation-level side channels and other TEE-specific vulnerabilities.
This study addresses the risk of tampering by untrusted applications at Trusted Execution Environment (TEE) interaction boundaries by proposing the PRA-TLS protocol. For the first time, this work extends remote attestation to the client application layer, employing a customized Attester Daemon to perform runtime measurements of both host and application states. This approach establishes an end-to-end chain of trust, ensuring that only legitimate environments can invoke enclaves. A prototype implementation is developed using Intel SGX, accompanied by comprehensive performance evaluations. Furthermore, the protocol’s security properties are formally verified using the Tamarin Prover. The results demonstrate that the proposed scheme achieves rigorous security guarantees and effectively defends against input and output tampering attacks.
This work addresses the challenge of detecting input validation vulnerabilities in Trusted Execution Environments (TEEs), which stem from their complex configuration and hardware-enforced isolation. To overcome this, the authors propose SymTEE, a novel symbolic execution framework that uniquely integrates abstract syntax tree (AST)-based static analysis with large language models (specifically GPT-5). The approach first identifies suspicious code segments and then leverages the LLM to automatically generate lightweight, KLEE-compatible mock execution environments, enabling symbolic execution without requiring actual TEE deployment. This significantly lowers the barrier to TEE security analysis while enhancing scalability. Evaluated on 26 known vulnerability cases, SymTEE achieves 100% precision and 92.3% recall, with an average analysis cost of merely $0.05 per instance.
This work addresses the vulnerability of Trusted Execution Environments (TEEs) to sensitive data leakage stemming from enclave code flaws and hardware-level exploits, which undermines their resilience against real-world threats. To bridge the gap between idealized TEE security models and practical robustness, the authors propose a RISC-V-based hardware-enhanced architecture that enables fine-grained tracking of sensitive data flows and enforces boundary-aware access control directly at the hardware level. Notably, the design incorporates, for the first time, a controlled declassification mechanism that systematically monitors intra-enclave data propagation and securely releases information when appropriate. FPGA-based prototype evaluation demonstrates that the proposed solution incurs only a 10.8% area overhead and a 5.69% performance penalty while effectively preventing unauthorized data exfiltration.
AMD SEV lacks formal verification of its core security properties, including confidentiality, integrity, and availability. This work presents the first systematic formal framework for rigorously verifying these critical security attributes by introducing design-level and property-level abstractions of the SEV architecture, combined with formal modeling and model checking techniques. By establishing a mathematically grounded analysis of SEV’s security guarantees, the study addresses a significant gap in the trusted execution environment literature, where prior evaluations have largely relied on informal or empirical methods. The proposed approach substantially enhances the reliability and trustworthiness of SEV as a confidential computing platform in cloud environments, providing a foundation for future formal analyses of hardware-based security mechanisms.
为解决TEE中的缓存侧信道攻击问题,本文提出HermiCache,一种针对RISC-V核心设计的缓存替换策略,提供细粒度配置与确定性保护。
This study addresses the challenge of remote attestation for proprietary software within Trusted Execution Environments (TEEs), where closed-source code impedes verification. To overcome this, we propose a disclosure-free attribute proof architecture that introduces a novel "provable auditing" paradigm. By leveraging hardware-endorsed zero-knowledge proof chains, this approach cryptographically binds automated auditing conclusions—derived from static analysis and fuzz testing—to TEE measurement values. We implement an end-to-end workflow using technology stacks including Intel SGX and Gramine, validating its feasibility in Python-based scenarios. The proposed framework enables verifiers to confidently ascertain that running artifacts satisfy established security properties without requiring trust in third parties or access to the underlying source code.
该研究通过构建一种新的类型系统SIR及其扩展SIREN,结合自动编译技术,解决了在LLVM低级语言中使用TEE时的信息流安全问题及手动分区难题。
研究通过分析115个TEE部署,发现91%不可重现,并探讨了技术及生态系统层面的挑战,提出需整体开发方法以解决TEE构建可重现性问题。
Centralized AI deployments entail exposing sensitive data and code to cloud providers, posing significant privacy and security risks. This work proposes the first end-to-end confidential AI workflow that systematically integrates CPU-based trusted execution environments (TEEs)—such as Intel TDX and AMD SEV-SNP—with GPU TEEs on NVIDIA H100/H200 platforms, ensuring data confidentiality and integrity across both virtual machine and application layers. The study identifies and mitigates novel threats, including unauthorized access to confidential VM contents by Kubernetes administrators, by leveraging remote attestation and end-to-end encrypted execution to provide strong security guarantees. The proposed framework is evaluated on an integrated Intel TDX and NVIDIA H200 platform using industry-standard benchmarks, quantifying performance overhead and demonstrating the feasibility and robustness of the approach.
为解决TEE中内存安全和性能问题,本文提出PRISM架构,利用棱镜能力创建用户空间隔离区,实现高效的所有权建立、域转换及远程证明。