secure enclave integration

Designs, builds, and analyzes systems and software components that incorporate hardware-backed secure enclaves, including enclave-host interfaces, lifecycle management, remote attestation, key provisioning, and secure channeling so that sensitive code and data execute inside an isolated trusted environment. This competence also covers integrating enclave APIs into larger applications, validating enclave interactions, and assessing threats such as side channels and enclave-host communication vulnerabilities.

secureenclaveintegration

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.35
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the lack of comprehensive lifecycle management support for trusted execution environments (TEEs) on RISC-V, particularly the absence of mechanisms for secure enclaves’ updates and migration. The authors propose the first modular lifecycle management framework tailored for RISC-V TEEs, introducing three lightweight extensions at the security monitor layer to enable enclave state continuity, secure migration, and trusted time services. The design is compatible with mainstream RISC-V TEE frameworks such as Keystone and CURE, requiring only minimal interface adaptations. Experimental evaluation demonstrates that the overhead for state continuity is below 1.5%, and enclave downtime during migration is merely 0.8% for a 1KB state, meeting the stringent requirements of safety-critical domains including IoT and automotive systems.

enclave lifecycleRISC-Vsecure migration

SoC security architecture design is highly susceptible to critical vulnerabilities from minor oversights and struggles to simultaneously address supply-chain attack resilience and hardware reusability. This paper proposes CITADEL—the first modular, configurable SoC security framework explicitly designed to withstand supply-chain attacks. CITADEL’s key contributions are: (1) plug-and-play integration of heterogeneous security IP modules, enabling flexible composition and diverse deployment of security primitives; (2) unified threat modeling across multi-vector attack surfaces, enhancing architectural adaptability and cross-process-node reusability; and (3) ASIC implementation demonstrating minimal overhead—less than 0.8% area and 1.2% power increase across mainstream technology nodes. Experimental evaluation confirms that CITADEL significantly improves design efficiency, verification speed, and silicon-proven integration practicality, establishing a scalable foundation for secure, reusable SoC development in adversarial supply chains.

Addressing supply-chain threats in hardware security is a pressing concernDesigning secure SoC architectures is complex and time-consumingMinor architectural oversights can cause critical security vulnerabilities

This work addresses the limitations of existing encrypted telemetry schemes, which struggle to support high-frequency (10 Hz) power data streams and lack robust source authentication, rendering them vulnerable to spoofing by malicious hosts. To overcome these challenges, the authors propose a distributed hardware-assisted telemetry architecture that integrates DCAP remote attestation, event-level differential privacy, and SPDM-based authentication to establish a secure first-mile layer. The design further incorporates Byzantine fault tolerance and GPU enclave-based global verification to enable traceable, extraction-attack-resistant, high-resolution AI modeling of power transients. Experimental results demonstrate that the system achieves 0% success rate against post-extraction attacks across 32 GCP Confidential VMs, with a per-enclave throughput of 131,406 samples/second and an authentication overhead of merely 0.23 microseconds per sample. On H100/A100/L4 platforms, it attains a dynamic scheduling error of 1.3 MW, significantly outperforming centralized differential privacy baselines.

data authenticitypower telemetryscalability

DASICS: Enhancing Memory Protection with Dynamic Compartmentalization

Oct 10, 2023
YJ
Yue Jin
🏛️ Institute of Computing Technology, Chinese Academy of Sciences

Existing hardware and software defenses against fine-grained memory-access vulnerabilities (e.g., out-of-bounds access, ROP attacks) stemming from third-party code struggle to simultaneously achieve strong security, low overhead, and broad portability. Method: This paper proposes a dynamic in-process address-space isolation mechanism that enables multi-privilege, programmable security domains within a single virtual address space—ensuring end-to-end protection for both data and control flows while supporting secure system calls. It introduces the first “dynamically code-segment-driven” isolation architecture, overcoming limitations of static partitioning in granularity, performance cost, and compatibility. The design integrates a custom secure processor microarchitecture (FPGA prototype), QEMU-based simulation, compiler-assisted tagging, and runtime monitoring. Results: Evaluation demonstrates robust resilience against representative memory corruption attacks, with average hardware overhead under 8%—significantly outperforming pure-software approaches—while preserving binary compatibility.

Addressing memory access vulnerabilities from third-party codeProviding dynamic isolation across multiple privilege levelsReducing performance overhead of software-based security mechanisms

Latest Papers

What's happening recently
View more

This work addresses the fragmentation in existing confidential container systems, which often rely on virtual machines or specific trusted execution environments (TEEs), thereby disrupting unified management with standard OCI runtimes. The paper proposes EBCC, an architecture that treats the rich execution environment (REE) anchor and the TEE-side confidential stage as a unified containerized entity. By introducing a TEE backend adapter to abstract underlying heterogeneity, EBCC enables OCI-compliant lifecycle operations. It is the first framework to seamlessly integrate diverse TEEs—including Keystone, SGX, TDX, and OP-TEE—while avoiding significant expansion of the trusted computing base. Experimental results demonstrate EBCC’s functional correctness and strong concurrency on Keystone, broad cross-TEE portability, and only modest, manageable latency overheads, with additional costs primarily confined to host-side management operations.

confidential containerscontainer lifecyclehardware-enforced isolation

This work addresses the vulnerability of Trusted Execution Environments (TEEs) to sensitive data leakage stemming from enclave code flaws and hardware-level exploits, which undermines their resilience against real-world threats. To bridge the gap between idealized TEE security models and practical robustness, the authors propose a RISC-V-based hardware-enhanced architecture that enables fine-grained tracking of sensitive data flows and enforces boundary-aware access control directly at the hardware level. Notably, the design incorporates, for the first time, a controlled declassification mechanism that systematically monitors intra-enclave data propagation and securely releases information when appropriate. FPGA-based prototype evaluation demonstrates that the proposed solution incurs only a 10.8% area overhead and a 5.69% performance penalty while effectively preventing unauthorized data exfiltration.

data leakageenclavehardware vulnerabilities

This work addresses the vulnerability of conventional processors that expose code in plaintext during execution. We propose SABLE, a lightweight, microarchitecture-agnostic instruction-level authenticated encryption architecture that enables runtime instruction decryption and dual verification—spanning both instruction memory and the CPU frontend—within a RISC-V processor. SABLE integrates seamlessly with standard toolchains and requires only minimal post-processing of ELF binaries. Leveraging the ASCON-128a algorithm, we implement seven single- and multi-cycle microarchitectural variants on the NEORV32 SoC and validate them on a Xilinx Artix-7 FPGA. Experimental results demonstrate that, compared to a baseline, these configurations incur overheads of 1.6–9.3× in LUT usage, 4.1–10.0× in performance degradation, 1.5–8.0× in power consumption, and 10.4–80.0× in energy per instruction, thereby systematically revealing the trade-off space among area, performance, and energy efficiency for secure instruction execution.

authenticated encryptionconfidential computinghardware security

Hot Scholars

JN

Jianyu Niu

Research Assistant Professor, Southern University of Science and Technology
Distributed SystemsBlockchainsTEEAI Agents
YZ

Yinqian Zhang

Professor, Southern University of Science and Technology
Computer Security
DR

Daniel Ramage

Google Research
Federated learningFederated analyticsMachine learning
MK

Marios Kogias

Imperial College London
Operating SystemsDistributed SystemsNetworkingDatacenter Systems