Pith. sign in

REVIEW 3 major objections 6 minor 153 references

Teaching an Old Dog New Tricks: Verifiable FHE Using Commodity Hardware

T0 review · 3 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read The paper's central claim is that an integrity-only enclave, with the attestation key sealed in a discrete TPM, turns semi-honest fully homomorphic encryption into maliciously-secure verifiable FHE on commodity hardware at roughly 3%…

desk verdict Good systems idea and open-source prototype, but the attestation scheme has a design-level hole: the malicious OS can directly invoke the TPM signing oracle and forge a valid-looking transcript. read the letter →

arxiv 2412.03550 v2 pith:YOO2TKHS submitted 2024-12-04 cs.CR

classification cs.CR
keywords fullyhomomorphicencryptiontrustedexecutionenvironmentmicroarchitecturalsidechannelstransientattacksverifiablecomputationmalicioussecurityprivateinformationretrievalsetintersection
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Fully homomorphic encryption lets a server compute on encrypted data, but standard FHE schemes assume the server is honest-but-curious: a malicious server can supply malformed ciphertexts, recover keys, or run the wrong function, and cryptographic proofs that fix this are four to seven orders of magnitude slower than FHE itself. Argos claims that commodity trusted hardware—a hypervisor-based security monitor plus a discrete TPM—can add verifiability to FHE against malicious servers at roughly 3% overhead for FHE evaluation and under 8% for complex protocols like private information retrieval and private set intersection. The key move is to build an integrity-only enclave that enforces program and data integrity but not confidentiality, because in FHE all data stays encrypted; the only secret is the attestation key, which is kept in a microarchitecturally isolated TPM so no software attacker can ever share CPU state with it. Attestation then becomes a single TPM signature over a transcript of the enclave binary, inputs, and outputs, made at the end of the computation, turning a semi-honest FHE scheme into a maliciously-secure verifiable one. If this holds, verifiable FHE can move beyond the semi-honest setting without paying the cost of cryptographic proof systems.

What carries the argument

The central object is the attested transcript: a hash chain built by the security monitor that records the dynamic-root-of-trust measurement of the security monitor, the measurement of the enclave binary and initial registers, and the hashes of every client input and output, which is extended in the security monitor and then signed once by the discrete TPM at the end of the computation. This turns remote attestation into a fixed-cost proof system $(\Pi.\mathrm{Gen}, \Pi.\mathrm{Prove}, \Pi.\mathrm{Verify})$ with completeness and soundness properties; the vFHE construction wraps $E.\mathrm{Eval}$ in $\Pi.\mathrm{Prove}$, so that Verify must pass before the client calls $E.\mathrm{Dec}$. The supporting mechanism that makes the transcript safe is microarchitectural isolation of the TPM: side channels are read-only and need shared resources, and since the attestation key never leaves the TPM, no attacker-controlled program in the CPU can ever share cache lines, TLBs, or branch-predictor state with the secret's use.

What would settle it

A concrete falsifier would be a software-only attack in which a malicious OS, with no physical access, obtains a valid TPM signature over a transcript that does not correspond to the enclave binary and inputs actually executed, or causes the client's Verify to accept and decrypt a ciphertext that is not the result of $E.\mathrm{Eval}$ of the agreed circuit on the client's ciphertext; any such demonstration would break the claimed soundness.

Watch

Extended reading notes

Core claim

Argos's central claim is that an integrity-only enclave platform can realize maliciously-secure, verifiable fully homomorphic encryption (vFHE) on commodity hardware, with no dedicated extensions and without cryptographic proofs. Because all application data in FHE remains encrypted end to end, the enclave needs no confidentiality: the only secret in the system is the private key used for remote attestation. Argos stores that key in a discrete TPM, whose simple microarchitecture and physical separation from the CPU make it microarchitecturally isolated, so no software attacker can mount a cache, TLB, branch-predictor, or transient-execution side channel against it. The attestation protocol is a transcript-based proof system: the security monitor records the measurement of the enclave binary and initial state together with hashes of all client inputs and outputs, and asks the TPM to sign the resulting transcript once, after the computation is finished. The paper formalizes this as a tuple $(\Pi.\mathrm{Gen}, \Pi.\mathrm{Prove}, \Pi.\mathrm{Verify})$ with completeness and soundness, and constructs circuit-level vFHE by wrapping $E.\mathrm{Eval}$ inside $\Pi.\mathrm{Prove}$; soundness of the vFHE scheme reduces to the soundness of the TPM signature, the correctness of the dynamic root of trust and hardware isolation, and the assumption that the security monitor and application are bug-free. On a prototype built from a small micro-hypervisor security monitor and a standard BFV-based FHE library, Argos reports 3% average overhead for FHE evaluation and under 8% for authenticated PIR and PSI, while being 80 times faster than a prior SGX-based FHE-in-TEE approach.

Load-bearing premise

The security argument assumes the roughly 18,000-line security monitor and the enclave application are bug-free, and that the discrete TPM, dynamic root of trust, nested page tables, and IOMMU behave exactly as specified; if any one of these gives way, a malicious server could influence what the TPM signs and forge a valid-looking transcript.

Editorial extensions

If this is right

  • Semi-honest FHE evaluations can be upgraded to circuit-level malicious security with about 3% average overhead and negligible communication cost, removing the need for 4 to 7 orders of magnitude of cryptographic proof overhead.
  • Because the TPM signature is a per-batch fixed cost, batching independent FHE evaluations amortizes attestation further, making the discrete TPM's roughly 196 ms signing time negligible for throughput workloads.
  • Adding a well-formedness check on the server's database and a commitment to it in the transcript gives FHE-based PIR and PSI schemes integrity (authenticated PIR and authenticated PSI) at under 8% overhead with no large offline communication.
  • The approach requires only commodity virtualization extensions and a discrete TPM available since roughly 2008, so its security properties do not depend on proprietary enclave hardware.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the integrity-only pattern is sound, it should generalize to any delegated computation whose inputs are entirely encrypted and whose evaluator holds no secret inputs, giving malicious security at hardware cost instead of proof cost.
  • The discrete TPM is the linchpin; replacing it with a formally verified secure element or a post-quantum signature algorithm would address the two most plausible long-term failure modes of the construction.
  • For latency-critical single-query workloads the roughly 196 ms TPM signing time will dominate, so the reported 3% to 8% averages likely only hold when attestation is batched over many queries.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. Argos is an enclave platform purpose-built to add verifiability and malicious security to FHE without cryptographic proof systems. The core idea is to run FHE evaluation inside an integrity-only hypervisor-based enclave, keep all attestation secrets in a discrete TPM outside the CPU, and replace per-message attestation with a single TPM quote over a transcript accumulated by the security monitor (binary hash, inputs, outputs, and, for PIR/PSI, a database commitment). Because no secret ever enters the CPU or memory hierarchy, the paper argues that microarchitectural side channels and transient-execution attacks are eliminated by construction. The paper formalizes circuit-level vFHE (correctness, completeness, soundness, IND-CCA1-style security), gives a construction and proof sketch, extends the formalism to authenticated PIR and PSI, and reports a Tyche-based prototype evaluated with the SEAL library, measuring roughly 0-8% overhead over semi-honest baselines on commodity hardware.

Significance. If the security claims hold, this is an important result for applied FHE: it offers a practical route from semi-honest to malicious security at single-digit-percent overhead instead of the 4-7 orders of magnitude of cryptographic proofs, on commodity hardware and with an open-source prototype (a Tyche fork; repository given in Section 4.3). The design insight is genuinely useful: for integrity-only FHE workloads, the confidentiality problem, and with it the microarchitectural side-channel problem, largely disappears because the only secret is the signing key, which is confined to a microarchitecturally isolated coprocessor. The paper is honest about its TCB assumptions (bug-free 18KLOC monitor and application, functionally correct hardware, constant-time TPM), and the formal template for circuit-level vFHE extends prior work by Viand et al. The fixed-cost batching argument and the PIR/PSI case studies address real deployment bottlenecks. The main risk is that the attestation soundness argument is incomplete as written, leaving the central claim unproven until the TPM access-control mechanism is specified.

major comments (3)
  1. [§5.4, §5.5, §8.1, Appendix A] The stress-test concern about the TPM being an unauthenticated signing oracle is well-founded and load-bearing for the paper's central soundness claim. Section 8.1 describes attestation as the security monitor loading the transcript hash into a PCR and requesting a TPM quote, and Section 5.5 concludes that soundness 'reduces to the soundness of the TPM signature scheme.' However, TPM2_Extend and TPM2_Quote authenticate only the PCR/key authorization values, not the identity of the calling software, and Section 2's threat model grants the adversary control of the OS. A malicious OS can compute the transcript hash for a forged output, extend the transcript PCR itself, and request a quote from the same TPM signing key; the quote still contains the genuine DRoT measurement of the security monitor from boot, so the client-side checks in Section 5.4 (genuine TPM key, correct security-monitor measurement, matching transcript hash) all pass. The paper never states any mechanism that gives the security monitor exclusive access to the TPM command interface (for example, EPT-based exclusion of the TPM MMIO region from all guest domains, or PCR/authorization values known only to the monitor), and Appendix A is explicit that the TPM 'needs to be instructed and fed inputs to extend its internal measurements'; under the threat model a malicious OS is exactly such software. The authors should specify and implement an access-control mechanism that makes the security monitor the only possible caller of Extend and Quote on the relevant PCRs, or redesign the attestation protocol (and the formal soundness definition in Appendix C.2) to be sound against a TPM signing oracle that any software can invoke. As written, the Section 5.5 reduction does not go through.
  2. [Appendix D] The IND-CCA1 reduction in Appendix D has a flaw in its simulation of the decryption oracle. In step (2), B runs Π.Verify(cy, cx, πy) using 'the latest cx it stored.' A CCA1 adversary can interleave Enc and Dec queries: it may query Enc(x1), Enc(x2), and then Dec(cy, πy) for a transcript bound to x1, in which case B verifies against the wrong ciphertext and can return ⊥ on a transcript that the real oracle would accept (or accept one it would reject), letting A distinguish the simulated game from the real one. The reduction to the IND-CPA security of the underlying FHE scheme therefore does not go through as written. The fix is local (B should maintain a table of (x, cx) pairs and select the entry matching the input hash contained in the transcript), but the proof as printed must be corrected.
  3. [§7.1, §7.2, Appendices E, F] The contribution list claims that Argos 'can be used to build fully malicious and authenticated PSI and PIR schemes,' and Section 7.1 refers to 'a detailed security argument' in Appendix E. In fact, Appendix E states 'We leave out the detailed proofs' and Appendix F states 'We omit these proofs in the interest of space.' The authenticated-PIR and authenticated-PSI constructions are described only at the level of 'this fits our formalism by extending h(·)' and 'adapting the vFHE properties is straightforward.' Since application-level malicious security (selective-failure defenses, database commitment binding, server privacy of PSI) is a headline contribution of the paper, the appendices need to supply the actual arguments, or Sections 7.1-7.2 and the contribution list need to be weakened to sketch-level claims.
minor comments (6)
  1. [§9.1, §9.4] The performance tables report single-point averages over 10 runs with no variance or significance measures. Since the headline claims are single-digit percentages (Table 4: +0%, +6%, +2%; Tables 5-6: 1-8% ranges), the reader cannot tell whether the reported overheads are distinguishable from machine noise; please add standard deviations or per-run distributions.
  2. [§9.3] The reported transcript size of 1,407 bits appears inconsistent with the sentence stating that the transcript 'contains the signature and the TPM public key along with the TPM certificates endorsed by the manufacturer,' since a single X.509 TPM certificate is typically several kilobytes. Please clarify whether the 1,407-bit figure is only the hash/measurement portion, with certificates provisioned or cached separately.
  3. [§5.4] The client-verification description never states explicitly that the client recomputes the hashes of the received output ciphertext(s) and compares them against the attested transcript before decrypting; this binding check is essential and should be stated as part of the verification procedure rather than left implicit.
  4. [§5.4, §9.7] Section 5.4 refers the reader to Section 9.7 for how a reference measurement of the security monitor is obtained, but Section 9.7 does not discuss this. The trust anchor for the monitor's reference hash (reproducible builds, a publishing authority, or a secure distribution channel) needs an explicit statement.
  5. [Appendix C.2, Appendix D] In the attestation-soundness definitions and in the hybrid steps, verification is written as Π.Verify_sk (and the H0-H1 and H1-H2 steps swap the hybrid indices); verification under the secret key would defeat the whole game, and the index swaps make the hybrid argument hard to follow. These appear typographical but should be fixed.
  6. [§8.1] The paper does not specify which PCR indices are used for the security-monitor measurements and the transcript hash, nor which TPM localities and authorization policies apply to those PCRs; specifying these details would also clarify the access-control discussion needed for the soundness concern.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation: Argos's performance numbers are measured and its security claims reduce to explicit, independent assumptions rather than to their own conclusions.

full rationale

Argos's central claims are not circular. The 3% FHE-evaluation and sub-8% protocol overheads are empirical measurements taken against semi-honest baselines on the same hardware (Tables 4-6), not parameters fitted from the conclusions. The security derivation is a sequence of explicit reductions: circuit-level vFHE soundness reduces to the soundness of the remote-attestation proof system (Appendix D), whose soundness in turn rests on stated assumptions (DRoT measurement, a bug-free 18 KLOC security monitor, hardware isolation, and TPM signature security, Section 5.5); none of these assumptions asserts the target claim that malicious servers cannot forge attested transcripts. The paper's few self-citations, e.g., the SGX background survey [46], are not load-bearing, and the reuse of Viand et al.'s vFHE definitions is attributed rather than presented as new. Non-circular assurance gaps are flagged: Appendices E and F explicitly omit formal proofs for the authenticated PIR/PSI extensions, and Section 5.4's pointer to Section 9.7 for obtaining the reference security-monitor measurement is not developed there. The TPM signing-oracle concern raised against Section 5.5 is a soundness gap in the proof as written, not a circular derivation, because the paper does not define or fit that gap into its assumptions.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

The central claims rest on no fitted parameters: the 196ms TPM signature and the performance overheads are measured, not derived. Instead, they rely on domain assumptions about a bug-free TCB, correct hardware isolation, TPM isolation, and client-side reference measurements. No new physical or mathematical entities are introduced; the integrity-only enclave and transcript attestation are protocol constructions.

assumptions (5)
  • domain assumption TCB (18KLOC security monitor and enclave application) is bug-free
    Section 2 defines the TCB as only the security monitor and the application, both assumed bug-free. No formal verification of the monitor is provided.
  • domain assumption Hardware is functionally correct and enforces memory and DMA isolation via nested page tables and IOMMU
    Section 8.2 relies on VT-x/AMD-V extended page tables and VT-d/AMD-Vi to protect enclave integrity, with no formal verification of these mechanisms.
  • domain assumption Discrete TPM is microarchitecturally isolated from the CPU and its cryptography is constant-time
    Section 4.2 argues that physical TPMs do not share microarchitectural resources with the CPU. The paper notes known attacks on integrated TPMs such as faulTPM but treats them as out of scope for the discrete TPM design.
  • domain assumption Client knows a correct reference measurement of the security monitor and can verify the TPM endorsement chain
    Section 5.4 requires the client to check that the security monitor measurement in the transcript matches a reference known to be correct. The paper defers the distribution mechanism to Section 9.7 without specifying it.
  • standard math Underlying FHE scheme is IND-CPA secure and E.Eval is deterministic
    Section 6 and Appendix C.3 build the vFHE security and soundness definitions on the standard security of the FHE scheme and on deterministic Eval, which the paper states holds in its setting.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Teaching an Old Dog New Tricks: Verifiable FHE Using Commodity Hardware." pith.science (2026). https://pith.science/paper/YOO2TKHS

@misc{pith2026241203550,
  author       = {Pith},
  title        = {Pith review of: Teaching an Old Dog New Tricks: Verifiable FHE Using Commodity Hardware},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YOO2TKHS}},
  note         = {Machine review of arXiv:2412.03550}
}
read the original abstract

We present Argos, a simple approach for adding verifiability to fully homomorphic encryption (FHE) schemes using trusted hardware. Traditional approaches to verifiable FHE require expensive cryptographic proofs, which incur an overhead of up to seven orders of magnitude on top of FHE, making them impractical. With Argos, we show that trusted hardware can be securely used to provide verifiability for FHE computations, with minimal overhead relative to the baseline FHE computation. An important contribution of Argos is showing that the major security pitfall associated with trusted hardware, microarchitectural side channels, can be completely mitigated by excluding any secrets from the CPU and the memory hierarchy. This is made possible by focusing on building a platform that only enforces program and data integrity and not confidentiality. All secrets related to the attestation mechanism are kept in a separate coprocessor (e.g., a TPM)-inaccessible to any software-based attacker. Relying on a discrete TPM typically incurs significant performance overhead, which is why (insecure) software-based TPMs are used in practice. As a second contribution, we show that for FHE applications, the attestation protocol can be adapted to only incur a fixed cost. Argos requires no dedicated hardware extensions and is supported on commodity processors from 2008 onward. Our prototype implementation introduces 3% overhead for FHE evaluation, and 8% for more complex protocols. In particular, we show that Argos can be used for real-world applications of FHE, such as private information retrieval (PIR) and private set intersection (PSI), where providing verifiability is imperative. By demonstrating how to combine cryptography with trusted hardware, Argos paves the way for widespread deployment of FHE-based protocols beyond the semi-honest setting, without the overhead of cryptographic proofs.

Figures

Figures reproduced from arXiv: 2412.03550 by the authors.

Figure 1
Figure 1. Evolution of the attack surface on TEE platforms. Enc: enclave program, Att: attestation enclave. [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. Evolution of remote attestation protocols. The naive approach with a secure co-processor is inefficient as it requires [PITH_FULL_IMAGE:figures/full_fig_p006_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

153 extracted references · 72 canonical work pages

  1. [1]

    Onur Acıiçmez, Çetin Kaya Koç, and Jean-Pierre Seifert. 2006. Predicting secret keys via branch prediction. In Topics in Cryptology–CT-RSA 2007: The Cryptographers’ Track at the RSA Conference 2007, San Francisco, CA, USA, February 5-9, 2007. Proceedings . Springer, 225–242

  2. [2]

    Dakshi Agrawal, Bruce Archambeault, Josyula R Rao, and Pankaj Rohatgi. 2003. The EM side—channel (s). In Cryptographic Hardware and Embedded Systems- CHES 2002: 4th International Workshop Redwood Shores, CA, USA, August 13–15, 2002 Revised Papers 4 . Springer, 29–45

  3. [3]

    José Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir, and Michael Emmi. 2016. Verifying {Constant-Time} Implementations. In 25th USENIX Security Symposium (USENIX Security 16) . 53–70

  4. [4]

    Sebastian Angel, Hao Chen, Kim Laine, and Srinath Setty. 2018. PIR with compressed queries and amortized query processing. In 2018 IEEE symposium on security and privacy (SP) . IEEE, 962–979

  5. [5]

    Pedro Antonino, Ante Derek, and Wojciech Aleksander Wołoszyn. 2023. Flexible remote attestation of pre-SNP SEV VMs using SGX enclaves. IEEE access 11 (2023), 90839–90856

  6. [6]

    Apple. 2022. Apple Platform Security. https://help.apple.com/pdf/security/en_ US/apple-platform-security-guide.pdf. Accessed on 28.04.2023

  7. [7]

    Apple. 2024. Private Cloud Compute: A new frontier for AI privacy in the cloud. https://security.apple.com/blog/private-cloud-compute/

  8. [8]

    Apple. 2024. Private Cloud Compute Security Guide. https://security.apple. com/documentation/private-cloud-compute

Show all 153 references
  1. [9]

    Gilad Asharov, Abhishek Jain, Adriana López-Alt, Eran Tromer, Vinod Vaikun- tanathan, and Daniel Wichs. 2012. Multiparty computation with low com- munication, computation and interaction via threshold FHE. In Advances in Cryptology–EUROCRYPT 2012: 31st Annual International Con...

  2. [10]

    Shahla Atapoor, Karim Baghery, Hilder VL Pereira, and Jannik Spiessens. 2024. Verifiable FHE via Lattice-based SNARKs. Cryptology ePrint Archive (2024)

  3. [11]

    AWS. 2024. AWS Nitro Enclaves Documentation. https://docs.aws.amazon. com/enclaves/latest/user/nitro-enclave.html

  4. [12]

    AWS. 2024. AWS Nitro TPM Documentation. https://aws.amazon.com/ blogs/compute/deep-dive-into-nitrotpm-and-uefi-secure-boot-support-in- amazon-ec2/

  5. [13]

    Ahmed M Azab, Peng Ning, and Xiaolan Zhang. 2011. Sice: a hardware-level strongly isolated computing environment for x86 multi-core platforms. In Pro- ceedings of the 18th ACM conference on Computer and communications security . 375–388

  6. [14]

    Azure. 2024. Virtual TPMs in Azure confidential VMs. https: //learn.microsoft.com/en-us/azure/confidential-computing/virtual-tpms-in- azure-confidential-vm

  7. [15]

    Michael Backes, Markus Dürmuth, Sebastian Gerling, Manfred Pinkal, Caroline Sporleder, et al. 2010. Acoustic {Side-Channel} attacks on printers. In 19th USENIX Security Symposium (USENIX Security 10)

  8. [16]

    Raad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig, Matthias Klimmek, Ahmad-Reza Sadeghi, and Emmanuel Stapf. 2021. CURE: A Security Architecture with CUstomizable and Resilient Enclaves.. In USENIX Security Symposium. 1073–1090

  9. [17]

    Paul Barham, Boris Dragovic, Keir Fraser, Steven Hand, Tim Harris, Alex Ho, Rolf Neugebauer, Ian Pratt, and Andrew Warfield. 2003. Xen and the art of virtualization. ACM SIGOPS operating systems review 37, 5 (2003), 164–177

  10. [18]

    Mihir Bellare, Anand Desai, David Pointcheval, and Phillip Rogaway. 1998. Rela- tions among notions of security for public-key encryption schemes. InAdvances in Cryptology—CRYPTO’98: 18th Annual International Cryptology Conference Santa Barbara, California, USA August 23–27, 1...

  11. [19]

    Eli Ben-Sasson, Alessandro Chiesa, Michael Riabzev, Nicholas Spooner, Madars Virza, and Nicholas P Ward. 2019. Aurora: Transparent succinct arguments for R1CS. In Advances in Cryptology–EUROCRYPT 2019: 38th Annual Interna- tional Conference on the Theory and Applications of Cr...

  12. [20]

    Ravi Bhargava, Benjamin Serebrin, Francesco Spadini, and Srilatha Manne. 2008. Accelerating two-dimensional page walks for virtualized systems. InProceedings of the 13th international conference on Architectural support for programming languages and operating systems . 26–35

  13. [21]

    Anton Borisov. 2009. Coreboot at your service! Linux Journal 2009, 186 (2009), 1

  14. [22]

    Thomas Bourgeat, Ilia Lebedev, Andrew Wright, Sizhuo Zhang, and Srinivas Devadas. 2019. Mi6: Secure enclaves in a speculative out-of-order processor. In Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microar- chitecture. 42–56

  15. [23]

    Zvika Brakerski, Craig Gentry, and Vinod Vaikuntanathan. 2014. (Leveled) fully homomorphic encryption without bootstrapping. ACM Transactions on Computation Theory (TOCT) 6, 3 (2014), 1–36

  16. [24]

    Ferdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi, and Emmanuel Stapf. 2019. SANCTUARY: ARMing TrustZone with User-space Enclaves.. In NDSS

  17. [25]

    Ferdinand Brasser, Urs Müller, Alexandra Dmitrienko, Kari Kostiainen, Srdjan Capkun, and Ahmad-Reza Sadeghi. 2017. Software grand exposure: {SGX} cache attacks are practical. In 11th USENIX workshop on offensive technologies (WOOT 17)

  18. [26]

    Jakub Breier and Xiaolu Hou. 2022. How practical are fault injection attacks, really? IEEE Access 10 (2022), 113122–113130

  19. [27]

    Robert Buhren, Hans-Niklas Jacob, Thilo Krachenfels, and Jean-Pierre Seifert

  20. [28]

    Robert Buhren, Christian Werling, and Jean-Pierre Seifert. 2019. Insecure until proven updated: analyzing AMD SEV’s remote attestation. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 1087–1099

  21. [29]

    Benedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra, Pieter Wuille, and Greg Maxwell. 2018. Bulletproofs: Short proofs for confidential transactions and more. In 2018 IEEE symposium on security and privacy (SP) . IEEE, 315–334

  22. [30]

    Charly Castes, Adrien Ghosn, Neelu S Kalani, Yuchen Qian, Marios Kogias, Mathias Payer, and Edouard Bugnion. 2023. Creating Trust by Abolishing Hierarchies. In Proceedings of the 19th Workshop on Hot Topics in Operating Systems. 231–238

  23. [31]

    Melissa Chase, Hao Chen, Jintai Ding, Shafi Goldwasser, Sergey Gorbunov, Jeffrey Hoffstein, Kristin Lauter, Satya Lokam, Dustin Moody, Travis Morrison, et al. 2017. Security of homomorphic encryption. HomomorphicEncryption. org, Redmond W A, Tech. Rep(2017)

  24. [32]

    Bhuvnesh Chaturvedi, Anirban Chakraborty, Ayantika Chatterjee, and Debdeep Mukhopadhyay. 2022. A practical full key recovery attack on tfhe and fhew by inducing decryption errors. Cryptology ePrint Archive (2022)

  25. [33]

    Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H Lai. 2019. Sgxpectre: Stealing intel secrets from sgx enclaves via spec- ulative execution. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 142–157

  26. [34]

    Hao Chen, Zhicong Huang, Kim Laine, and Peter Rindal. 2018. Labeled PSI from fully homomorphic encryption with malicious security. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 1223–1237

  27. [35]

    Hao Chen, Kim Laine, and Rachel Player. 2017. Simple encrypted arithmetic library-SEAL v2. 1. In Financial Cryptography and Data Security: FC 2017 Inter- national Workshops, W AHC, BITCOIN, VOTING, WTSC, and TA, Sliema, Malta, April 7, 2017, Revised Selected Papers 21 . Springer, 3–18

  28. [36]

    Hao Chen, Kim Laine, and Peter Rindal. 2017. Fast private set intersection from homomorphic encryption. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . 1243–1255

  29. [37]

    2021.{VoltPillager}: Hardware-based fault injection attacks against Intel{SGX} Enclaves using the{SVID} voltage scaling interface

    Zitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean, David Oswald, and Flavio D Garcia. 2021.{VoltPillager}: Hardware-based fault injection attacks against Intel{SGX} Enclaves using the{SVID} voltage scaling interface. In 30th USENIX Security Symposium (USENIX Security 21...

  30. [38]

    Massimo Chenal and Qiang Tang. 2015. On key recovery attacks against existing somewhat homomorphic encryption schemes. InProgress in Cryptology- LATINCRYPT 2014: Third International Conference on Cryptology and Information Security in Latin America Florianópolis, Brazil, Septe...

  31. [39]

    Pau-Chen Cheng, Wojciech Ozga, Enriquillo Valdez, Salman Ahmed, Zhongshu Gu, Hani Jamjoom, Hubertus Franke, and James Bottomley. 2024. Intel tdx demystified: A top-down approach. Comput. Surveys 56, 9 (2024), 1–33

  32. [40]

    Ilaria Chillotti, Nicolas Gama, Mariya Georgieva, and Malika Izabachène. 2020. TFHE: fast fully homomorphic encryption over the torus. Journal of Cryptology 33, 1 (2020), 34–91

  33. [41]

    Simone Colombo, Kirill Nikitin, Henry Corrigan-Gibbs, David J Wu, and Bryan Ford. 2023. Authenticated private information retrieval. In32nd USENIX security symposium (USENIX Security 23) . 3835–3851

  34. [42]

    Kelong Cong, Radames Cruz Moreno, Mariana Botelho da Gama, Wei Dai, Ilia Iliashenko, Kim Laine, and Michael Rosenberg. 2021. Labeled PSI from homomorphic encryption with reduced computation and communication. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Com...

  35. [43]

    Intel Corporation. 2019. Intel CSME, Intel SPS, Intel TXE, Intel ‘DAL, and Intel AMT 2019.1 QSR advisory. https://www.intel.com/content/www/us/en/ security-center/advisory/intel-sa-00213.html

  36. [44]

    Intel Corporation. 2022. Intel ® Converged Security and Management Engine (Intel® CSME) Security. https://www.intel.com/content/dam/www/public/us/ en/security-advisory/documents/intel-csme-security-white-paper.pdf

  37. [45]

    Intel Corporation. 2024. Intel ® Software Guard Extensions Attestation Service Using Intel ® Enhanced Privacy Identification End-of-Life Time- line. https://www.intel.com/content/www/us/en/developer/articles/technical/ software-security-guidance/resources/sgx-ias-using-epid-eo...

  38. [46]

    Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive (2016)

  39. [47]

    Victor Costan, Ilia Lebedev, and Srinivas Devadas. 2016. Sanctum: Minimal hardware extensions for strong software isolation. In 25th USENIX Security Symposium (USENIX Security 16) . 857–874

  40. [48]

    Morten Dahl, Daniel Demmler, Sarah El Kazdadi, Arthur Meyre, Jean-Baptiste Orfila, Dragos Rotaru, Nigel P Smart, Samuel Tap, and Michael Walter. 2023. Noah’s Ark: Efficient Threshold-FHE Using Noise Flooding. InProceedings of the 11th Workshop on Encrypted Computing & Applied ...

  41. [49]

    Leo de Castro and Keewoo Lee. 2024. VeriSimplePIR: verifiability in simplePIR at no online cost for honest servers. Cryptology ePrint Archive (2024)

  42. [50]

    Emiliano De Cristofaro, Jihye Kim, and Gene Tsudik. 2010. Linear-complexity private set intersection protocols secure in malicious model. In International Conference on the Theory and Application of Cryptology and Information Security . Springer, 213–231

  43. [51]

    Liang Deng, Qingkai Zeng, Weiguang Wang, and Yao Liu. 2014. EqualVisor: Providing memory protection in an untrusted commodity hypervisor. In 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and Communications. IEEE, 300–309

  44. [52]

    Marian Dietz and Stefano Tessaro. 2024. Fully malicious authenticated PIR. In Annual International Cryptology Conference. Springer, 113–147

  45. [53]

    Léo Ducas and Daniele Micciancio. 2015. FHEW: bootstrapping homomorphic encryption in less than a second. In Annual international conference on the theory and applications of cryptographic techniques . Springer, 617–640

  46. [54]

    Alexander Ermolov. 2016. Safeguarding rootkits: Intel BootGuard. Remote access (01 Sep 2021): https://2016. zeronights. ru/wp-content/uploads/2017/03/Intel- BootGuard. pdf (2016)

  47. [55]

    Mark Ermolov and Maxim Goryachy. 2017. How to hack a turned-off computer, or running unsigned code in intel management engine.Black Hat Europe (2017)

  48. [56]

    Dmitry Evtyushkin, Ryan Riley, Nael CSE Abu-Ghazaleh, ECE, and Dmitry Ponomarev. 2018. Branchscope: A new side-channel attack on directional branch predictor. ACM SIGPLAN Notices 53, 2 (2018), 693–707

  49. [57]

    Prastudy Fauzi, Martha Norberg Hovd, and Håvard Raddum. 2022. On the IND-CCA1 security of FHE schemes. Cryptography 6, 1 (2022), 13

  50. [58]

    Erhu Feng, Xu Lu, Dong Du, Bicheng Yang, Xueqiang Jiang, Yubin Xia, Binyu Zang, and Haibo Chen. 2021. Scalable Memory Protection in the{PENGLAI} Enclave. In 15th{USENIX} Symposium on Operating Systems Design and Imple- mentation ({OSDI} 21). 275–294

  51. [59]

    Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, and Bryan Parno

  52. [60]

    William Futral and James Greene. 2013. Intel Trusted Execution Technology for Server Platforms: A Guide to More Secure Datacenters . Springer Nature

  53. [61]

    Chaya Ganesh, Anca Nitulescu, and Eduardo Soria-Vazquez. 2023. Rinocchio: SNARKs for ring arithmetic. Journal of Cryptology 36, 4 (2023), 41

  54. [62]

    Daniel Genkin, Itamar Pipman, and Eran Tromer. 2015. Get your hands off my laptop: physical side-channel key-extraction attacks on pcs: Extended version. Journal of Cryptographic Engineering 5 (2015), 95–112

  55. [63]

    Craig Gentry. 2009. Fully homomorphic encryption using ideal lattices. In Proceedings of the forty-first annual ACM symposium on Theory of computing . 169–178

  56. [64]

    Oded Goldreich, Silvio Micali, and Avi Wigderson. 2019. How to play any mental game, or a completeness theorem for protocols with honest majority. In Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali. 307–328

  57. [65]

    Johannes Götzfried, Moritz Eckert, Sebastian Schinzel, and Tilo Müller. 2017. Cache attacks on Intel SGX. In Proceedings of the 10th European Workshop on Systems Security. 1–6

  58. [66]

    Ben Gras, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, et al. 2018. Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB Attacks.. In USENIX Security Symposium, Vol. 216

  59. [67]

    Matthew Green, Watson Ladd, and Ian Miers. 2016. A protocol for privately reporting ad impressions at scale. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security . 1591–1601

  60. [68]

    Jens Groth. 2016. On the size of pairing-based non-interactive arguments. In Advances in Cryptology–EUROCRYPT 2016: 35th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Vienna, Austria, May 8-12, 2016, Proceedings, Part II 35 . Sprin...

  61. [69]

    Qian Guo, Denis Nabokov, Elias Suvanto, and Thomas Johansson. 2024. Key Recovery Attacks on Approximate Homomorphic Encryption with Non-Worst- Case Noise Flooding Countermeasures. In Usenix Security

  62. [70]

    J Alex Halderman, Seth D Schoen, Nadia Heninger, William Clarkson, William Paul, Joseph A Calandrino, Ariel J Feldman, Jacob Appelbaum, and Edward W Felten. 2009. Lest we remember: cold-boot attacks on encryption keys.Commun. ACM 52, 5 (2009), 91–98

  63. [71]

    Alexandra Henzinger, Emma Dauterman, Henry Corrigan-Gibbs, and Nickolai Zeldovich. 2023. Private web search with Tiptoe. In Proceedings of the 29th symposium on operating systems principles . 396–416

  64. [72]

    Alexandra Henzinger, Matthew M Hong, Henry Corrigan-Gibbs, Sarah Meik- lejohn, and Vinod Vaikuntanathan. 2023. One Server for the Price of Two: Simple and Fast{Single-Server} Private Information Retrieval. In 32nd USENIX Security Symposium (USENIX Security 23) . 3889–3905

  65. [73]

    Intel. 2024. Core Processors. Deprecated Technologies. https: //edc.intel.com/content/www/us/en/design/ipla/software-development- platforms/client/platforms/alder-lake-desktop/12th-generation-intel-core- processors-datasheet-volume-1-of-2/004/deprecated-technologies/

  66. [74]

    Hans Niklas Jacob, Christian Werling, Robert Buhren, and Jean-Pierre Seifert

  67. [75]

    Scott Johnson, Dominic Rizzo, Parthasarathy Ranganathan, Jon McCune, and Richard Ho. 2018. Titan: enabling a transparent silicon root of trust for cloud. In Hot Chips: A Symposium on High Performance Chips , Vol. 194. 10

  68. [76]

    2020.{V0LTpwn}: Attacking x86 processor integrity from software

    Zijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz, and Ahmad-Reza Sadeghi. 2020.{V0LTpwn}: Attacking x86 processor integrity from software. In 29th USENIX Security Symposium (USENIX Security 20) . 1445–1461

  69. [77]

    Ágnes Kiss, Jian Liu, Thomas Schneider, N Asokan, and Benny Pinkas. 2017. Private set intersection for unequal set sizes with mobile applications. InPrivacy Enhancing Technologies Symposium. De Gruyter, 177–197

  70. [78]

    Gerwin Klein, Kevin Elphinstone, Gernot Heiser, June Andronick, David Cock, Philip Derrin, Dhammika Elkaduwe, Kai Engelhardt, Rafal Kolanski, Michael Norrish, et al. 2009. seL4: Formal verification of an OS kernel. In Proceedings of the ACM SIGOPS 22nd symposium on Operating s...

  71. [79]

    Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, et al

  72. [80]

    Esmaeil Mohammadian Koruyeh, Khaled N Khasawneh, Chengyu Song, and Nael B Abu-Ghazaleh. 2018. Spectre Returns! Speculation Attacks using the Return Stack Buffer.. In WOOT@ USENIX Security Symposium

  73. [81]

    Nishant Kumar, Mayank Rathee, Nishanth Chandran, Divya Gupta, Aseem Rastogi, and Rahul Sharma. 2020. Cryptflow: Secure tensorflow inference. In 2020 IEEE Symposium on Security and Privacy (SP) . IEEE, 336–353

  74. [82]

    Eyal Kushilevitz and Rafail Ostrovsky. 1997. Replication is not needed: Single database, computationally-private information retrieval. In Proceedings 38th annual symposium on foundations of computer science . IEEE, 364–373

  75. [83]

    Dayeol Lee, Dongha Jung, Ian T Fang, Chia-Che Tsai, and Raluca Ada Popa

  76. [84]

    Dayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanović, and Dawn Song. 2020. Keystone: An open framework for architecting trusted execution environments. In Proceedings of the Fifteenth European Conference on Computer Systems. 1–16

  77. [85]

    Mengyuan Li, Yuheng Yang, Guoxing Chen, Mengjia Yan, and Yinqian Zhang

  78. [86]

    Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. 2022. Design and verification of the arm confidential compute architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22) . 465–484

  79. [87]

    Yehuda Lindell, David Cook, Tim Geoghegan, Sarah Gran, Rolfe Schmidt, Ehren Kret, Darya Kaviani, and Raluca Ada Popa. 2023. The deployment dilemma: Merits & challenges of deploying MPC. https://mpc.cs.berkeley.edu/blog/ deployment-dilemma.html

  80. [88]

    2022.{AMD} prefetch attacks through power and time

    Moritz Lipp, Daniel Gruss, and Michael Schwarz. 2022.{AMD} prefetch attacks through power and time. In 31st USENIX Security Symposium (USENIX Security 22). 643–660

  81. [89]

    In 29th USENIX Security Symposium (USENIX Security 20)

    An{Off-Chip} attack on hardware enclaves via the memory bus. In 29th USENIX Security Symposium (USENIX Security 20)

  82. [90]

    Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B Lee. 2015. Last- level cache side-channel attacks are practical. In2015 IEEE symposium on security and privacy. IEEE, 605–622

  83. [91]

    Kevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman, Dimitrios Skarlatos, and Baris Kasikci. 2023. Siloz: Leveraging DRAM isolation domains to prevent inter-VM rowhammer. In Proceedings of the 29th Symposium on Operating Systems Principles. 417–433

  84. [92]

    Heiko Mantel, Johannes Schickel, Alexandra Weber, and Friedrich Weber. 2018. How secure is green IT? The case of software-based energy side channels. In Computer Security: 23rd European Symposium on Research in Computer Security, ESORICS 2018, Barcelona, Spain, September 3-7, ...

  85. [93]

    Jonathan M McCune, Yanlin Li, Ning Qu, Zongwei Zhou, Anupam Datta, Vir- gil Gligor, and Adrian Perrig. 2010. TrustVisor: Efficient TCB reduction and attestation. In 2010 IEEE Symposium on Security and Privacy . IEEE, 143–158

  86. [94]

    Jonathan M McCune, Bryan J Parno, Adrian Perrig, Michael K Reiter, and Hiroshi Isozaki. 2008. Flicker: An execution infrastructure for TCB minimization. In Proceedings of the 3rd ACM SIGOPS/EuroSys European Conference on Computer Systems 2008. 315–328

  87. [95]

    Samir Jordan Menon and David J Wu. 2022. Spiral: Fast, high-rate single-server PIR via FHE composition. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 930–947

  88. [96]

    Moritz Lipp, Andreas Kogler, David Oswald, Michael Schwarz, Catherine Eas- don, Claudio Canella, and Daniel Gruss. 2021. PLATYPUS: Software-based Power Side-Channel Attacks on x86. In 2021 IEEE Symposium on Security and Privacy (SP). IEEE

  89. [97]

    Daniel Moghimi. 2023. Downfall: Exploiting speculative data gathering. In 32nd USENIX Security Symposium (USENIX Security 23) . 7179–7193

  90. [98]

    Daniel Moghimi, Berk Sunar, Thomas Eisenbarth, and Nadia Heninger. 2020. TPM-FAIL:TPM meets Timing and Lattice Attacks. In 29th USENIX Security Symposium (USENIX Security 20) . 2057–2073

  91. [99]

    moxie0. 2017. Technology preview: Private contact discovery for Signal. https: //signal.org/blog/private-contact-discovery/. Accessed on 28.04.2023

  92. [100]

    Kit Murdock, David Oswald, Flavio D Garcia, Jo Van Bulck, Daniel Gruss, and Frank Piessens. 2020. Plundervolt: Software-based fault injection attacks against Intel SGX. In 2020 IEEE Symposium on Security and Privacy (SP) . IEEE, 1466–1482

  93. [101]

    musl. 2024. Musl Libc. https://musl.libc.org

  94. [102]

    Deepika Natarajan, Andrew Loveless, Wei Dai, and Ronald Dreslinski. 2021. Chex-mix: Combining homomorphic encryption with trusted execution en- vironments for two-party oblivious inference in the cloud. Cryptology ePrint Archive (2021)

  95. [103]

    Samir Jordan Menon and David J Wu. 2024. YPIR: High-Throughput Single- Server PIR with Silent Preprocessing. Cryptology ePrint Archive (2024)

  96. [104]

    Cong Nie. 2007. Dynamic root of trust in trusted computing. In TKK T1105290 Seminar on Network Security . Citeseer

  97. [105]

    Dag Arne Osvik, Adi Shamir, and Eran Tromer. 2006. Cache attacks and coun- termeasures: the case of AES. In Topics in Cryptology–CT-RSA 2006: The Cryp- tographers’ Track at the RSA Conference 2006, San Jose, CA, USA, February 13-17,

  98. [106]

    Bijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan, Luke Valenta, Tara Whalen, Christopher Wood, Thomas Ristenpart, and Rahul Chatterjee

  99. [107]

    Ronald Perez, Reiner Sailer, Leendert van Doorn, et al. 2006. vTPM: virtualizing the trusted platform module. In Proc. 15th Conf. on USENIX Security Symposium . 305–320

  100. [108]

    James L Peterson and Theodore A Norman. 1977. Buddy systems. Commun. ACM 20, 6 (1977), 421–431

  101. [109]

    Benny Pinkas, Mike Rosulek, Ni Trieu, and Avishay Yanai. 2020. PSI from PaXoS: fast, malicious private set intersection. In Annual International Conference on the Theory and Applications of Cryptographic Techniques . Springer, 739–767

  102. [110]

    Ofri Nevo, Ni Trieu, and Avishay Yanai. 2021. Simple, fast malicious multiparty private set intersection. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 1151–1165

  103. [111]

    Gramine Project. 2024. Gramine Documentation. Microsoft Azure Attestation (MAA) Integration. https://github.com/gramineproject/contrib/tree/master/ Integrations/azure/ra_tls_maa

  104. [112]

    Gramine Project. 2024. Gramine Documentation. Performance tuning and analysis. https://gramine.readthedocs.io/en/stable/performance.html

  105. [113]

    Pengfei Qiu, Dongsheng Wang, Yongqiang Lyu, and Gang Qu. 2019. VoltJockey: Breaking SGX by software-controlled voltage-induced hardware faults. In 2019 Asian Hardware Oriented Security and Trust Symposium (AsianHOST) . IEEE, 1–6

  106. [114]

    Srinivasan Raghuraman and Peter Rindal. 2022. Blazing fast PSI from improved OKVS and subfield VOLE. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 2505–2517

  107. [115]

    Himanshu Raj, Stefan Saroiu, Alec Wolman, Ronald Aigner, Jeremiah Cox, Paul England, Chris Fenner, Kinshuman Kinshumann, Jork Loeser, Dennis Mattoon, et al. 2016. fTPM: A Software-Only Implementation of a TPM Chip.. In USENIX Security Symposium, Vol. 16. 841–856

  108. [116]

    Peter Rindal and Phillipp Schoppmann. 2021. VOLE-PSI: fast OPRF and circuit- PSI from vector-OLE. In Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 901–930

  109. [117]

    Mike Rosulek and Ni Trieu. 2021. Compact and malicious private set intersection for small sets. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 1166–1181

  110. [118]

    Keegan Ryan. 2019. Hardware-backed heist: Extracting ECDSA keys from qualcomm’s trustzone. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 181–194

  111. [119]

    Sandro Pinto and Nuno Santos. 2019. Demystifying arm trustzone: A compre- hensive survey. ACM Computing Surveys (CSUR) 51, 6 (2019), 1–36

  112. [120]

    Michael Schwarz, Martin Schwarzl, Moritz Lipp, Jon Masters, and Daniel Gruss

  113. [121]

    AMD SEV-SNP. 2020. Strengthening VM isolation with integrity protection and more. White Paper, January (2020)

  114. [122]

    Nigel P Smart. 2023. Practical and Efficient FHE-based MPC. InIMA International Conference on Cryptography and Coding . Springer, 263–283

  115. [123]

    Yunqing Sun, Jonathan Katz, Mariana Raykova, Phillipp Schoppmann, and Xiao Wang. 2024. Actively Secure Private Set Intersection in the Client-Server Setting. Cryptology ePrint Archive, Paper 2024/570. https://eprint.iacr.org/2024/570

  116. [124]

    Cheng Tan, Lijun Zhang, and Liang Bao. 2020. A Deep Exploration of BitLocker Encryption and Security Analysis. In 2020 IEEE 20th International Conference on Communication Technology (ICCT). IEEE, 1070–1074

  117. [125]

    Florian Tramer, Fan Zhang, Huang Lin, Jean-Pierre Hubaux, Ari Juels, and Elaine Shi. 2017. Sealed-glass proofs: Using transparent enclaves to prove and sell knowledge. In 2017 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 19–34

  118. [126]

    Chia-Che Tsai, Donald E Porter, and Mona Vij. 2017. {Graphene-SGX}: A practical library{OS} for unmodified applications on{SGX}. In 2017 USENIX Annual Technical Conference (USENIX ATC 17). 645–658

  119. [127]

    Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx

  120. [128]

    Mark D Ryan. 2013. Enhanced certificate transparency and end-to-end en- crypted mail. Cryptology ePrint Archive (2013)

  121. [129]

    Stephan van Schaik, Andrew Kwong, Daniel Genkin, and Yuval Yarom. 2020. SGAxe: How SGX fails in practice

  122. [130]

    Thomas Van Strydonck, Job Noorman, Jennifer Jackson, Leonardo Alves Dias, Robin Vanderstraeten, David Oswald, Frank Piessens, and Dominique Devriese

  123. [131]

    Alexander Viand, Christian Knabenhans, and Anwar Hithnawi. 2023. Verifiable fully homomorphic encryption. arXiv preprint arXiv:2301.07041 (2023)

  124. [132]

    Yao Wang, Andrew Ferraiuolo, and G Edward Suh. 2014. Timing channel protection for a shared memory controller. In 2014 IEEE 20th International Symposium on High Performance Computer Architecture (HPCA). IEEE, 225–236

  125. [133]

    Yingchen Wang, Riccardo Paccagnella, Elizabeth Tang He, Hovav Shacham, Christopher W Fletcher, and David Kohlbrenner. 2022. Hertzbleed: Turning power{Side-Channel} attacks into remote timing attacks on x86. In31st USENIX Security Symposium (USENIX Security 22) . 679–697

  126. [134]

    Samuel Weiser, Mario Werner, Ferdinand Brasser, Maja Malenko, Stefan Man- gard, and Ahmad-Reza Sadeghi. 2019. Timber-v: Tag-isolated memory bringing fine-grained enclaves to risc-v.. In NDSS

  127. [135]

    Rafal Wojtczuk and Joanna Rutkowska. 2009. Attacking intel trusted execution technology. Black Hat DC 2009 (2009), 1–6. 16 Teaching an Old Dog New Tricks: Verifiable FHE Using Commodity Hardware

  128. [136]

    Rafal Wojtczuk, Joanna Rutkowska, and Alexander Tereshkin. 2009. Another way to circumvent Intel trusted execution technology. Invisible Things Lab (2009), 1–8

  129. [137]

    Tianhong Xu, Aidong Adam Ding, and Yunsi Fei. 2024. TrustZoneTunnel: A Cross-World Pattern History Table-Based Microarchitectural Side-Channel Attack. In 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST). IEEE, 01–11

  130. [138]

    Yuval Yarom and Katrina Falkner. 2014. FLUSH+ RELOAD: A high resolution, low noise, L3 cache side-channel attack. In 23rd{USENIX} Security Symposium ({USENIX} Security 14). 719–732

  131. [139]

    Leendert Van Doorn. 2006. Hardware virtualization trends. In ACM/Usenix International Conference On Virtual Execution Environments: Proceedings of the 2 nd international conference on Virtual execution environments , Vol. 14. 45–45

  132. [140]

    Zhenkai Zhang, Sisheng Liang, Fan Yao, and Xing Gao. 2021. Red alert for power leakage: Exploiting intel rapl-induced side channels. InProceedings of the 2021 ACM Asia Conference on Computer and Communications Security . 162–175

  133. [141]

    L1” cache which is connected to other larger (but slower, 10 - 100 cycles) caches (“L2

    Vincent Zimmer and Michael Krau. 2016. Establishing the root of trust. UEFI. org document dated August (2016). A Primer on Measured Boot Measured boot is obtained using a trust chain that binds the mea- surement of the operating system or hypervisor to a component that is inhe...

  134. [142]

    In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)

    CHERI-TrEE: Flexible enclaves on capability machines. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) . IEEE, 1143–1159

  135. [151]

    Zhi Zhang, Decheng Chen, Jiahao Qi, Yueqiang Cheng, Shijie Jiang, Yiyang Lin, Yansong Gao, Surya Nepal, Yi Zou, Jiliang Zhang, et al. 2024. SoK: Rowham- mer on Commodity Operating Systems. In Proceedings of the 19th ACM Asia Conference on Computer and Communications Security . 436–452

  136. [2005]

    Springer, 1–20

    Proceedings. Springer, 1–20

  137. [2012]

    Springer, 483–501

    Proceedings 31. Springer, 483–501

  138. [2017]

    In Proceedings of the 26th Symposium on Operating Systems Principles

    Komodo: Using verification to disentangle secure-enclave hardware from software. In Proceedings of the 26th Symposium on Operating Systems Principles . 287–305

  139. [2018]

    In 27th{USENIX} Security Symposium ({USENIX} Security 18)

    Foreshadow: Extracting the keys to the intel{SGX} kingdom with tran- sient out-of-order execution. In 27th{USENIX} Security Symposium ({USENIX} Security 18). 991–1008

  140. [2019]

    In Computer Security– ESORICS 2019: 24th European Symposium on Research in Computer Security, Luxembourg, September 23–27, 2019, Proceedings, Part I 24

    Netspectre: Read arbitrary memory over network. In Computer Security– ESORICS 2019: 24th European Symposium on Research in Computer Security, Luxembourg, September 23–27, 2019, Proceedings, Part I 24 . Springer, 279–299

  141. [2020]

    Spectre attacks: Exploiting speculative execution. Commun. ACM 63, 7 (2020), 93–101

  142. [2021]

    In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security

    One glitch to rule them all: Fault injection attacks against amd’s secure encrypted virtualization. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 2875–2889

  143. [2022]

    In 31st USENIX Security Symposium (USENIX Security 22)

    Might I get pwned: A second generation compromised credential checking service. In 31st USENIX Security Symposium (USENIX Security 22) . 1831–1848

  144. [2023]

    In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)

    faulTPM: Exposing AMD fTPMs’ Deepest Secrets. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) . IEEE, 1128–1142

  145. [2024]

    Environments

    SoK: Understanding Design Choices and Pitfalls of Trusted Execution 15 Drean et al. Environments. In Proceedings of the 19th ACM Asia Conference on Computer and Communications Security. 1600–1616

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.