Pith. sign in

REVIEW 3 major objections 1 minor 78 references

ODYSSEY: Reestablishing Confidentiality in Confidential Blockchain via Delegated Execution

T0 review · 3 major / 1 minor · reviewed 2026-06-28 · grok-4.3

Pith's one-line read ODYSSEY delegates transaction execution to designated trustees so that other nodes synchronize only results and thereby shrink the TEE attack surface.

desk verdict ODYSSEY's delegation model cuts TEE exposure by limiting execution to trustees, but the security rests on unexamined assumptions about trustee behavior and result synchronization with no formal analysis provided. read the letter →

arxiv 2606.04892 v1 pith:FOTGU7QX submitted 2026-06-03 cs.CR

classification cs.CR
keywords confidentialblockchaintrustedexecutionenvironmentdelegationmodelexecution-inferenceattackexecution-replayside-channelmitigationconsortiumFISCOBCOS
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper identifies execution-inference and execution-replay attacks that exploit long-lived side channels and state-continuity problems inside TEEs used by consortium blockchains. It proposes a delegation model in which each client assigns execution to its own trustees while every other participant receives only the final results. This change limits the number of nodes that must run sensitive code inside the enclave. The authors add location-aware concurrent execution and a delegation-failure handler to keep throughput and latency acceptable. A prototype built on FISCO BCOS reaches roughly 4 000 transactions per second with 0.4–0.5 s latency in a three-node WAN setting.

What carries the argument

The delegation model, in which each client chooses its own trustees to execute inside the TEE and every other node receives only the resulting state updates.

What would settle it

A demonstration that an adversary can still recover a transaction’s private inputs by observing only the synchronized results and the public ledger state after a single execution round.

Watch

Extended reading notes

Core claim

The delegation model lets clients assign transaction execution to designated trustees while all other participants synchronize only the execution results; this arrangement measurably reduces the attack surface for execution-inference and execution-replay attacks without sacrificing confidentiality or system performance.

Load-bearing premise

Designated trustees will execute transactions without introducing new confidentiality leaks or collusion risks, and synchronizing only results will not open alternative inference channels.

Editorial extensions

If this is right

  • Only the chosen trustees ever run the confidential transaction logic inside the enclave.
  • Side-channel and state-continuity attacks are confined to the smaller trustee set.
  • Throughput and latency remain comparable to existing TEE-based systems when location-aware concurrency and failure handling are used.
  • The same result-synchronization pattern can be applied to any consortium blockchain that already relies on TEEs.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Trust assumptions shift from the entire validator set to a per-client trustee subset, which may change how consortium governance is structured.
  • If trustees are drawn from the same organizations that already operate nodes, the model may require additional audit or rotation mechanisms not described in the paper.
  • The approach could be tested on other TEE platforms or in permissionless settings to measure whether the reduced executor set still suffices for liveness.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 1 minor

Summary. The paper taxonomizes execution-inference and execution-replay attacks exploiting TEE side-channel and state-continuity issues in confidential consortium blockchains. It proposes ODYSSEY, whose core is a delegation model in which clients delegate transaction execution to designated trustees (who run inside TEEs) while all other participants synchronize only the resulting state; two supporting techniques (location-aware concurrent execution and a delegation failure handler) are introduced to improve efficiency and security. A prototype implemented on FISCO BCOS is reported to achieve roughly 4k TPS with 0.4-0.5 s latency in a 3-node WAN setting.

Significance. If the security properties can be rigorously established, the delegation approach would constitute a practical architectural change that shrinks the TEE-exposed surface while preserving throughput, which could influence the design of enterprise confidential blockchains. The reported prototype numbers indicate that the performance overhead is modest, but the absence of formal verification, reduction proofs, or comparative security evaluations currently limits the result's immediate impact on the literature.

major comments (3)
  1. [Abstract / Security Claims] Abstract and security claims section: the central assertion that the delegation model 'significantly reduces the attack surface' while preserving confidentiality rests on the unanalyzed assumption that designated trustees introduce neither new leaks nor collusion vectors and that synchronizing only results creates no alternative inference channels; no formal model, game-based definition, or reduction is supplied (formal_verification listed as none).
  2. [Evaluation] Evaluation section: throughput and latency figures are stated for the 3-node WAN prototype, yet the manuscript supplies neither baseline comparisons against prior TEE-based confidential systems, details of the attack-mitigation test methodology, nor quantitative evidence that the two novel techniques close the taxonomized attack vectors.
  3. [Attack Taxonomy and Mitigation] Attack taxonomy and mitigation: while execution-inference and execution-replay attacks are defined, the text asserts without supporting analysis or experiments that location-aware concurrent execution and the delegation failure handler suffice to mitigate them; this gap is load-bearing for the paper's primary contribution.
minor comments (1)
  1. [Abstract] The abstract is dense; expanding the one-sentence description of the two novel techniques would improve readability without altering technical content.

Simulated Author's Rebuttal

3 responses · 1 unresolved

We thank the referee for the constructive feedback and the recommendation for major revision. We address each major comment below with clarifications on our design choices and indicate where revisions will strengthen the manuscript.

read point-by-point responses
  1. Referee: [Abstract / Security Claims] Abstract and security claims section: the central assertion that the delegation model 'significantly reduces the attack surface' while preserving confidentiality rests on the unanalyzed assumption that designated trustees introduce neither new leaks nor collusion vectors and that synchronizing only results creates no alternative inference channels; no formal model, game-based definition, or reduction is supplied (formal_verification listed as none).

    Authors: The delegation model limits TEE execution exposure to client-designated trustees rather than all nodes, with only final state results synchronized to other participants. Trustees are selected and trusted by clients, reducing the surface for side-channel and continuity attacks. We agree a more rigorous treatment is needed and will expand the security claims section with an informal argument addressing collusion risks and potential inference from result synchronization. However, the manuscript does not include a formal model or reduction proof, as the primary contribution is the practical delegation architecture. revision: partial

  2. Referee: [Evaluation] Evaluation section: throughput and latency figures are stated for the 3-node WAN prototype, yet the manuscript supplies neither baseline comparisons against prior TEE-based confidential systems, details of the attack-mitigation test methodology, nor quantitative evidence that the two novel techniques close the taxonomized attack vectors.

    Authors: We will add baseline comparisons against prior TEE-based confidential blockchain systems in the revised evaluation. The current prototype evaluation reports performance in a 3-node WAN setting. Attack mitigation is supported by the architectural design rather than direct quantitative attack experiments. We will include additional details on the test methodology and explain how the techniques address the taxonomized vectors. New quantitative attack-simulation results cannot be added without further experimental work. revision: partial

  3. Referee: [Attack Taxonomy and Mitigation] Attack taxonomy and mitigation: while execution-inference and execution-replay attacks are defined, the text asserts without supporting analysis or experiments that location-aware concurrent execution and the delegation failure handler suffice to mitigate them; this gap is load-bearing for the paper's primary contribution.

    Authors: We will revise the mitigation section to provide explicit step-by-step reasoning showing how location-aware concurrent execution distributes execution to limit side-channel visibility and how the delegation failure handler maintains state continuity to prevent replays. These explanations will be tied directly to the defined attack vectors with concrete scenarios. The supporting analysis will be expanded, though it remains design-based rather than experimental. revision: yes

standing simulated objections not resolved
  • A formal game-based security model, definition, or reduction proof for the delegation approach and its mitigations.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity; architecture proposal with independent prototype evaluation

full rationale

The paper introduces a delegation model and two techniques (location-aware concurrent execution, delegation failure handler) to address taxonomized attacks on confidential blockchains, then reports a prototype on FISCO BCOS with measured throughput and latency. No equations, fitted parameters, predictions, or self-citation chains appear in the provided abstract or description; the central claims rest on the proposed design and empirical results rather than reducing to inputs by construction. This is a standard systems paper with no load-bearing self-referential steps.

Assumptions & free parameters 0 free parameters · 1 assumptions · 0 invented entities

The central claim rests on the domain assumption that TEEs have exploitable side-channel and state-continuity vulnerabilities; no free parameters or invented entities are introduced in the abstract.

assumptions (1)
  • domain assumption TEEs suffer from long-lasting side-channel and state-continuity issues that enable execution-inference and execution-replay attacks.
    This assumption underpins the identification of the two attack classes and the need for the delegation model.

how reviews work

0 comments
Cite this review

Pith. "Pith review of ODYSSEY: Reestablishing Confidentiality in Confidential Blockchain via Delegated Execution." pith.science (2026). https://pith.science/paper/FOTGU7QX

@misc{pith2026260604892,
  author       = {Pith},
  title        = {Pith review of: ODYSSEY: Reestablishing Confidentiality in Confidential Blockchain via Delegated Execution},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/FOTGU7QX}},
  note         = {Machine review of arXiv:2606.04892}
}
read the original abstract

Confidential blockchains leveraging Trusted Execution Environments (TEEs) have garnered extensive attention for transaction confidentiality. In this paper, we first taxonomize two classes of attacks against confidential blockchains, i.e., execution-inference and execution-replay attacks, which exploit TEEs' long-lasting side-channel and state-continuity issues to compromise the confidentiality of existing consortium blockchains. Then, we present ODYSSEY, a confidential blockchain that efficiently mitigates these attacks. The core innovations of ODYSSEY are the following: (1) Its delegation model: clients delegate transaction execution to their designated trustees, while other participants synchronize only the execution results, which significantly reduces the attack surface while preserving confidentiality and system performance. (2) Two novel techniques to improve ODYSSEY's efficiency and security: location-aware concurrent execution and delegation failure handler. Finally, we develop a prototype of ODYSSEY on FISCO BCOS, an enterprise-grade consortium blockchain platform. We have conducted various experiments, and our evaluation results show that in a WAN environment with 3 nodes, ODYSSEY can achieve about 4k throughput while keeping latency as low as 0.4-0.5s.

Figures

Figures reproduced from arXiv: 2606.04892 by the authors.

Figure 1
Figure 1. An auction example running on a smart contract. The [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. A overview of ODYSSEY architecture. For demon￾stration purposes, we set up two clients c1, c2 and three nodes p1, p2, p3, all of which may become primary nodes or delegators during the consensus and execution phase. aborted ones, and includes them in the following block to ensure all nodes agree on the same system’s state. VI. DESIGN DETAILS A. Overview We incorporate the above ideas into a novel Confiden￾tial block… view at source ↗
Figure 3
Figure 3. SDG of the example. Given a series of transactions [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Latency vs. throughput in LAN. (a) ODYSSEY (b) FISCO BCOS (c) Maximum TPS vs. faults (d) Maximum latency vs. faults [PITH_FULL_IMAGE:figures/full_fig_p011_4.png]
Figure 5
Figure 5. Figure 5: Latency vs. throughput in WAN. with those in the LAN environment as shown in [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: Latency vs. throughput in WAN with crash delegator. [PITH_FULL_IMAGE:figures/full_fig_p011_6.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

78 extracted references · 4 canonical work pages

  1. [1]

    Bitcoin: A peer-to-peer electronic cash system,

    S. Nakamoto, “Bitcoin: A peer-to-peer electronic cash system,”Decen- tralized business review, 2008

  2. [2]

    Proof-of-stake (POS),

    “Proof-of-stake (POS),” https://ethereum.org/en/developers/docs/ consensus-mechanisms/pos/

  3. [3]

    Hyperledger Fabric: A distributed operating system for permissioned blockchains,

    E. Androulaki, A. Barger, V . Bortnikov, C. Cachin, K. Christidis, A. De Caro, D. Enyeart, C. Ferris, G. Laventman, Y . Manevichet al., “Hyperledger Fabric: A distributed operating system for permissioned blockchains,” inProceedings of the thirteenth EuroSys conference, 2018, pp. 1–15

  4. [4]

    “Quorum,” https://consensys.io/

  5. [5]

    FISCO-BCOS: An enterprise-grade permissioned blockchain system with high-performance,

    H. Li, Y . Chen, X. Shi, X. Bai, N. Mo, W. Li, R. Guo, Z. Wang, and Y . Sun, “FISCO-BCOS: An enterprise-grade permissioned blockchain system with high-performance,” inProceedings of the International Conference for High Performance Computing, Networking, Storage and Analysis, 2023, pp. 1–17

  6. [6]

    Corda: an introduc- tion,

    R. G. Brown, J. Carlyle, I. Grigg, and M. Hearn, “Corda: an introduc- tion,”R3 CEV , August, vol. 1, no. 15, p. 14, 2016

  7. [7]

    A low-cost cross-border payment system based on auditable cryptocurrency with consortium blockchain: Joint digital currency,

    M. M. Islam, M. K. Islam, M. Shahjalal, M. Z. Chowdhury, and Y . M. Jang, “A low-cost cross-border payment system based on auditable cryptocurrency with consortium blockchain: Joint digital currency,” IEEE Transactions on Services Computing, 2022

  8. [8]

    Private-blockchain-based industrial iot for material and product tracking in smart manufacturing,

    M. I. S. Assaqty, Y . Gao, X. Hu, Z. Ning, V . C. Leung, Q. Wen, and Y . Chen, “Private-blockchain-based industrial iot for material and product tracking in smart manufacturing,”IEEE Network, vol. 34, no. 5, pp. 91–97, 2020

Show all 78 references
  1. [9]

    High-efficiency blockchain-based supply chain traceability,

    H. Wu, S. Jiang, and J. Cao, “High-efficiency blockchain-based supply chain traceability,”IEEE Transactions on Intelligent Transportation Systems, vol. 24, no. 4, pp. 3748–3758, 2023

  2. [10]

    Ccf: A framework for building confidential verifiable replicated services,

    M. Russinovich, E. Ashton, C. Avanessians, M. Castro, A. Chamayou, S. Clebsch, M. Costa, F. C ´edric, M. Kerner, S. Krishnaet al., “Ccf: A framework for building confidential verifiable replicated services,” Technical report, Microsoft Research and Microsoft Azure, 2019

  3. [11]

    Confidentiality support over financial grade consortium blockchain,

    Y . Yan, C. Wei, X. Guo, X. Lu, X. Zheng, Q. Liu, C. Zhou, X. Song, B. Zhao, H. Zhanget al., “Confidentiality support over financial grade consortium blockchain,” inProceedings of the 2020 ACM SIGMOD international conference on management of data, 2020, pp. 2227–2240

  4. [12]

    Confidential consortium framework: Secure multiparty applications with confidentiality, integrity, and high availability,

    H. Howard, F. Alder, E. Ashton, A. Chamayou, S. Clebsch, M. Costa, A. Delignat-Lavaud, C. Fournet, A. Jeffery, M. Kerner, F. Kounelis, M. A. Kuppe, J. Maffre, M. Russinovich, and C. M. Wintersteiger, “Confidential consortium framework: Secure multiparty applications with confi...

  5. [13]

    Software grand exposure: SGX cache attacks are practical,

    F. Brasser, U. M ¨uller, A. Dmitrienko, K. Kostiainen, S. Capkun, and A.- R. Sadeghi, “Software grand exposure: SGX cache attacks are practical,” in11th USENIX Workshop on Offensive Technologies (WOOT 17), 2017

  6. [14]

    Cache attacks on intel SGX,

    J. G ¨otzfried, M. Eckert, S. Schinzel, and T. M ¨uller, “Cache attacks on intel SGX,” inProceedings of the 10th European Workshop on Systems Security, 2017, pp. 1–6

  7. [15]

    Malware guard extension: Using SGX to conceal cache attacks,

    M. Schwarz, S. Weiser, D. Gruss, C. Maurice, and S. Mangard, “Malware guard extension: Using SGX to conceal cache attacks,” in Detection of Intrusions and Malware, and Vulnerability Assessment: 14th International Conference, DIMVA 2017, Bonn, Germany, July 6-7, 2017, Proceedin...

  8. [16]

    Cachezoom: How SGX amplifies the power of cache attacks,

    A. Moghimi, G. Irazoqui, and T. Eisenbarth, “Cachezoom: How SGX amplifies the power of cache attacks,” inCryptographic Hardware and Embedded Systems–CHES 2017: 19th International Conference, Taipei, Taiwan, September 25-28, 2017, Proceedings. Springer, 2017, pp. 69– 90

  9. [17]

    Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution,

    J. Van Bulck, N. Weichbrodt, R. Kapitza, F. Piessens, and R. Strackx, “Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution,” in26th USENIX Security Symposium (USENIX Security 17), 2017, pp. 1041–1056

  10. [18]

    Controlled-channel attacks: Deter- ministic side channels for untrusted operating systems,

    Y . Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deter- ministic side channels for untrusted operating systems,” in2015 IEEE Symposium on Security and Privacy. IEEE, 2015, pp. 640–656

  11. [19]

    Leaky cauldron on the dark land: Un- derstanding memory side-channel hazards in SGX,

    W. Wang, G. Chen, X. Pan, Y . Zhang, X. Wang, V . Bindschaedler, H. Tang, and C. A. Gunter, “Leaky cauldron on the dark land: Un- derstanding memory side-channel hazards in SGX,” inProceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017, pp....

  12. [20]

    Multi-certificate attacks against proof-of-elapsed-time and their countermeasures

    H. Wang, G. Chen, Y . Zhang, and Z. Lin, “Multi-certificate attacks against proof-of-elapsed-time and their countermeasures.” inNDSS, 2022

  13. [21]

    Rote: Rollback protection for trusted execution,

    S. Matetic, M. Ahmed, K. Kostiainen, A. Dhar, D. Sommer, A. Ger- vais, A. Juels, and S. Capkun, “Rote: Rollback protection for trusted execution,” 2017

  14. [22]

    Narrator: Secure and practical state continuity for trusted execution in the cloud,

    J. Niu, W. Peng, X. Zhang, and Y . Zhang, “Narrator: Secure and practical state continuity for trusted execution in the cloud,” inProceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 2385–2399. 14

  15. [23]

    Sok: Privacy-preserving smart contract,

    H. Qi, M. Xu, D. Yu, and X. Cheng, “Sok: Privacy-preserving smart contract,”High-Confidence Computing, vol. 4, no. 1, p. 100183, 2024

  16. [24]

    Sok: Understand- ing design choices and pitfalls of trusted execution environments,

    M. Li, Y . Yang, G. Chen, M. Yan, and Y . Zhang, “Sok: Understand- ing design choices and pitfalls of trusted execution environments,” inProceedings of the 19th ACM Asia Conference on Computer and Communications Security, 2024, pp. 1600–1616

  17. [25]

    Blockchain and trusted computing: Problems, pitfalls, and a solution for hyperledger fabric,

    R. K. Marcus Brandenburger, Christian Cachin and A. Sorniotti, “Blockchain and trusted computing: Problems, pitfalls, and a solution for hyperledger fabric,” 2018. [Online]. Available: http: //arxiv.org/abs/1805.08541

  18. [26]

    The oasis blockchain platform,

    O. Labs, “The oasis blockchain platform,” 2020

  19. [27]

    Asymmetric distributed trust,

    C. Cachin, “Asymmetric distributed trust,” inProceedings of the 22nd International Conference on Distributed Computing and Networking, ser. ICDCN, 2021, p. 3

  20. [28]

    Asymmetric asynchronous Byzantine consensus,

    C. Cachin and L. Zanolini, “Asymmetric asynchronous Byzantine consensus,” inInternational Workshop on Data Privacy Management. Springer, 2021, pp. 192–207

  21. [29]

    “Ripple,” https://ripple.com/

  22. [30]

    Stellar,

    “Stellar,” https://stellar.org

  23. [31]

    Hyperledger besu for private networks,

    “Hyperledger besu for private networks,” https://besu.hyperledger.org/ private-networks

  24. [32]

    FISCO BCOS,

    “FISCO BCOS,” https://github.com/FISCO-BCOS/FISCO-BCOS

  25. [33]

    Viewstamped replication revisited,

    B. Liskov and J. Cowling, “Viewstamped replication revisited,” 2012

  26. [34]

    Intel Trust Domain eXtensions,

    “Intel Trust Domain eXtensions,” https://www.intel.com/content/www/ us/en/developer/articles/technical/intel-trust-domain-extensions.html

  27. [35]

    Ekiden: A platform for confidentiality- preserving, trustworthy, and performant smart contracts,

    R. Cheng, F. Zhang, J. Kos, W. He, N. Hynes, N. Johnson, A. Juels, A. Miller, and D. Song, “Ekiden: A platform for confidentiality- preserving, trustworthy, and performant smart contracts,” in2019 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 2019, pp. 185–200

  28. [36]

    AMD Secure Encrypted Virtualization,

    “AMD Secure Encrypted Virtualization,” https://www.amd.com/en/ processors/amd-secure-encrypted-virtualization

  29. [37]

    Practical Byzantine fault tolerance,

    M. Castro and B. Liskov, “Practical Byzantine fault tolerance,” inOSDI, 2002

  30. [38]

    Hot- stuff: Bft consensus with linearity and responsiveness,

    M. Yin, D. Malkhi, M. K. Reiter, G. G. Gueta, and I. Abraham, “Hot- stuff: Bft consensus with linearity and responsiveness,” inProceedings of the 2019 ACM Symposium on Principles of Distributed Computing, 2019, pp. 347–356

  31. [39]

    Solidity,

    “Solidity,” https://soliditylang.org

  32. [40]

    Ethereum virtual machine (EVM),

    “Ethereum virtual machine (EVM),” https://ethereum.org/en/developers/ docs/evm/

  33. [41]

    Intel Software Guard eXtensions,

    “Intel Software Guard eXtensions,” https://www.intel.com/content/www/ us/en/architecture-and-technology/software-guard-extensions.html

  34. [42]

    Security vulnerabilities of SGX and countermeasures: A survey,

    S. Fei, Z. Yan, W. Ding, and H. Xie, “Security vulnerabilities of SGX and countermeasures: A survey,”ACM Comput. Surv., vol. 54, no. 6, jul 2021. [Online]. Available: https://doi.org/10.1145/3456631

  35. [43]

    A systematic look at ciphertext side channels on AMD SEV- SNP,

    M. Li, L. Wilke, J. Wichelmann, T. Eisenbarth, R. Teodorescu, and Y . Zhang, “A systematic look at ciphertext side channels on AMD SEV- SNP,” in2022 IEEE Symposium on Security and Privacy (SP). IEEE, 2022, pp. 337–351

  36. [44]

    Secauctee: Securing auction smart con- tracts using trusted execution environments,

    H. Desai and M. Kantarcioglu, “Secauctee: Securing auction smart con- tracts using trusted execution environments,” in2021 IEEE International Conference on Blockchain (Blockchain). IEEE, 2021, pp. 448–455

  37. [45]

    SgxPectre: Stealing intel secrets from SGX enclaves via speculative execution,

    G. Chen, S. Chen, Y . Xiao, Y . Zhang, Z. Lin, and T. H. Lai, “SgxPectre: Stealing intel secrets from SGX enclaves via speculative execution,” in 2019 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 2019, pp. 142–157

  38. [46]

    Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution,

    J. Van Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. F. Wenisch, Y . Yarom, and R. Strackx, “Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution,” in27th USENIX Security Symposium (USENIX Security...

  39. [47]

    Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient Recovery,

    J. Niu, X. Wen, G. Wu, S. Liu, J. Yu, and Y . Zhang, “Achilles: Efficient TEE-Assisted BFT Consensus via Rollback Resilient Recovery,” in EuroSys, 2025

  40. [48]

    Consensus in the presence of partial synchrony

    C. Dwork, N. Lynch, and L. Stockmeyer, “Consensus in the presence of partial synchrony.” ACM, 1988, pp. 288–323

  41. [49]

    Fast-HotStuff: A fast and robust bft protocol for blockchains,

    M. M. Jalalzai, J. Niu, C. Feng, and F. Gai, “Fast-HotStuff: A fast and robust bft protocol for blockchains,”IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 4, pp. 2478–2493, 2024

  42. [50]

    Fides: Scalable censorship-resistant DAG consensus via trusted components

    S. Xie, D. Kang, H. Lyu, J. Niu, and M. Sadoghi, “Fides: Scalable censorship-resistant DAG consensus via trusted components.”

  43. [51]

    Preventing page faults from telling your secrets,

    S. Shinde, Z. L. Chua, V . Narayanan, and P. Saxena, “Preventing page faults from telling your secrets,” inProceedings of the 11th ACM on Asia Conference on Computer and Communications Security, 2016, pp. 317–328

  44. [52]

    The severest of them all: Inference attacks against secure virtual en- claves,

    J. Werner, J. Mason, M. Antonakakis, M. Polychronakis, and F. Monrose, “The severest of them all: Inference attacks against secure virtual en- claves,” inProceedings of the 2019 ACM Asia Conference on Computer and Communications Security, 2019, pp. 73–85

  45. [53]

    Nemesis: Studying mi- croarchitectural timing leaks in rudimentary CPU interrupt logic,

    J. Van Bulck, F. Piessens, and R. Strackx, “Nemesis: Studying mi- croarchitectural timing leaks in rudimentary CPU interrupt logic,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018, pp. 178–195

  46. [54]

    Cipherleaks: Breaking constant-time cryptography on AMD SEV via the ciphertext side channel

    M. Li, Y . Zhang, H. Wang, K. Li, and Y . Cheng, “Cipherleaks: Breaking constant-time cryptography on AMD SEV via the ciphertext side channel.” inUSENIX Security Symposium, 2021, pp. 717–732

  47. [55]

    Adam-cs: Advanced asynchronous monotonic counter service,

    A. Martin, C. Lian, F. Gregor, R. Krahn, V . Schiavoni, P. Felber, and C. Fetzer, “Adam-cs: Advanced asynchronous monotonic counter service,” in2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2021, pp. 426–437

  48. [56]

    Cobra: Dynamic proactive secret sharing for confidential BFT services,

    R. Vassantlal, E. Alchieri, B. Ferreira, and A. Bessani, “Cobra: Dynamic proactive secret sharing for confidential BFT services,” in2022 IEEE Symposium on Security and Privacy (SP), 2022, pp. 1335–1353

  49. [57]

    Fast and secure global payments with stellar,

    M. Lokhava, G. Losa, D. Mazi `eres, G. Hoare, N. Barry, E. Gafni, J. Jove, R. Malinowsky, and J. McCaleb, “Fast and secure global payments with stellar,” inProceedings of the 27th ACM Symposium on Operating Systems Principles, 2019, pp. 80–96

  50. [58]

    Is stellar as secure as you think?

    M. Kim, Y . Kwon, and Y . Kim, “Is stellar as secure as you think?” in 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2019, pp. 377–385

  51. [59]

    Eosio blockchain,

    “Eosio blockchain,” https://eos.io

  52. [60]

    Near blockchain,

    “Near blockchain,” https://near.org

  53. [61]

    Ethereum flavored webassembly,

    “Ethereum flavored webassembly,” https://github.com/ewasm

  54. [62]

    Engraft: Enclave-guarded raft on Byzantine faulty nodes,

    W. Wang, S. Deng, J. Niu, M. K. Reiter, and Y . Zhang, “Engraft: Enclave-guarded raft on Byzantine faulty nodes,” inProceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 2841–2855

  55. [63]

    Secret key recovery in a global-scale end-to-end encryption system,

    G. Connell, V . Fang, R. Schmidt, E. Dauterman, and R. A. Popa, “Secret key recovery in a global-scale end-to-end encryption system,” in18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24), Santa Clara, CA, 2024, pp. 703–719

  56. [64]

    Dgcc: A new dependency graph based concur- rency control protocol for multicore database systems,

    C. Yao, D. Agrawal, P. Chang, G. Chen, B. C. Ooi, W.-F. Wong, and M. Zhang, “Dgcc: A new dependency graph based concur- rency control protocol for multicore database systems,”arXiv preprint arXiv:1503.03642, 2015

  57. [65]

    Raccoon: Closing digital side-channels through obfuscated execution,

    A. Rane, C. Lin, and M. Tiwari, “Raccoon: Closing digital side-channels through obfuscated execution,” in24th USENIX Security Symposium (USENIX Security 15), 2015, pp. 431–446

  58. [66]

    Strong and efficient cache side-channel protection using hardware transactional memory,

    D. Gruss, J. Lettner, F. Schuster, O. Ohrimenko, I. Haller, and M. Costa, “Strong and efficient cache side-channel protection using hardware transactional memory,” in26th USENIX Security Symposium (USENIX Security 17), 2017, pp. 217–233

  59. [67]

    The forking way: When tees meet consensus

    A. Wilde, T. N. Gruel, C. Soriente, and G. Karame, “The forking way: When tees meet consensus.” inNDSS, 2025

  60. [68]

    Tz4fabric: Executing smart contracts with arm trust- zone:(practical experience report),

    C. M ¨uller, M. Brandenburger, C. Cachin, P. Felber, C. G ¨ottel, and V . Schiavoni, “Tz4fabric: Executing smart contracts with arm trust- zone:(practical experience report),” in2020 International symposium on reliable distributed systems (SRDS). IEEE, 2020, pp. 31–40

  61. [69]

    Revisiting rollbacks on smart contracts in TEE-protected private blockchains,

    C. C. Lew, C. F. Torres, S. Shinde, and M. Brandenburger, “Revisiting rollbacks on smart contracts in TEE-protected private blockchains,” in 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2024, pp. 217–224

  62. [70]

    SGXonerated: Finding (and partially fixing) privacy flaws in TEE-based smart contract platforms without breaking the TEE,

    N. Jean-Louis, Y . Li, Y . Ji, H. Malvai, T. Yurek, S. Bellemare, and A. Miller, “SGXonerated: Finding (and partially fixing) privacy flaws in TEE-based smart contract platforms without breaking the TEE,” Cryptology ePrint Archive, Paper 2023/378, 2023. [Online]. Available: ht...

  63. [71]

    Obscuro: A Bitcoin mixer using trusted execution environments,

    M. Tran, L. Luu, M. S. Kang, I. Bentov, and P. Saxena, “Obscuro: A Bitcoin mixer using trusted execution environments,” inProceedings of the 34th Annual Computer Security Applications Conference, 2018, pp. 692–701

  64. [72]

    Teechain: a secure payment network with asynchronous blockchain access,

    J. Lind, O. Naor, I. Eyal, F. Kelbert, E. G. Sirer, and P. Pietzuch, “Teechain: a secure payment network with asynchronous blockchain access,” inProceedings of the 27th ACM Symposium on Operating Systems Principles, 2019, pp. 63–79

  65. [73]

    Fastkitten: Practical smart contracts on Bitcoin,

    P. Das, L. Eckey, T. Frassetto, D. Gens, K. Host ´akov´a, P. Jauernig, S. Faust, and A.-R. Sadeghi, “Fastkitten: Practical smart contracts on Bitcoin,” in28th USENIX security symposium (USENIX security 19), 2019, pp. 801–818

  66. [74]

    Pose: Practical off-chain smart contract execution,

    T. Frassetto, P. Jauernig, D. Koisser, D. Kretzler, B. Schlosser, S. Faust, and A.-R. Sadeghi, “Pose: Practical off-chain smart contract execution,” arXiv preprint arXiv:2210.07110, 2022. 15

  67. [75]

    TeeRollup: Efficient rollup design using heterogeneous TEE,

    X. Wen, Q. Feng, H. Lyu, J. Niu, Y . Zhang, and C. Feng, “TeeRollup: Efficient rollup design using heterogeneous TEE,” inIEEE Transactions on Computers, 2025

  68. [76]

    Formally verifying a rollback-prevention protocol for TEEs,

    W. Wang, J. Niu, M. K. Reiter, and Y . Zhang, “Formally verifying a rollback-prevention protocol for TEEs,” inProc. of FORTE, 2024

  69. [77]

    Ensuring state continuity for confidential computing: A blockchain-based approach,

    W. Peng, X. Li, J. Niu, X. Zhang, and Y . Zhang, “Ensuring state continuity for confidential computing: A blockchain-based approach,” inIEEE TDSC, 2024

  70. [78]

    Nimble: Rollback protection for confidential cloud services,

    S. Angel, A. Basu, W. Cui, T. Jaeger, S. Lau, S. Setty, and S. Singana- malla, “Nimble: Rollback protection for confidential cloud services,” in 17th USENIX Symposium on Operating Systems Design and Implemen- tation (OSDI 23), 2023, pp. 193–208

Pith tools

Reviewed June 28, 2026 · model on record in the stance chip above.