Pith. sign in

REVIEW 1 major objections 2 minor 115 references

TeeDAO: A Decentralized Autonomous Organization for Heterogeneous TEEs

T0 review · 1 major / 2 minor · reviewed 2026-06-28 · grok-4.3

Pith's one-line read TeeDAO couples BFT governance with heterogeneity-aware DPSS and MPC to maintain consistent secrets across changing committees of different TEEs.

desk verdict TeeDAO ships a real prototype tying HotStuff BFT to adapted COBRA DPSS across SGX/TDX/CSV with 1.8x throughput on 61 nodes, but the cross-TEE attestation normalization for dynamic committees is not detailed enough to verify consistency. read the letter →

arxiv 2606.04912 v1 pith:ANKXQGYP submitted 2026-06-03 cs.CR

classification cs.CR
keywords TEEdecentralizedautonomousorganizationBFTconsensusdistributedproactivesecretsharingsecuremulti-partycomputationheterogeneousTEEsattestationdynamiccommittee
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper introduces TeeDAO, a three-layer framework designed to organize multiple heterogeneous TEE instances into a decentralized system. It integrates BFT consensus for governance with distributed proactive secret sharing and multi-party computation that handles differences between TEE types. This setup ensures that when the committee of TEEs changes based on attestations, the secrets can be recovered and reshared securely without interruption. A reader would care because it addresses the vulnerability of depending on one TEE implementation while avoiding centralized control in distributed trust systems.

What carries the argument

The coupling of BFT-ordered governance with heterogeneity-aware DPSS and MPC that reflects attestation-driven committee changes in secret management and computation.

What would settle it

Demonstration of inconsistent secret recovery or a new vulnerability arising after an attestation-based committee change in a setup with mixed TEE types.

Watch

Extended reading notes

Core claim

TeeDAO is a novel three-layer framework that automatically organizes multiple heterogeneous TEE instances and provides unified interfaces to support diverse applications, while ensuring long-term guarantees of availability, integrity, and confidentiality. TeeDAO couples BFT-ordered governance with heterogeneity-aware Distributed Proactive Secret Sharing (DPSS) and Secure Multi-Party Computation (MPC) so that attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs.

Load-bearing premise

Attestation-driven committee changes can be consistently reflected in secret recovery, resharing, and computation without introducing new vulnerabilities from TEE heterogeneity or implementation differences.

Editorial extensions

If this is right

  • Evaluations show up to 1.8x higher key-value store throughput in a 61-node cluster compared to prior systems.
  • It supports integration with Intel SGX, TDX, and Hygon CSV.
  • It achieves efficient autonomous management of the committee.
  • It incurs minimal computation overhead of less than 18% for multi-party computation tasks.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The framework could allow applications to operate across multiple TEE vendors without increasing attack surface from any single implementation.
  • Similar coupling of consensus and secret sharing might apply to other dynamic committee systems beyond TEEs.
  • Testing with a wider range of TEE types would check whether the heterogeneity handling generalizes.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

1 major / 2 minor

Summary. The paper introduces TeeDAO, a three-layer framework for organizing heterogeneous TEEs (Intel SGX, TDX, Hygon CSV) that couples BFT-ordered governance (HotStuff) with heterogeneity-aware DPSS (adapted from COBRA) and MPC. This ensures attestation-driven committee changes are reflected in secret recovery, resharing, and computation for dynamic committees, providing unified interfaces with guarantees of availability, integrity, and confidentiality. A prototype implementation is evaluated, claiming up to 1.8x higher key-value store throughput in a 61-node cluster versus state-of-the-art systems, with efficient autonomous management and <18% MPC overhead.

Significance. If the core integration holds, TeeDAO would advance distributed-trust systems by enabling resilient use of multiple TEE implementations without centralized management, dispersing attack surfaces while maintaining performance in applications like key-value stores. The prototype evaluation and explicit coupling of BFT with DPSS/MPC represent concrete engineering contributions that could inform future heterogeneous TEE deployments.

major comments (1)
  1. [Abstract] Abstract, paragraph on framework coupling: the central claim that 'attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs' requires an explicit mechanism for normalizing attestation outputs (differing in format, measurement, and revocation semantics across SGX/TDX/CSV) into a common committee view inside the BFT state machine. No such normalization step or handling of TEE-specific timing/capability differences is described, which is load-bearing for the consistency guarantee and leaves open the possibility of desynchronization or expanded attack surface precisely when the committee is dynamic.
minor comments (2)
  1. [Abstract] Abstract: performance claims (1.8x throughput, <18% overhead) supply no methods details, error bars, baseline definitions, or data exclusion rules, preventing verification of the evaluation results.
  2. [Abstract] Abstract: the three-layer framework is introduced without a high-level diagram or enumeration of the layers, making the architecture description harder to follow.

Simulated Author's Rebuttal

1 responses · 0 unresolved

We thank the referee for the constructive feedback on TeeDAO. We address the single major comment below and will revise the manuscript accordingly.

read point-by-point responses
  1. Referee: [Abstract] Abstract, paragraph on framework coupling: the central claim that 'attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs' requires an explicit mechanism for normalizing attestation outputs (differing in format, measurement, and revocation semantics across SGX/TDX/CSV) into a common committee view inside the BFT state machine. No such normalization step or handling of TEE-specific timing/capability differences is described, which is load-bearing for the consistency guarantee and leaves open the possibility of desynchronization or expanded attack surface precisely when the committee is dynamic.

    Authors: We agree that the abstract presents a high-level claim without sufficient detail on attestation normalization. The manuscript describes a heterogeneity-aware DPSS adaptation and its coupling to HotStuff but does not explicitly document the normalization layer that maps SGX/TDX/CSV attestation outputs (formats, measurements, revocation semantics) or handles timing and capability differences into a unified BFT committee view. We will revise by adding a dedicated subsection on attestation normalization (including a common parser, standardized measurement mapping, revocation checks, and epoch-based synchronization to avoid desynchronization) and will update the abstract to reference this mechanism. This addresses the load-bearing consistency concern. revision: yes

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity in TeeDAO's architectural claims

full rationale

The paper presents an architectural framework that couples BFT-ordered governance with heterogeneity-aware DPSS and MPC for dynamic heterogeneous TEE committees. No equations, fitted parameters, predictions, or first-principles derivations appear that could reduce by construction to the paper's own inputs. The central claim is a design integration (BFT with adapted COBRA DPSS across SGX/TDX/CSV), not a self-definitional loop or renamed empirical pattern. Any self-citation to COBRA is not load-bearing for a uniqueness theorem or ansatz that forces the result; the work is self-contained as a systems prototype with throughput evaluations.

Assumptions & free parameters 0 free parameters · 2 assumptions · 1 invented entities

Only abstract available; ledger therefore contains only the minimal assumptions stated or implied by the abstract description.

assumptions (2)
  • standard math BFT consensus provides consistent ordering of governance decisions
    Invoked for attestation-driven committee changes.
  • domain assumption Heterogeneous TEE attestations can be used to trigger consistent secret operations across types
    Central to the coupling of governance with DPSS/MPC.
invented entities (1)
  • TeeDAO three-layer framework
    purpose: Automatically organize heterogeneous TEE instances with unified interfaces
    Newly proposed system architecture.

how reviews work

0 comments
Cite this review

Pith. "Pith review of TeeDAO: A Decentralized Autonomous Organization for Heterogeneous TEEs." pith.science (2026). https://pith.science/paper/ANKXQGYP

@misc{pith2026260604912,
  author       = {Pith},
  title        = {Pith review of: TeeDAO: A Decentralized Autonomous Organization for Heterogeneous TEEs},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ANKXQGYP}},
  note         = {Machine review of arXiv:2606.04912}
}
read the original abstract

Trusted Execution Environments (TEEs) have emerged as a critical technology for safeguarding sensitive data and ensuring code integrity in modern computing systems. However, relying on a single TEE implementation makes systems vulnerable to a central point of attack. Building distributed-trust systems leveraging heterogeneous TEEs helps disperse trust but still faces threats from centralized management and adaptive mobile adversaries. To address these challenges, this paper introduces TeeDAO, a novel three-layer framework that automatically organizes multiple heterogeneous TEE instances and provides unified interfaces to support diverse applications, while ensuring long-term guarantees of availability, integrity, and confidentiality. TeeDAO couples BFT-ordered governance with heterogeneity-aware Distributed Proactive Secret Sharing (DPSS) and Secure Multi-Party Computation (MPC) so that attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs. We implement a prototype of TeeDAO, integrating COBRA's DPSS scheme with the HotStuff BFT consensus protocol, and adapt it for Intel SGX, TDX, and Hygon CSV. Evaluations demonstrate that TeeDAO achieves up to 1.8x higher key-value store throughput in a large cluster with 61 nodes compared to state-of-the-art systems, efficient autonomous management, and minimal computation overhead (<18%) for multi-party computation tasks.

Figures

Figures reproduced from arXiv: 2606.04912 by the authors.

Figure 1
Figure 1. (a) TEE availability timeline. (b) Representative at [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Overview of TeeDAO services. challenges, i.e., evidence-driven autonomous management: and proactive secret maintenance, as presented in Sec. I. The central consistency requirement is that a node’s authority to participate in consensus, store a secret share, and contribute to MPC must be derived from the same certified configuration. Otherwise, reconfiguration may remove a compromised TEE from the committee while lea… view at source ↗
Figure 3
Figure 3. A three layer architecture of TeeDAO. a unique, totally ordered log (i.e., safety) and make progress during periods of synchrony (i.e., liveness), provided n ≥ 3t + 1. (A2) Certificate unforgeability. The signature scheme is un￾forgeable under chosen-message attacks (EU-CMA). The adversary cannot forge a valid commit certificate Certcfg(x) without the secret keys of a quorum of committee members. (A3) DPSS correctne… view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Interfaces of TeeDAO. maintenance to the DAO-driven configuration lifecycle. When the DAO commits a membership-changing proposal, such as removal, admission, or readmission, it moves the system into Reconfig and installs a new configuration cfg′ . The Protocol layer st…
Figure 5
Figure 5. Figure 5: Write and read throughput/latency. outlined above. We focus on Intel TDX and SGX for direct comparison, and defer the evaluation of CSV to Appendix B due to space constraints. B. KV Storage Performance To address Q1, we evaluate the performance of TeeDAO as a KVS in te…
Figure 6
Figure 6. Figure 6: Reconfiguration and recovery latency. TABLE III: Recovery latency (s) for storage with 1K entries. System Metric n = 4 n = 16 n = 25 n = 31 TDX Poly. Gen. 1.026 4.606 9.788 14.414 State Recon. 0.179 0.411 0.845 1.265 SGX Poly. Gen. 1.665 5.128 10.226 14.620 State Recon…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

115 extracted references

  1. [1]

    Intel® software guard extensions (intel® sgx),

    “Intel® software guard extensions (intel® sgx),” https://www.intel.com/content/www/us/en/architecture-and- technology/software-guard-extensions.html, 2015

  2. [2]

    Intel® trust domain extensions (intel® tdx),

    “Intel® trust domain extensions (intel® tdx),” https://www.intel.com/content/www/us/en/developer/tools/trust- domain-extensions/overview.html, 2023

  3. [3]

    Arm confidential compute architecture,

    “Arm confidential compute architecture,” https://www.arm.com/architecture/security-features/arm-confidential- compute-architecture, 2021

  4. [4]

    Amd secure encrypted virtualization (sev),

    “Amd secure encrypted virtualization (sev),” https://www.amd.com/en/developer/sev.html, 2016

  5. [5]

    Hygon secure virtualization,

    “Hygon secure virtualization,” 2023. [Online]. Available: https: //gitee.com/anolis/cloud-kernel/blob/devel-5.10/Documentation/x86/hy gon-secure-virtualization.rst

  6. [6]

    Azure confidential computing overview,

    “Azure confidential computing overview,” https://learn.microsoft.com/en-us/azure/confidential- computing/overview, 2024

  7. [7]

    Nitro enclaves,

    “Nitro enclaves,” https://aws.amazon.com/ec2/nitro/nitro-enclaves/, 2020

  8. [8]

    Google confidential computing,

    “Google confidential computing,” 2024. [Online]. Available: https: //cloud.google.com/security/products/confidential-computing

Show all 115 references
  1. [9]

    VC3: trustworthy data analytics in the cloud using SGX,

    F. Schuster, M. Costa, C. Fournet, C. Gkantsidis, M. Peinado, G. Mainar-Ruiz, and M. Russinovich, “VC3: trustworthy data analytics in the cloud using SGX,” inProc. of IEEE S&P, 2015

  2. [10]

    Enclavedb: A secure database using SGX,

    C. Priebe, K. Vaswani, and M. Costa, “Enclavedb: A secure database using SGX,” inProc. of IEEE S&P, 2018

  3. [11]

    Oblivious multi-party machine learning on trusted processors,

    O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa, “Oblivious multi-party machine learning on trusted processors,” inProc. of USENIX Security, 2016

  4. [12]

    Achieving keyless cdns with conclaves,

    S. Herwig, C. Garman, and D. Levin, “Achieving keyless cdns with conclaves,” inProc. of USENIX Security, 2020

  5. [13]

    IRON: functional encryption using intel SGX,

    B. Fisch, D. Vinayagamurthy, D. Boneh, and S. Gorbunov, “IRON: functional encryption using intel SGX,” inProc. of ACM CCS, 2017

  6. [14]

    Ekiden: A platform for confidentiality- preserving, trustworthy, and performant smart contracts,

    R. Cheng, F. Zhang, J. Kos, W. He, N. Hynes, N. M. Johnson, A. Juels, A. Miller, and D. Song, “Ekiden: A platform for confidentiality- preserving, trustworthy, and performant smart contracts,” inProc. of IEEE EuroS&P, 2019

  7. [15]

    Teechain: a secure payment network with asynchronous blockchain access,

    J. Lind, O. Naor, I. Eyal, F. Kelbert, E. G. Sirer, and P. R. Pietzuch, “Teechain: a secure payment network with asynchronous blockchain access,” inProc. of ACM SOSP, 2019

  8. [16]

    Town crier: An authenticated data feed for smart contracts,

    F. Zhang, E. Cecchetti, K. Croman, A. Juels, and E. Shi, “Town crier: An authenticated data feed for smart contracts,” inProc. of ACM CCS, 2016

  9. [17]

    BITE: bitcoin lightweight client privacy using trusted execution,

    S. Matetic, K. W ¨ust, M. Schneider, K. Kostiainen, G. Karame, and S. Capkun, “BITE: bitcoin lightweight client privacy using trusted execution,” inProc. of USENIX Security, 2019

  10. [18]

    Mercury: Practical cross-chain exchange via trusted hardware,

    X. Wen, Q. Feng, J. Niu, Y . Zhang, and C. Feng, “Mercury: Practical cross-chain exchange via trusted hardware,”IEEE Trans. Dependable Secur. Comput., vol. 23, no. 2, pp. 2949–2961, 2026

  11. [19]

    Teerollup: Efficient rollup design using heterogeneous TEE,

    X. Wen, Q. Feng, H. Lyu, J. Niu, Y . Zhang, and C. Feng, “Teerollup: Efficient rollup design using heterogeneous TEE,”IEEE Trans. Com- puters, vol. 74, no. 10, pp. 3546–3558, 2025

  12. [20]

    Sgxpectre: Stealing intel secrets from SGX enclaves via speculative execution,

    G. Chen, S. Chen, Y . Xiao, Y . Zhang, Z. Lin, and T. Lai, “Sgxpectre: Stealing intel secrets from SGX enclaves via speculative execution,” in Proc. of IEEE EuroS&P, 2019

  13. [21]

    Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of- order execution,

    J. V . Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. F. Wenisch, Y . Yarom, and R. Strackx, “Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of- order execution,” inProc. of USENIX Security, 2018

  14. [22]

    A systematic look at ciphertext side channels on AMD SEV-SNP,

    M. Li, L. Wilke, J. Wichelmann, T. Eisenbarth, R. Teodorescu, and Y . Zhang, “A systematic look at ciphertext side channels on AMD SEV-SNP,” inProc. IEEE S&P, 2022

  15. [23]

    Insecure until proven updated: Analyzing AMD sev’s remote attestation,

    R. Buhren, C. Werling, and J. Seifert, “Insecure until proven updated: Analyzing AMD sev’s remote attestation,” inProc. of ACM CCS, 2019

  16. [24]

    One glitch to rule them all: Fault injection attacks against amd’s secure encrypted virtualization,

    R. Buhren, H. N. Jacob, T. Krachenfels, and J. Seifert, “One glitch to rule them all: Fault injection attacks against amd’s secure encrypted virtualization,” inProc. of ACM CCS, 2021

  17. [25]

    Ar- mageddon: Cache attacks on mobile devices,

    M. Lipp, D. Gruss, R. Spreitzer, C. Maurice, and S. Mangard, “Ar- mageddon: Cache attacks on mobile devices,” inProc. of USENIX Security, 2016

  18. [26]

    High-resolution side channels for untrusted operating systems,

    M. H ¨ahnel, W. Cui, and M. Peinado, “High-resolution side channels for untrusted operating systems,” inProc. of USENIX ATC, 2017

  19. [27]

    Inferring fine-grained control flow inside SGX enclaves with branch shadowing,

    S. Lee, M. Shih, P. Gera, T. Kim, H. Kim, and M. Peinado, “Inferring fine-grained control flow inside SGX enclaves with branch shadowing,” inProc. of USENIX Security, 2017

  20. [28]

    Hacking in darkness: Return-oriented programming against secure enclaves,

    J. Lee, J. S. Jang, Y . Jang, N. Kwak, Y . Choi, C. Choi, T. Kim, M. Peinado, and B. B. Kang, “Hacking in darkness: Return-oriented programming against secure enclaves,” inProc. of USENIX Security, 2017

  21. [29]

    Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution,

    J. V . Bulck, N. Weichbrodt, R. Kapitza, F. Piessens, and R. Strackx, “Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution,” inProc. of USENIX Security, 2017

  22. [30]

    Tdxdown: Single-stepping and instruction counting attacks against intel TDX,

    L. Wilke, F. Sieck, and T. Eisenbarth, “Tdxdown: Single-stepping and instruction counting attacks against intel TDX,” inProc. of ACM CCS, 2024

  23. [31]

    Tdxploit: Novel techniques for single-stepping and cache attacks on intel TDX,

    F. Rauscher, L. Wilke, H. Weissteiner, T. Eisenbarth, and D. Gruss, “Tdxploit: Novel techniques for single-stepping and cache attacks on intel TDX,” inProc. of USENIX Security, 2025

  24. [32]

    Reflections on trusting distributed trust,

    E. Dauterman, V . Fang, N. Crooks, and R. A. Popa, “Reflections on trusting distributed trust,” inProc. of HotNets, 2022

  25. [33]

    Spectre attacks: Exploiting speculative execution,

    P. Kocher, J. Horn, A. Fogh, D. Genkin, D. Gruss, W. Haas, M. Ham- burg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y . Yarom, “Spectre attacks: Exploiting speculative execution,” inProc. of IEEE S&P, 2019

  26. [34]

    Meltdown: Reading kernel memory from user space,

    M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, A. Fogh, J. Horn, S. Mangard, P. Kocher, D. Genkin, Y . Yarom, and M. Hamburg, “Meltdown: Reading kernel memory from user space,” inProc. of USENIX Security, 2018

  27. [35]

    Trusted execution environments: Properties, applications, and challenges,

    P. Jauernig, A. Sadeghi, and E. Stapf, “Trusted execution environments: Properties, applications, and challenges,”IEEE Secur. Priv., vol. 18, no. 2, pp. 56–60, 2020

  28. [36]

    Sok: Understanding design choices and pitfalls of trusted execution environments,

    M. Li, Y . Yang, G. Chen, M. Yan, and Y . Zhang, “Sok: Understanding design choices and pitfalls of trusted execution environments,” inProc. of the 19th ACM AsiaCCS, 2024

  29. [37]

    Denial of service in sensor networks,

    A. D. Wood and J. A. Stankovic, “Denial of service in sensor networks,”Computer, vol. 35, no. 10, pp. 54–62, 2002

  30. [38]

    Side-channel attacks: Ten years after its publication and the impacts on cryptographic module security testing,

    Y . Zhou and D. Feng, “Side-channel attacks: Ten years after its publication and the impacts on cryptographic module security testing,” IACR Cryptol. ePrint Arch., p. 388, 2005

  31. [39]

    Secret key recovery in a global-scale end-to-end encryption system,

    G. Connell, V . Fang, R. Schmidt, E. Dauterman, and R. A. Popa, “Secret key recovery in a global-scale end-to-end encryption system,” inProc. of USENIX OSDI, 2024

  32. [40]

    Signalapp/securevaluerecovery2,

    “Signalapp/securevaluerecovery2,” 2025. [Online]. Available: https: //github.com/signalapp/SecureValueRecovery2

  33. [41]

    Tesseract: Real-time cryptocurrency exchange using trusted hard- ware,

    I. Bentov, Y . Ji, F. Zhang, L. Breidenbach, P. Daian, and A. Juels, “Tesseract: Real-time cryptocurrency exchange using trusted hard- ware,” inProc. of ACM CCS, 2019

  34. [42]

    Proactive secret sharing or: How to cope with perpetual leakage,

    A. Herzberg, S. Jarecki, H. Krawczyk, and M. Yung, “Proactive secret sharing or: How to cope with perpetual leakage,” inProc. of CRYPTO, 1995

  35. [43]

    Adaptive security for threshold cryptosystems,

    R. Canetti, R. Gennaro, S. Jarecki, H. Krawczyk, and T. Rabin, “Adaptive security for threshold cryptosystems,” inProc. of CRYPTO, 1999

  36. [44]

    COBRA: dynamic proactive secret sharing for confidential BFT services,

    R. Vassantlal, E. Alchieri, B. Ferreira, and A. Bessani, “COBRA: dynamic proactive secret sharing for confidential BFT services,” in Proc. of IEEE S&P, 2022

  37. [45]

    A next-generation smart contract and decentralized application platform,

    V . Buterin, “A next-generation smart contract and decentralized application platform,” vol. 3, no. 37, pp. 2–1, 2014. [Online]. Available: https://cryptorating.eu/whitepapers/Ethereum/Ethereum whi te paper.pdf

  38. [46]

    Governance of blockchain systems: Governance of and by distributed infrastructure,

    P. De Filippi and G. McMullen, “Governance of blockchain systems: Governance of and by distributed infrastructure,” Ph.D. dissertation, 2018

  39. [47]

    Avocado: A secure in-memory distributed storage system,

    M. Bailleu, D. Giantsidi, V . Gavrielatos, D. L. Quoc, V . Nagarajan, and P. Bhatotia, “Avocado: A secure in-memory distributed storage system,” inProc. of USENIX ATC, 2021

  40. [48]

    Bigsecret: A secure data management framework for key-value stores,

    E. Pattuk, M. Kantarcioglu, V . Khadilkar, H. Ulusoy, and S. Mehro- tra, “Bigsecret: A secure data management framework for key-value stores,” inProc. of IEEE CLOUD, 2013

  41. [49]

    Building an encrypted, distributed, and searchable key-value store,

    X. Yuan, X. Wang, C. Wang, C. Qian, and J. Lin, “Building an encrypted, distributed, and searchable key-value store,” inProc. of ACM AsiaCCS, 2016

  42. [50]

    Uncovering impact of mental models towards adoption of multi-device crypto-wallets,

    E. V . Mangipudi, U. Desai, M. Minaei, M. Mondal, and A. Kate, “Uncovering impact of mental models towards adoption of multi-device crypto-wallets,” inProc. of ACM CCS, 2023. 14

  43. [51]

    ”don’t put all your eggs in one basket

    Y . Yu, T. Sharma, S. Das, and Y . Wang, “”don’t put all your eggs in one basket”: How cryptocurrency users choose and secure their wallets,” inProc. of CHI, 2024

  44. [52]

    SECRECY: secure collaborative analytics in untrusted clouds,

    J. Liagouris, V . Kalavri, M. Faisal, and M. Varia, “SECRECY: secure collaborative analytics in untrusted clouds,” inProc. of USENIX NSDI, 2023

  45. [53]

    Prio: Private, robust, and scalable computation of aggregate statistics,

    H. Corrigan-Gibbs and D. Boneh, “Prio: Private, robust, and scalable computation of aggregate statistics,” inProc. of USENIX NSDI, 2017

  46. [54]

    DEMO: integrating MPC in big data workflows,

    N. V olgushev, M. Schwarzkopf, A. Lapets, M. Varia, and A. Bestavros, “DEMO: integrating MPC in big data workflows,” inProc. of ACM CCS, 2016

  47. [55]

    Shortcut: Making mpc-based collaborative analytics efficient on dynamic databases,

    P. Zhou, X. Guo, P. Chen, T. Li, S. Lv, and Z. Liu, “Shortcut: Making mpc-based collaborative analytics efficient on dynamic databases,” in Proc. of ACM CCS, 2024

  48. [56]

    Hotstuff: BFT consensus with linearity and responsiveness,

    M. Yin, D. Malkhi, M. K. Reiter, G. Golan-Gueta, and I. Abraham, “Hotstuff: BFT consensus with linearity and responsiveness,” inProc. of ACM PODC, 2019

  49. [57]

    Short signatures from the weil pairing,

    D. Boneh, B. Lynn, and H. Shacham, “Short signatures from the weil pairing,” inProc. of ASIACRYPT, 2001

  50. [58]

    MP-SPDZ: A versatile framework for multi-party compu- tation,

    M. Keller, “MP-SPDZ: A versatile framework for multi-party compu- tation,” inProc. of ACM CCS, 2020

  51. [59]

    Confidential computing for openpower,

    G. D. H. Hunt, R. Pai, M. V . Le, H. Jamjoom, S. Bhattiprolu, R. Boivie, L. Dufour, B. Frey, M. Kapur, K. A. Goldman, R. Grimm, J. Janakirman, J. M. Ludden, P. Mackerras, C. May, E. R. Palmer, B. B. Rao, L. Roy, W. A. Starke, J. Stuecheli, E. Valdez, and W. V oigt, “Confidenti...

  52. [60]

    Keystone: an open framework for architecting trusted execution envi- ronments,

    D. Lee, D. Kohlbrenner, S. Shinde, K. Asanovic, and D. Song, “Keystone: an open framework for architecting trusted execution envi- ronments,” inProc. of EuroSys, 2020

  53. [61]

    Sanctum: Minimal hardware extensions for strong software isolation,

    V . Costan, I. A. Lebedev, and S. Devadas, “Sanctum: Minimal hardware extensions for strong software isolation,” inProc. of USENIX Security, 2016

  54. [62]

    CURE: A security architecture with cus- tomizable and resilient enclaves,

    R. Bahmani, F. Brasser, G. Dessouky, P. Jauernig, M. Klimmek, A. Sadeghi, and E. Stapf, “CURE: A security architecture with cus- tomizable and resilient enclaves,” inProc. of USENIX Security, 2021

  55. [63]

    TIMBER-V: tag-isolated memory bringing fine-grained enclaves to RISC-V,

    S. Weiser, M. Werner, F. Brasser, M. Malenko, S. Mangard, and A. Sadeghi, “TIMBER-V: tag-isolated memory bringing fine-grained enclaves to RISC-V,” inProc. of NDSS, 2019

  56. [64]

    Controlled-channel attacks: Deter- ministic side channels for untrusted operating systems,

    Y . Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deter- ministic side channels for untrusted operating systems,” inProc. of IEEE S&P, 2015

  57. [65]

    Plundervolt: Software-based fault injection attacks against intel SGX,

    K. Murdock, D. F. Oswald, F. D. Garcia, J. V . Bulck, D. Gruss, and F. Piessens, “Plundervolt: Software-based fault injection attacks against intel SGX,” inProc. of IEEE S&P, 2020

  58. [66]

    Æpic leak: Architecturally leaking uninitialized data from the microarchitecture,

    P. Borrello, A. Kogler, M. Schwarzl, M. Lipp, D. Gruss, and M. Schwarz, “Æpic leak: Architecturally leaking uninitialized data from the microarchitecture,” inProc. of USENIX Security, 2022

  59. [67]

    Iago attacks: why the system call API is a bad untrusted RPC interface,

    S. Checkoway and H. Shacham, “Iago attacks: why the system call API is a bad untrusted RPC interface,” inProc. of ACM ASPLOS, 2013

  60. [68]

    Async- shock: Exploiting synchronisation bugs in intel SGX enclaves,

    N. Weichbrodt, A. Kurmus, P. R. Pietzuch, and R. Kapitza, “Async- shock: Exploiting synchronisation bugs in intel SGX enclaves,” inProc. of ESORICS, 2016

  61. [69]

    T-SGX: eradicating controlled-channel attacks against enclave programs,

    M. Shih, S. Lee, T. Kim, and M. Peinado, “T-SGX: eradicating controlled-channel attacks against enclave programs,” inProc. of NDSS, 2017

  62. [70]

    Leaky cauldron on the dark land: Understanding memory side-channel hazards in SGX,

    W. Wang, G. Chen, X. Pan, Y . Zhang, X. Wang, V . Bindschaedler, H. Tang, and C. A. Gunter, “Leaky cauldron on the dark land: Understanding memory side-channel hazards in SGX,” inProc. of ACM CCS, 2017

  63. [71]

    How to share a secret,

    A. Shamir, “How to share a secret,”Commun. ACM, vol. 22, no. 11, pp. 612–613, 1979

  64. [72]

    Society and group oriented cryptography: A new con- cept,

    Y . Desmedt, “Society and group oriented cryptography: A new con- cept,” inProc. of CRYPTO, 1987

  65. [73]

    APSS: proactive secret sharing in asynchronous systems,

    L. Zhou, F. B. Schneider, and R. van Renesse, “APSS: proactive secret sharing in asynchronous systems,”ACM Trans. Inf. Syst. Secur., vol. 8, no. 3, pp. 259–286, 2005

  66. [74]

    MPSS: mobile proactive secret sharing,

    D. A. Schultz, B. Liskov, and M. D. Liskov, “MPSS: mobile proactive secret sharing,”ACM Trans. Inf. Syst. Secur., vol. 13, no. 4, pp. 34:1– 34:32, 2010

  67. [75]

    Communication-optimal proactive secret sharing for dynamic groups,

    J. Baron, K. E. Defrawy, J. Lampkins, and R. Ostrovsky, “Communication-optimal proactive secret sharing for dynamic groups,” inProc. of ACNS, 2015

  68. [76]

    CHURP: dynamic-committee proactive secret sharing,

    S. K. D. Maram, F. Zhang, L. Wang, A. Low, Y . Zhang, A. Juels, and D. Song, “CHURP: dynamic-committee proactive secret sharing,” in Proc. of ACM CCS, 2019

  69. [77]

    Protocols for secure computations (extended abstract),

    A. C. Yao, “Protocols for secure computations (extended abstract),” in Proc. of FOCS, 1982

  70. [78]

    Secure multiparty computation,

    Y . Lindell, “Secure multiparty computation,”Commun. ACM, vol. 64, no. 1, pp. 86–96, 2021

  71. [79]

    An introduction to secret-sharing-based secure multi- party computation,

    D. Escudero, “An introduction to secret-sharing-based secure multi- party computation,”IACR Cryptol. ePrint Arch., p. 62, 2022

  72. [80]

    Practical byzantine fault tolerance and proactive recovery,

    M. Castro and B. Liskov, “Practical byzantine fault tolerance and proactive recovery,”ACM Trans. Comput. Syst., vol. 20, no. 4, pp. 398–461, 2002

  73. [81]

    Trusted computing base recovery,

    “Trusted computing base recovery,” Intel, 2025. [Online]. Available: https://www.intel.com/content/www/us/en/developer/articles/technical /software-security-guidance/best-practices/trusted-computing-base-rec overy.html

  74. [82]

    Affected processors: Transient execution attacks & related security,

    “Affected processors: Transient execution attacks & related security,” Intel, 2025. [Online]. Available: https://www.intel.com/content/www/ us/en/developer/topic-technology/software-security-guidance/processo rs-affected-consolidated-product-cpu-model.html

  75. [83]

    Amd sev confidential computing vulnerability,

    “Amd sev confidential computing vulnerability,” AMD, 2025. [Online]. Available: https://www.amd.com/en/resources/product-security/bulletin /amd-sb-3019.html

  76. [84]

    Ladon: High-performance multi-bft consensus via dynamic global ordering,

    H. Lyu, S. Xie, J. Niu, C. Feng, Y . Zhang, and I. Beschastnikh, “Ladon: High-performance multi-bft consensus via dynamic global ordering,” inProc. of EuroSys, 2025

  77. [85]

    Fast-hotstuff: A fast and robust BFT protocol for blockchains,

    M. M. Jalalzai, J. Niu, C. Feng, and F. Gai, “Fast-hotstuff: A fast and robust BFT protocol for blockchains,”IEEE Trans. Dependable Secur. Comput., vol. 21, no. 4, pp. 2478–2493, 2024

  78. [86]

    A practical scheme for non-interactive verifiable secret sharing,

    P. Feldman, “A practical scheme for non-interactive verifiable secret sharing,” inProc. of FOCS, 1987

  79. [87]

    MAGE: mutual attestation for a group of enclaves without trusted third parties,

    G. Chen and Y . Zhang, “MAGE: mutual attestation for a group of enclaves without trusted third parties,” inProc. USENIX Security, 2022

  80. [88]

    A framework for constructing fast MPC over arithmetic circuits with malicious adversaries and an honest-majority,

    Y . Lindell and A. Nof, “A framework for constructing fast MPC over arithmetic circuits with malicious adversaries and an honest-majority,” inProc. of ACM CCS, 2017

  81. [89]

    Hot-stuff/libhotstuff,

    “Hot-stuff/libhotstuff,” https://github.com/hot-stuff/libhotstuff, Jan. 2018

  82. [90]

    Intel® tdx connect architecture specification,

    “Intel® tdx connect architecture specification,” https://www.intel.com/content/www/us/en/content- details/773614/intel-tdx-connect-architecture-specification.html, 2023

  83. [91]

    From byzantine consensus to BFT state machine replication: A latency-optimal transformation,

    J. Sousa and A. N. Bessani, “From byzantine consensus to BFT state machine replication: A latency-optimal transformation,” inProc. of IEEE EDCC, 2012

  84. [92]

    [Online]

    (2026) Aws key management service documentation. [Online]. Available: https://docs.aws.amazon.com/kms/

  85. [93]

    [Online]

    (2026) Azure key vault overview - azure key vault. [Online]. Available: https://learn.microsoft.com/en-us/azure/key-vault/general/overview

  86. [94]

    [Online]

    (2026) Safe{Wallet}. [Online]. Available: https://safe.global/

  87. [95]

    [Online]

    (2026) Fireblocks. [Online]. Available: https://www.fireblocks.com/

  88. [96]

    Private join and compute from PIR with default,

    T. Lepoint, S. Patel, M. Raykova, K. Seth, and N. Trieu, “Private join and compute from PIR with default,” inProc. of ASIACRYPT, 2021

  89. [97]

    ROTE: rollback protection for trusted execution,

    S. Matetic, M. Ahmed, K. Kostiainen, A. Dhar, D. M. Sommer, A. Gervais, A. Juels, and S. Capkun, “ROTE: rollback protection for trusted execution,” inProc. of USENIX Security, 2017

  90. [98]

    NARRATOR: secure and practical state continuity for trusted execution in the cloud,

    J. Niu, W. Peng, X. Zhang, and Y . Zhang, “NARRATOR: secure and practical state continuity for trusted execution in the cloud,” inProc. of ACM CCS, 2022

  91. [99]

    Ensuring state continuity for confidential computing: A blockchain-based approach,

    W. Peng, X. Li, J. Niu, X. Zhang, and Y . Zhang, “Ensuring state continuity for confidential computing: A blockchain-based approach,” IEEE Trans. Dependable Secur. Comput., vol. 21, no. 6, pp. 5635–5649, 2024

  92. [100]

    Formally verifying a rollback-prevention protocol for tees,

    W. Wang, J. Niu, M. K. Reiter, and Y . Zhang, “Formally verifying a rollback-prevention protocol for tees,” inProc. of FORTE, 2024

  93. [101]

    Nimble: Rollback protection for confidential cloud services,

    S. Angel, A. Basu, W. Cui, T. Jaeger, S. Lau, S. T. V . Setty, and S. Singanamalla, “Nimble: Rollback protection for confidential cloud services,” inProc. of USENIX OSDI, 2023

  94. [102]

    RR: A fault model for efficient TEE replication,

    B. Dinis, P. Druschel, and R. Rodrigues, “RR: A fault model for efficient TEE replication,” inProc. of NDSS, 2023

  95. [103]

    Achilles: Efficient tee-assisted BFT consensus via rollback resilient recovery,

    J. Niu, X. Wen, G. Wu, S. Liu, J. Yu, and Y . Zhang, “Achilles: Efficient tee-assisted BFT consensus via rollback resilient recovery,” inProc. of EuroSys, 2025. 15

  96. [104]

    ENGRAFT: enclave-guarded raft on byzantine faulty nodes,

    W. Wang, S. Deng, J. Niu, M. K. Reiter, and Y . Zhang, “ENGRAFT: enclave-guarded raft on byzantine faulty nodes,” inProc. of ACM CCS, 2022

  97. [105]

    Confidential consortium framework: Secure multiparty applications with confidentiality, integrity, and high availability,

    H. Howard, F. Alder, E. Ashton, A. Chamayou, S. Clebsch, M. Costa, A. Delignat-Lavaud, C. Fournet, A. Jeffery, M. Kerner, F. Kounelis, M. A. Kuppe, J. Maffre, M. Russinovich, and C. M. Wintersteiger, “Confidential consortium framework: Secure multiparty applications with confi...

  98. [106]

    Chameleon: A hybrid secure computation frame- work for machine learning applications,

    M. S. Riazi, C. Weinert, O. Tkachenko, E. M. Songhori, T. Schneider, and F. Koushanfar, “Chameleon: A hybrid secure computation frame- work for machine learning applications,” inProc. of ACM AsiaCCS, 2018

  99. [107]

    Correlated randomness teleportation via semi-trusted hardware - enabling silent multi-party computation,

    Y . Lu, B. Zhang, H. Zhou, W. Liu, L. Zhang, and K. Ren, “Correlated randomness teleportation via semi-trusted hardware - enabling silent multi-party computation,” inProc. of ESORICS, 2021

  100. [108]

    Hybrid trust multi- party computation with trusted execution environment,

    P. Wu, J. Ning, J. Shen, H. Wang, and E. Chang, “Hybrid trust multi- party computation with trusted execution environment,” inProc. of NDSS, 2022

  101. [109]

    Towards efficient and practical multi-party computation under inconsistent trust in tees,

    X. Hu, R. Li, Y . Liu, and Q. Wang, “Towards efficient and practical multi-party computation under inconsistent trust in tees,” inProc. of IEEE S&P, 2025

  102. [110]

    The deployment dilemma: Merits & challenges of deploying mpc,

    “The deployment dilemma: Merits & challenges of deploying mpc,”

  103. [111]

    Available: https://mpc.cs.berkeley.edu/blog/deploymen t-dilemma.html

    [Online]. Available: https://mpc.cs.berkeley.edu/blog/deploymen t-dilemma.html

  104. [112]

    Unconditional communication-efficient MPC via hall’s marriage theorem,

    V . Goyal, A. Polychroniadou, and Y . Song, “Unconditional communication-efficient MPC via hall’s marriage theorem,” inProc. of CRYPTO, 2021

  105. [113]

    Scalable multiparty garbling,

    G. Beck, A. Goel, A. Hegde, A. Jain, Z. Jin, and G. Kaptchuk, “Scalable multiparty garbling,” inProc. of ACM CCS, 2023

  106. [114]

    [Online]

    (2023) How confidential space and mpc can help secure digital assets. [Online]. Available: https://cloud.google.com/blog/products/identity-s ecurity/how-confidential-space-and-mpc-can-help-secure-digital-asset s

  107. [115]

    Covault: Secure, scalable analytics of personal data,

    R. D. Viti, I. Sheff, N. Glaeser, B. Dinis, R. Rodrigues, B. Bhattachar- jee, A. Hithnawi, D. Garg, and P. Druschel, “Covault: Secure, scalable analytics of personal data,” inProc. of USENIX Security, 2025. APPENDIX A. Complementarity of MPC and Heterogeneous TEEs Deploying MP...

Pith tools

Reviewed June 28, 2026 · model on record in the stance chip above.