REVIEW 2 cited by
SoK: TEE-assisted Confidential Smart Contract
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The blockchain-based smart contract lacks privacy since the contract state and instruction code are exposed to the public. Combining smart-contract execution with Trusted Execution Environments (TEEs) provides an efficient solution, called TEE-assisted smart contracts, for protecting the confidentiality of contract states. However, the combination approaches are varied, and a systematic study is absent. Newly released systems may fail to draw upon the experience learned from existing protocols, such as repeating known design mistakes or applying TEE technology in insecure ways. In this paper, we first investigate and categorize the existing systems into two types: the layer-one solution and layer-two solution. Then, we establish an analysis framework to capture their common lights, covering the desired properties (for contract services), threat models, and security considerations (for underlying systems). Based on our taxonomy, we identify their ideal functionalities and uncover the fundamental flaws and reasons for the challenges in each specification design. We believe that this work would provide a guide for the development of TEE-assisted smart contracts, as well as a framework to evaluate future TEE-assisted confidential contract systems.
Forward citations
Cited by 2 Pith papers
-
Share No More Than the Request Requires: Federated Disclosure for Perspective-Aware AI
A new protocol formalizes minimum-necessary selective disclosure over temporal knowledge graphs of personal data, but is not yet implemented.
-
Narrowing the Gap between TEEs Threat Model and Deployment Strategies
TEE attestation should include a hardware-bound platform identifier (PPID) so users can verify which cloud provider's infrastructure hosts a confidential VM.
Discussion (0). Continue with ORCID to comment.