{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:3LM6SJDEVVONUB773N4ZYIYDIA","short_pith_number":"pith:3LM6SJDE","schema_version":"1.0","canonical_sha256":"dad9e92464ad5cda07ffdb799c230340107588e4c652f816d6d8eb0f30909566","source":{"kind":"arxiv","id":"2407.16694","version":1},"attestation_state":"computed","paper":{"title":"Aster: Fixing the Android TEE Ecosystem with Arm CCA","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Andrin Bertschi, Mark Kuhne, Nicolas Dutly, Shweta Shinde, Srdjan Capkun, Supraja Sridhara","submitted_at":"2024-07-23T17:57:36Z","abstract_excerpt":"The Android ecosystem relies on either TrustZone (e.g., OP-TEE, QTEE, Trusty) or trusted hypervisors (pKVM, Gunyah) to isolate security-sensitive services from malicious apps and Android bugs. TrustZone allows any secure world code to access the normal world that runs Android. Similarly, a trusted hypervisor has full access to Android running in one VM and security services in other VMs. In this paper, we motivate the need for mutual isolation, wherein Android, hypervisors, and the secure world are isolated from each other. Then, we propose a sandboxed service abstraction, such that a sandboxe"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.16694","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-07-23T17:57:36Z","cross_cats_sorted":[],"title_canon_sha256":"ee844755a547ddf29d2cde09ca731d4f8251d615b08f44b0f790d86f95ee8200","abstract_canon_sha256":"fa09d4054f68a1487d067c0d38d6b2ea77b411d2fee4f7b09fb9f3d3da3cd6d5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:47:36.991161Z","signature_b64":"7cPQNsLsXo4q+HlA5uMJKk/gGd0iPO+xIUiQrUulPtNSxf31dkBOI2gzWquCPEnISIEMKMsIi5+pnsjnj7iDCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dad9e92464ad5cda07ffdb799c230340107588e4c652f816d6d8eb0f30909566","last_reissued_at":"2026-07-05T08:47:36.990659Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:47:36.990659Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Aster: Fixing the Android TEE Ecosystem with Arm CCA","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Andrin Bertschi, Mark Kuhne, Nicolas Dutly, Shweta Shinde, Srdjan Capkun, Supraja Sridhara","submitted_at":"2024-07-23T17:57:36Z","abstract_excerpt":"The Android ecosystem relies on either TrustZone (e.g., OP-TEE, QTEE, Trusty) or trusted hypervisors (pKVM, Gunyah) to isolate security-sensitive services from malicious apps and Android bugs. TrustZone allows any secure world code to access the normal world that runs Android. Similarly, a trusted hypervisor has full access to Android running in one VM and security services in other VMs. In this paper, we motivate the need for mutual isolation, wherein Android, hypervisors, and the secure world are isolated from each other. Then, we propose a sandboxed service abstraction, such that a sandboxe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.16694","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.16694/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.16694","created_at":"2026-07-05T08:47:36.990723+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.16694v1","created_at":"2026-07-05T08:47:36.990723+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.16694","created_at":"2026-07-05T08:47:36.990723+00:00"},{"alias_kind":"pith_short_12","alias_value":"3LM6SJDEVVON","created_at":"2026-07-05T08:47:36.990723+00:00"},{"alias_kind":"pith_short_16","alias_value":"3LM6SJDEVVONUB77","created_at":"2026-07-05T08:47:36.990723+00:00"},{"alias_kind":"pith_short_8","alias_value":"3LM6SJDE","created_at":"2026-07-05T08:47:36.990723+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.26018","citing_title":"Shielded but Lightweight: Building Practical Confidential Containers with ARM CCA","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2512.01594","citing_title":"CAEC: Confidential, Attestable, and Efficient Inter-CVM Communication with Arm CCA","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2604.18231","citing_title":"AgenTEE: Confidential LLM Agent Execution on Edge Devices","ref_index":28,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA","json":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA.json","graph_json":"https://pith.science/api/pith-number/3LM6SJDEVVONUB773N4ZYIYDIA/graph.json","events_json":"https://pith.science/api/pith-number/3LM6SJDEVVONUB773N4ZYIYDIA/events.json","paper":"https://pith.science/paper/3LM6SJDE"},"agent_actions":{"view_html":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA","download_json":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA.json","view_paper":"https://pith.science/paper/3LM6SJDE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.16694&json=true","fetch_graph":"https://pith.science/api/pith-number/3LM6SJDEVVONUB773N4ZYIYDIA/graph.json","fetch_events":"https://pith.science/api/pith-number/3LM6SJDEVVONUB773N4ZYIYDIA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA/action/storage_attestation","attest_author":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA/action/author_attestation","sign_citation":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA/action/citation_signature","submit_replication":"https://pith.science/pith/3LM6SJDEVVONUB773N4ZYIYDIA/action/replication_record"}},"created_at":"2026-07-05T08:47:36.990723+00:00","updated_at":"2026-07-05T08:47:36.990723+00:00"}