{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:L64KPSYZKVE5YLXDH3I6SVEQFN","short_pith_number":"pith:L64KPSYZ","schema_version":"1.0","canonical_sha256":"5fb8a7cb195549dc2ee33ed1e954902b4fde7921889eff7599a784a3cac5c31f","source":{"kind":"arxiv","id":"1908.11143","version":3},"attestation_state":"computed","paper":{"title":"SGX-LKL: Securing the Host OS Interface for Trusted Execution","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.OS","authors_text":"Christian Priebe, Divya Muthukumaran, Huanzhou Zhu, Joshua Lind, Peter Pietzuch, Shujie Cui, Vasily A. Sartakov","submitted_at":"2019-08-29T10:25:37Z","abstract_excerpt":"Hardware support for trusted execution in modern CPUs enables tenants to shield their data processing workloads in otherwise untrusted cloud environments. Runtime systems for the trusted execution must rely on an interface to the untrusted host OS to use external resources such as storage, network, and other functions. Attackers may exploit this interface to leak data or corrupt the computation.\n  We describe SGX-LKL, a system for running Linux binaries inside of Intel SGX enclaves that only exposes a minimal, protected and oblivious host interface: the interface is (i) minimal because SGX-LKL"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1908.11143","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-29T10:25:37Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"83483b4b3e9a354b9f9fdea3688b820c4b6f6af7f0f167961f0f3a547f915c75","abstract_canon_sha256":"5648ecb9917449aa6921ec2c266d9e34b1990c8eccdc9caec9889bb35a6d2eb6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:34:17.132733Z","signature_b64":"VWfalHc0kWGEDL/XtDC/vUGZ0OdSsfMPpJ3OJsE/v1d7WVF7zh7wmMQdwUADsyy5906qHhmi/KlCrfHGz4fSBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5fb8a7cb195549dc2ee33ed1e954902b4fde7921889eff7599a784a3cac5c31f","last_reissued_at":"2026-07-05T00:34:17.132221Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:34:17.132221Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SGX-LKL: Securing the Host OS Interface for Trusted Execution","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.OS","authors_text":"Christian Priebe, Divya Muthukumaran, Huanzhou Zhu, Joshua Lind, Peter Pietzuch, Shujie Cui, Vasily A. Sartakov","submitted_at":"2019-08-29T10:25:37Z","abstract_excerpt":"Hardware support for trusted execution in modern CPUs enables tenants to shield their data processing workloads in otherwise untrusted cloud environments. Runtime systems for the trusted execution must rely on an interface to the untrusted host OS to use external resources such as storage, network, and other functions. Attackers may exploit this interface to leak data or corrupt the computation.\n  We describe SGX-LKL, a system for running Linux binaries inside of Intel SGX enclaves that only exposes a minimal, protected and oblivious host interface: the interface is (i) minimal because SGX-LKL"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1908.11143","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1908.11143/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1908.11143","created_at":"2026-07-05T00:34:17.132290+00:00"},{"alias_kind":"arxiv_version","alias_value":"1908.11143v3","created_at":"2026-07-05T00:34:17.132290+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1908.11143","created_at":"2026-07-05T00:34:17.132290+00:00"},{"alias_kind":"pith_short_12","alias_value":"L64KPSYZKVE5","created_at":"2026-07-05T00:34:17.132290+00:00"},{"alias_kind":"pith_short_16","alias_value":"L64KPSYZKVE5YLXD","created_at":"2026-07-05T00:34:17.132290+00:00"},{"alias_kind":"pith_short_8","alias_value":"L64KPSYZ","created_at":"2026-07-05T00:34:17.132290+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2508.20962","citing_title":"Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study","ref_index":165,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN","json":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN.json","graph_json":"https://pith.science/api/pith-number/L64KPSYZKVE5YLXDH3I6SVEQFN/graph.json","events_json":"https://pith.science/api/pith-number/L64KPSYZKVE5YLXDH3I6SVEQFN/events.json","paper":"https://pith.science/paper/L64KPSYZ"},"agent_actions":{"view_html":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN","download_json":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN.json","view_paper":"https://pith.science/paper/L64KPSYZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1908.11143&json=true","fetch_graph":"https://pith.science/api/pith-number/L64KPSYZKVE5YLXDH3I6SVEQFN/graph.json","fetch_events":"https://pith.science/api/pith-number/L64KPSYZKVE5YLXDH3I6SVEQFN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN/action/storage_attestation","attest_author":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN/action/author_attestation","sign_citation":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN/action/citation_signature","submit_replication":"https://pith.science/pith/L64KPSYZKVE5YLXDH3I6SVEQFN/action/replication_record"}},"created_at":"2026-07-05T00:34:17.132290+00:00","updated_at":"2026-07-05T00:34:17.132290+00:00"}