{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:NXOGQOVNNCCQZL4VOKEKAPYCR2","short_pith_number":"pith:NXOGQOVN","canonical_record":{"source":{"id":"1905.10723","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-26T04:34:07Z","cross_cats_sorted":[],"title_canon_sha256":"d3018e23da5df225f3401fb2f6c3aa7ea989de27af278ef02f88d0fbdbdc19ce","abstract_canon_sha256":"e89c9af4bb6648d83d17c5b9138b551f13af6e52005d2c7ab185b1b5759ba847"},"schema_version":"1.0"},"canonical_sha256":"6ddc683aad68850caf957288a03f028eb896669e9799fd5ca482c05f601c67d5","source":{"kind":"arxiv","id":"1905.10723","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.10723","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"arxiv_version","alias_value":"1905.10723v1","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.10723","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"pith_short_12","alias_value":"NXOGQOVNNCCQ","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"NXOGQOVNNCCQZL4V","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"NXOGQOVN","created_at":"2026-05-18T12:33:24Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:NXOGQOVNNCCQZL4VOKEKAPYCR2","target":"record","payload":{"canonical_record":{"source":{"id":"1905.10723","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-26T04:34:07Z","cross_cats_sorted":[],"title_canon_sha256":"d3018e23da5df225f3401fb2f6c3aa7ea989de27af278ef02f88d0fbdbdc19ce","abstract_canon_sha256":"e89c9af4bb6648d83d17c5b9138b551f13af6e52005d2c7ab185b1b5759ba847"},"schema_version":"1.0"},"canonical_sha256":"6ddc683aad68850caf957288a03f028eb896669e9799fd5ca482c05f601c67d5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:45:05.450762Z","signature_b64":"KkbA4AsrbWPDqeRLWz3uKsaFO2i9FyKsb3qx0vPxdeqUqcAnTDIqEuZOcfPRuUVsJVuBjxNZN/oHr7SuS6RYAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6ddc683aad68850caf957288a03f028eb896669e9799fd5ca482c05f601c67d5","last_reissued_at":"2026-05-17T23:45:05.450059Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:45:05.450059Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.10723","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Etp0Ue+tltSFkPXzAu03qmcgYXjGYwh2FpVPIboSmbs83t5zn8ydh0rIFCMjtqQp3AnabhNuJjiQd9em07w8Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T15:45:21.934104Z"},"content_sha256":"ab1a3d57cb419cfa02220f40c2cbbbe5348da6fb9564776eeba1a40dcb3568d8","schema_version":"1.0","event_id":"sha256:ab1a3d57cb419cfa02220f40c2cbbbe5348da6fb9564776eeba1a40dcb3568d8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:NXOGQOVNNCCQZL4VOKEKAPYCR2","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"TEE-aided Write Protection Against Privileged Data Tampering","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Lianying Zhao, Mohammad Mannan","submitted_at":"2019-05-26T04:34:07Z","abstract_excerpt":"Unauthorized data alteration has been a longstanding threat since the emergence of malware. System and application software can be reinstalled and hardware can be replaced, but user data is priceless in many cases. Especially in recent years, ransomware has become high-impact due to its direct monetization model. State-of-the-art defenses are mostly based on known signature or behavior analysis, and more importantly, require an uncompromised OS kernel. However, malware with the highest software privileges has shown its obvious existence. We propose to move from current detection/recovery based"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.10723","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Pi7WmCsghWTdfJXPSRuo/2tuTqUMeaXfxKe7aZMaQZMfkGi0Ejb3bL7btFJN9i3sCfAZBLZ5oWcaFzPNROWdAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T15:45:21.934462Z"},"content_sha256":"ef436f0a9e4249315bacb2b7582a01e9563e17cd0632a2d6aac9b2365508598b","schema_version":"1.0","event_id":"sha256:ef436f0a9e4249315bacb2b7582a01e9563e17cd0632a2d6aac9b2365508598b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/bundle.json","state_url":"https://pith.science/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T15:45:21Z","links":{"resolver":"https://pith.science/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2","bundle":"https://pith.science/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/bundle.json","state":"https://pith.science/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/state.json","well_known_bundle":"https://pith.science/.well-known/pith/NXOGQOVNNCCQZL4VOKEKAPYCR2/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:NXOGQOVNNCCQZL4VOKEKAPYCR2","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e89c9af4bb6648d83d17c5b9138b551f13af6e52005d2c7ab185b1b5759ba847","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-26T04:34:07Z","title_canon_sha256":"d3018e23da5df225f3401fb2f6c3aa7ea989de27af278ef02f88d0fbdbdc19ce"},"schema_version":"1.0","source":{"id":"1905.10723","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.10723","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"arxiv_version","alias_value":"1905.10723v1","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.10723","created_at":"2026-05-17T23:45:05Z"},{"alias_kind":"pith_short_12","alias_value":"NXOGQOVNNCCQ","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"NXOGQOVNNCCQZL4V","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"NXOGQOVN","created_at":"2026-05-18T12:33:24Z"}],"graph_snapshots":[{"event_id":"sha256:ef436f0a9e4249315bacb2b7582a01e9563e17cd0632a2d6aac9b2365508598b","target":"graph","created_at":"2026-05-17T23:45:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Unauthorized data alteration has been a longstanding threat since the emergence of malware. System and application software can be reinstalled and hardware can be replaced, but user data is priceless in many cases. Especially in recent years, ransomware has become high-impact due to its direct monetization model. State-of-the-art defenses are mostly based on known signature or behavior analysis, and more importantly, require an uncompromised OS kernel. However, malware with the highest software privileges has shown its obvious existence. We propose to move from current detection/recovery based","authors_text":"Lianying Zhao, Mohammad Mannan","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-26T04:34:07Z","title":"TEE-aided Write Protection Against Privileged Data Tampering"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.10723","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ab1a3d57cb419cfa02220f40c2cbbbe5348da6fb9564776eeba1a40dcb3568d8","target":"record","created_at":"2026-05-17T23:45:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e89c9af4bb6648d83d17c5b9138b551f13af6e52005d2c7ab185b1b5759ba847","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-26T04:34:07Z","title_canon_sha256":"d3018e23da5df225f3401fb2f6c3aa7ea989de27af278ef02f88d0fbdbdc19ce"},"schema_version":"1.0","source":{"id":"1905.10723","kind":"arxiv","version":1}},"canonical_sha256":"6ddc683aad68850caf957288a03f028eb896669e9799fd5ca482c05f601c67d5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6ddc683aad68850caf957288a03f028eb896669e9799fd5ca482c05f601c67d5","first_computed_at":"2026-05-17T23:45:05.450059Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:45:05.450059Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"KkbA4AsrbWPDqeRLWz3uKsaFO2i9FyKsb3qx0vPxdeqUqcAnTDIqEuZOcfPRuUVsJVuBjxNZN/oHr7SuS6RYAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:45:05.450762Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.10723","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ab1a3d57cb419cfa02220f40c2cbbbe5348da6fb9564776eeba1a40dcb3568d8","sha256:ef436f0a9e4249315bacb2b7582a01e9563e17cd0632a2d6aac9b2365508598b"],"state_sha256":"fb7ed76afa929b85a6992404fac4dcbc96013342ac1e43ce628e3d6237941e8c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ck72BCmYhfOosSNMjSXhHhJakviDj2WE5IZgiWJPYiUxnzCB6sdmfzFGxEnC+8305PN9AA/xTD0OONZcLIyzDw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T15:45:21.936337Z","bundle_sha256":"f4737a3bbb96713e7acf7f7f8980c7b4543b093b9e5664178bf5343225e546f0"}}