Pith. sign in
Pith Number

pith:QK4DWUDA

pith:2026:QK4DWUDAOI3Q7R6QDSBBT5PNG6
not attested not anchored not stored refs resolved

EBCC: Enclave-Backed Confidential Containers via OCI-Compatible Runtime Integration

Di Lu, Jianfeng Ma, Qingwen Zhang, Xuewen Dong, Yujia Liu, Yulong Shen, Zhiquan Liu

EBCC lets TEE-backed confidential containers follow the standard OCI lifecycle without enlarging the protected TCB.

arxiv:2605.13676 v1 · 2026-05-13 · cs.CR

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{QK4DWUDAOI3Q7R6QDSBBT5PNG6}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

EBCC can make TEE-backed execution manageable through an OCI-style lifecycle without materially enlarging the protected-side TCB.

C2weakest assumption

The backend adapter and lifecycle mediation preserve isolation and do not introduce new attack surfaces or require post-hoc security assumptions beyond standard TEE guarantees.

C3one line summary

EBCC provides an OCI-compatible runtime architecture that unifies REE and TEE stages for confidential containers while preserving standard lifecycle operations behind a backend adapter.

References

63 extracted · 63 resolved · 2 Pith anchors

[1] Crossing shifted moats: Replacing old bridges with new tunnels to confidential containers, 2024
[2] Serverless confidential containers: Challenges and experiences, 2024
[3] Scone: Secure linux containers with intel sgx, 2016
[4] Occlum: Secure and efficient multitasking inside a single enclave of intel sgx, 2020
[5] Graphene-sgx: A practical library os for unmodified applications on sgx, 2017
Receipt and verification
First computed 2026-05-18T02:44:17.094818Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed

Aliases

arxiv: 2605.13676 · arxiv_version: 2605.13676v1 · doi: 10.48550/arxiv.2605.13676 · pith_short_12: QK4DWUDAOI3Q · pith_short_16: QK4DWUDAOI3Q7R6Q · pith_short_8: QK4DWUDA
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/QK4DWUDAOI3Q7R6QDSBBT5PNG6 \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "89508ee99d0011efe14d1fd4fdf081b0f6082f943424de3111e9ece4b4f62511",
    "cross_cats_sorted": [],
    "license": "http://creativecommons.org/licenses/by-nc-nd/4.0/",
    "primary_cat": "cs.CR",
    "submitted_at": "2026-05-13T15:35:12Z",
    "title_canon_sha256": "849ced78a970a8c2e685b3cfa601c3ffafc4c618ce39a900a496f555b2f4a79c"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2605.13676",
    "kind": "arxiv",
    "version": 1
  }
}