pith:QK4DWUDA
EBCC: Enclave-Backed Confidential Containers via OCI-Compatible Runtime Integration
EBCC lets TEE-backed confidential containers follow the standard OCI lifecycle without enlarging the protected TCB.
arxiv:2605.13676 v1 · 2026-05-13 · cs.CR
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{QK4DWUDAOI3Q7R6QDSBBT5PNG6}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
EBCC can make TEE-backed execution manageable through an OCI-style lifecycle without materially enlarging the protected-side TCB.
The backend adapter and lifecycle mediation preserve isolation and do not introduce new attack surfaces or require post-hoc security assumptions beyond standard TEE guarantees.
EBCC provides an OCI-compatible runtime architecture that unifies REE and TEE stages for confidential containers while preserving standard lifecycle operations behind a backend adapter.
References
Receipt and verification
| First computed | 2026-05-18T02:44:17.094818Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/QK4DWUDAOI3Q7R6QDSBBT5PNG6 \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "89508ee99d0011efe14d1fd4fdf081b0f6082f943424de3111e9ece4b4f62511",
"cross_cats_sorted": [],
"license": "http://creativecommons.org/licenses/by-nc-nd/4.0/",
"primary_cat": "cs.CR",
"submitted_at": "2026-05-13T15:35:12Z",
"title_canon_sha256": "849ced78a970a8c2e685b3cfa601c3ffafc4c618ce39a900a496f555b2f4a79c"
},
"schema_version": "1.0",
"source": {
"id": "2605.13676",
"kind": "arxiv",
"version": 1
}
}