{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:T7PRDZJ6AG4IJNV6DWFVR6LOEC","short_pith_number":"pith:T7PRDZJ6","canonical_record":{"source":{"id":"1707.05082","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-07-17T10:38:13Z","cross_cats_sorted":["cs.OS"],"title_canon_sha256":"10f61c2d4b12b5ee510fed6acbb4b6370932a1a0646728cb926635068484a5d5","abstract_canon_sha256":"35994ed735e9df531232dab45752e6ab4c760c07832099f1cde3276447d4aa21"},"schema_version":"1.0"},"canonical_sha256":"9fdf11e53e01b884b6be1d8b58f96e20a2918e2da3950b6d628d989f37179121","source":{"kind":"arxiv","id":"1707.05082","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1707.05082","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"arxiv_version","alias_value":"1707.05082v2","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1707.05082","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"pith_short_12","alias_value":"T7PRDZJ6AG4I","created_at":"2026-05-18T12:31:43Z"},{"alias_kind":"pith_short_16","alias_value":"T7PRDZJ6AG4IJNV6","created_at":"2026-05-18T12:31:43Z"},{"alias_kind":"pith_short_8","alias_value":"T7PRDZJ6","created_at":"2026-05-18T12:31:43Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:T7PRDZJ6AG4IJNV6DWFVR6LOEC","target":"record","payload":{"canonical_record":{"source":{"id":"1707.05082","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-07-17T10:38:13Z","cross_cats_sorted":["cs.OS"],"title_canon_sha256":"10f61c2d4b12b5ee510fed6acbb4b6370932a1a0646728cb926635068484a5d5","abstract_canon_sha256":"35994ed735e9df531232dab45752e6ab4c760c07832099f1cde3276447d4aa21"},"schema_version":"1.0"},"canonical_sha256":"9fdf11e53e01b884b6be1d8b58f96e20a2918e2da3950b6d628d989f37179121","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:40:02.694211Z","signature_b64":"qD6RbGW5CAS2xv3q/8DcXw2LIrUysB9PvXh++ZFJZAnv+mBGegvFwUEb1zPCwF8Rcpc0uV/GAB/mmuBjBnmTCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9fdf11e53e01b884b6be1d8b58f96e20a2918e2da3950b6d628d989f37179121","last_reissued_at":"2026-05-18T00:40:02.693781Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:40:02.693781Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1707.05082","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:40:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aux03GlPrT+AcDGS/uhDGkWhC/eg4V0H4+Vff4aufjdnAibvPtE+8qN69+puGluRFzDTrK4DUfjyEmWVBRwhCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T11:00:02.672492Z"},"content_sha256":"5b81cc57df2f98408570cff4aa83e44db889a0c21b5d511b671fc8f3c20da4be","schema_version":"1.0","event_id":"sha256:5b81cc57df2f98408570cff4aa83e44db889a0c21b5d511b671fc8f3c20da4be"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:T7PRDZJ6AG4IJNV6DWFVR6LOEC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Downgrade Attack on TrustZone","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Tao Wei, Yue Chen, Yulong Zhang, Zhi Wang","submitted_at":"2017-07-17T10:38:13Z","abstract_excerpt":"Security-critical tasks require proper isolation from untrusted software. Chip manufacturers design and include trusted execution environments (TEEs) in their processors to secure these tasks. The integrity and security of the software in the trusted environment depend on the verification process of the system.\n  We find a form of attack that can be performed on the current implementations of the widely deployed ARM TrustZone technology. The attack exploits the fact that the trustlet (TA) or TrustZone OS loading verification procedure may use the same verification key and may lack proper rollb"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1707.05082","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:40:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BOmwi0TFtrjdLIRBeF2t8546URayRCJZqYNkIxci6yUwQDddFXdylJPY3YL1p3+bcl0JfIgWhU1XbSm1cVDwCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T11:00:02.672843Z"},"content_sha256":"6e1b30e6745f02701b84212b1b76ec869f5bbf0cbd861776eb7b15406e5df197","schema_version":"1.0","event_id":"sha256:6e1b30e6745f02701b84212b1b76ec869f5bbf0cbd861776eb7b15406e5df197"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/bundle.json","state_url":"https://pith.science/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-04T11:00:02Z","links":{"resolver":"https://pith.science/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC","bundle":"https://pith.science/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/bundle.json","state":"https://pith.science/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/T7PRDZJ6AG4IJNV6DWFVR6LOEC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:T7PRDZJ6AG4IJNV6DWFVR6LOEC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"35994ed735e9df531232dab45752e6ab4c760c07832099f1cde3276447d4aa21","cross_cats_sorted":["cs.OS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-07-17T10:38:13Z","title_canon_sha256":"10f61c2d4b12b5ee510fed6acbb4b6370932a1a0646728cb926635068484a5d5"},"schema_version":"1.0","source":{"id":"1707.05082","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1707.05082","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"arxiv_version","alias_value":"1707.05082v2","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1707.05082","created_at":"2026-05-18T00:40:02Z"},{"alias_kind":"pith_short_12","alias_value":"T7PRDZJ6AG4I","created_at":"2026-05-18T12:31:43Z"},{"alias_kind":"pith_short_16","alias_value":"T7PRDZJ6AG4IJNV6","created_at":"2026-05-18T12:31:43Z"},{"alias_kind":"pith_short_8","alias_value":"T7PRDZJ6","created_at":"2026-05-18T12:31:43Z"}],"graph_snapshots":[{"event_id":"sha256:6e1b30e6745f02701b84212b1b76ec869f5bbf0cbd861776eb7b15406e5df197","target":"graph","created_at":"2026-05-18T00:40:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Security-critical tasks require proper isolation from untrusted software. Chip manufacturers design and include trusted execution environments (TEEs) in their processors to secure these tasks. The integrity and security of the software in the trusted environment depend on the verification process of the system.\n  We find a form of attack that can be performed on the current implementations of the widely deployed ARM TrustZone technology. The attack exploits the fact that the trustlet (TA) or TrustZone OS loading verification procedure may use the same verification key and may lack proper rollb","authors_text":"Tao Wei, Yue Chen, Yulong Zhang, Zhi Wang","cross_cats":["cs.OS"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-07-17T10:38:13Z","title":"Downgrade Attack on TrustZone"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1707.05082","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5b81cc57df2f98408570cff4aa83e44db889a0c21b5d511b671fc8f3c20da4be","target":"record","created_at":"2026-05-18T00:40:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"35994ed735e9df531232dab45752e6ab4c760c07832099f1cde3276447d4aa21","cross_cats_sorted":["cs.OS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-07-17T10:38:13Z","title_canon_sha256":"10f61c2d4b12b5ee510fed6acbb4b6370932a1a0646728cb926635068484a5d5"},"schema_version":"1.0","source":{"id":"1707.05082","kind":"arxiv","version":2}},"canonical_sha256":"9fdf11e53e01b884b6be1d8b58f96e20a2918e2da3950b6d628d989f37179121","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9fdf11e53e01b884b6be1d8b58f96e20a2918e2da3950b6d628d989f37179121","first_computed_at":"2026-05-18T00:40:02.693781Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:40:02.693781Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qD6RbGW5CAS2xv3q/8DcXw2LIrUysB9PvXh++ZFJZAnv+mBGegvFwUEb1zPCwF8Rcpc0uV/GAB/mmuBjBnmTCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:40:02.694211Z","signed_message":"canonical_sha256_bytes"},"source_id":"1707.05082","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5b81cc57df2f98408570cff4aa83e44db889a0c21b5d511b671fc8f3c20da4be","sha256:6e1b30e6745f02701b84212b1b76ec869f5bbf0cbd861776eb7b15406e5df197"],"state_sha256":"f389aca0386ada3bdf805440a78ecfe39528e7dc209efd95da3eeb6f72136cce"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tQw6HK1kuLkcyBDTttCXs5M/vm47uxR2JOGqLsWMqSa5svM2FgNC4OeMkTOh5iXfwbPJBvxIgCxgAQWJ8+XODQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-04T11:00:02.674805Z","bundle_sha256":"0fe97024e45fe8cec360857808ac410fba745ab9b9923fc0be405befaee50e3c"}}