{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:X72PPSAA3OKHES5VLXZFOTL3QE","short_pith_number":"pith:X72PPSAA","canonical_record":{"source":{"id":"1902.03256","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-02-08T19:05:00Z","cross_cats_sorted":[],"title_canon_sha256":"1fe4dbab57409b0bb319916a1063306064b2733a7d35eaaa7283436745aefec6","abstract_canon_sha256":"a15b3ba503c7eb7a3193f89bb4929f56a10a02fcd47ee0ab9853c3fc808fc2c4"},"schema_version":"1.0"},"canonical_sha256":"bff4f7c800db94724bb55df2574d7b8106825d544ff594ed60efde8c1c4a9d6f","source":{"kind":"arxiv","id":"1902.03256","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.03256","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"arxiv_version","alias_value":"1902.03256v1","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.03256","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"pith_short_12","alias_value":"X72PPSAA3OKH","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"X72PPSAA3OKHES5V","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"X72PPSAA","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:X72PPSAA3OKHES5VLXZFOTL3QE","target":"record","payload":{"canonical_record":{"source":{"id":"1902.03256","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-02-08T19:05:00Z","cross_cats_sorted":[],"title_canon_sha256":"1fe4dbab57409b0bb319916a1063306064b2733a7d35eaaa7283436745aefec6","abstract_canon_sha256":"a15b3ba503c7eb7a3193f89bb4929f56a10a02fcd47ee0ab9853c3fc808fc2c4"},"schema_version":"1.0"},"canonical_sha256":"bff4f7c800db94724bb55df2574d7b8106825d544ff594ed60efde8c1c4a9d6f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:54:21.453091Z","signature_b64":"tICAgFHYkzTsW0Ld8n37lZeG+XPafSVRTSekPc+JoHn/JGkC1ENlyXJNOZmQCEVjzzo9db7sTKG2qcLwsGJSAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bff4f7c800db94724bb55df2574d7b8106825d544ff594ed60efde8c1c4a9d6f","last_reissued_at":"2026-05-17T23:54:21.452496Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:54:21.452496Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1902.03256","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YrF6PE5OwhVsXpXW+pif1XfyPAQcBG4N0Td2kV2d+7cROvGGHoo13PLoLIeZZ3ReiBZ6V3gG6UyKyNo7WuGNCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T22:17:55.774750Z"},"content_sha256":"3b1ffb0f0eb32d4ff6bbb27d75c3c02b30a8d33181dd1c0f775fb322296edde8","schema_version":"1.0","event_id":"sha256:3b1ffb0f0eb32d4ff6bbb27d75c3c02b30a8d33181dd1c0f775fb322296edde8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:X72PPSAA3OKHES5VLXZFOTL3QE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Practical Enclave Malware with Intel SGX","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Daniel Gruss, Michael Schwarz, Samuel Weiser","submitted_at":"2019-02-08T19:05:00Z","abstract_excerpt":"Modern CPU architectures offer strong isolation guarantees towards user applications in the form of enclaves. For instance, Intel's threat model for SGX assumes fully trusted enclaves, yet there is an ongoing debate on whether this threat model is realistic. In particular, it is unclear to what extent enclave malware could harm a system. In this work, we practically demonstrate the first enclave malware which fully and stealthily impersonates its host application. Together with poorly-deployed application isolation on personal computers, such malware can not only steal or encrypt documents for"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.03256","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MqF3naxcvBpmK5TmLjPnoJp33pziDfnb293Nme14fqy2rhtmQmD41FmkEkurCAUI7ka9YM749/lH3VJ1b8bYCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T22:17:55.775091Z"},"content_sha256":"f8b1d5140e31911cd2048cff708d935edac14d2163175d275f23bda7157ec14d","schema_version":"1.0","event_id":"sha256:f8b1d5140e31911cd2048cff708d935edac14d2163175d275f23bda7157ec14d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/X72PPSAA3OKHES5VLXZFOTL3QE/bundle.json","state_url":"https://pith.science/pith/X72PPSAA3OKHES5VLXZFOTL3QE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/X72PPSAA3OKHES5VLXZFOTL3QE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T22:17:55Z","links":{"resolver":"https://pith.science/pith/X72PPSAA3OKHES5VLXZFOTL3QE","bundle":"https://pith.science/pith/X72PPSAA3OKHES5VLXZFOTL3QE/bundle.json","state":"https://pith.science/pith/X72PPSAA3OKHES5VLXZFOTL3QE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/X72PPSAA3OKHES5VLXZFOTL3QE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:X72PPSAA3OKHES5VLXZFOTL3QE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a15b3ba503c7eb7a3193f89bb4929f56a10a02fcd47ee0ab9853c3fc808fc2c4","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-02-08T19:05:00Z","title_canon_sha256":"1fe4dbab57409b0bb319916a1063306064b2733a7d35eaaa7283436745aefec6"},"schema_version":"1.0","source":{"id":"1902.03256","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.03256","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"arxiv_version","alias_value":"1902.03256v1","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.03256","created_at":"2026-05-17T23:54:21Z"},{"alias_kind":"pith_short_12","alias_value":"X72PPSAA3OKH","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"X72PPSAA3OKHES5V","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"X72PPSAA","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:f8b1d5140e31911cd2048cff708d935edac14d2163175d275f23bda7157ec14d","target":"graph","created_at":"2026-05-17T23:54:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Modern CPU architectures offer strong isolation guarantees towards user applications in the form of enclaves. For instance, Intel's threat model for SGX assumes fully trusted enclaves, yet there is an ongoing debate on whether this threat model is realistic. In particular, it is unclear to what extent enclave malware could harm a system. In this work, we practically demonstrate the first enclave malware which fully and stealthily impersonates its host application. Together with poorly-deployed application isolation on personal computers, such malware can not only steal or encrypt documents for","authors_text":"Daniel Gruss, Michael Schwarz, Samuel Weiser","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-02-08T19:05:00Z","title":"Practical Enclave Malware with Intel SGX"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.03256","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3b1ffb0f0eb32d4ff6bbb27d75c3c02b30a8d33181dd1c0f775fb322296edde8","target":"record","created_at":"2026-05-17T23:54:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a15b3ba503c7eb7a3193f89bb4929f56a10a02fcd47ee0ab9853c3fc808fc2c4","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-02-08T19:05:00Z","title_canon_sha256":"1fe4dbab57409b0bb319916a1063306064b2733a7d35eaaa7283436745aefec6"},"schema_version":"1.0","source":{"id":"1902.03256","kind":"arxiv","version":1}},"canonical_sha256":"bff4f7c800db94724bb55df2574d7b8106825d544ff594ed60efde8c1c4a9d6f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bff4f7c800db94724bb55df2574d7b8106825d544ff594ed60efde8c1c4a9d6f","first_computed_at":"2026-05-17T23:54:21.452496Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:54:21.452496Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"tICAgFHYkzTsW0Ld8n37lZeG+XPafSVRTSekPc+JoHn/JGkC1ENlyXJNOZmQCEVjzzo9db7sTKG2qcLwsGJSAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:54:21.453091Z","signed_message":"canonical_sha256_bytes"},"source_id":"1902.03256","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3b1ffb0f0eb32d4ff6bbb27d75c3c02b30a8d33181dd1c0f775fb322296edde8","sha256:f8b1d5140e31911cd2048cff708d935edac14d2163175d275f23bda7157ec14d"],"state_sha256":"fc669f71afc9b028e16361d702a0804faada31dcff3f078a252b33c4f8ed1954"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yR+RfUzyEQN8dSNl/ufnfPDaNARDY6WoB5zg2AmobnXH/lOvtX8U7uSm31OtBoPEF1jBrQYSYJsRTvcWG3mkCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T22:17:55.777116Z","bundle_sha256":"3dc51e7f5f38ac41a23915382d07ea1ee139fd2b23168bdd0672227d3f88d866"}}