Rollbaccine : Herd Immunity against Storage Rollback Attacks in TEEs [Technical Report]

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Chu, David, Balasubramanian, Aditya, Bao, Dee, Crooks, Natacha, Howard, Heidi, Katahanas, Lucky E., Ponnapalli, Soujanya
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912802306785280
author Chu, David
Balasubramanian, Aditya
Bao, Dee
Crooks, Natacha
Howard, Heidi
Katahanas, Lucky E.
Ponnapalli, Soujanya
author_facet Chu, David
Balasubramanian, Aditya
Bao, Dee
Crooks, Natacha
Howard, Heidi
Katahanas, Lucky E.
Ponnapalli, Soujanya
contents Today, users can "lift-and-shift" unmodified applications into modern, VM-based Trusted Execution Environments (TEEs) in order to gain hardware-based security guarantees. However, TEEs do not protect applications against disk rollback attacks, where persistent storage can be reverted to an earlier state after a crash; existing rollback resistance solutions either only support a subset of applications or require code modification. Our key insight is that restoring disk consistency after a rollback attack guarantees rollback resistance for any application. We present Rollbaccine, a device mapper that provides automatic rollback resistance for all applications by provably preserving disk consistency. Rollbaccine intercepts and replicates writes to disk, restores lost state from backups during recovery, and minimizes overheads by taking advantage of the weak, multi-threaded semantics of disk operations. Rollbaccine performs on-par with state-of-the-art, non-automatic rollback resistant solutions; in fact, across benchmarks over PostgreSQL, HDFS, and two file systems (ext4 and xfs), Rollbaccine adds only 19% overhead, except for the fsync-heavy Filebench Varmail.
format Preprint
id arxiv_https___arxiv_org_abs_2505_04014
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Rollbaccine : Herd Immunity against Storage Rollback Attacks in TEEs [Technical Report]
Chu, David
Balasubramanian, Aditya
Bao, Dee
Crooks, Natacha
Howard, Heidi
Katahanas, Lucky E.
Ponnapalli, Soujanya
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Today, users can "lift-and-shift" unmodified applications into modern, VM-based Trusted Execution Environments (TEEs) in order to gain hardware-based security guarantees. However, TEEs do not protect applications against disk rollback attacks, where persistent storage can be reverted to an earlier state after a crash; existing rollback resistance solutions either only support a subset of applications or require code modification. Our key insight is that restoring disk consistency after a rollback attack guarantees rollback resistance for any application. We present Rollbaccine, a device mapper that provides automatic rollback resistance for all applications by provably preserving disk consistency. Rollbaccine intercepts and replicates writes to disk, restores lost state from backups during recovery, and minimizes overheads by taking advantage of the weak, multi-threaded semantics of disk operations. Rollbaccine performs on-par with state-of-the-art, non-automatic rollback resistant solutions; in fact, across benchmarks over PostgreSQL, HDFS, and two file systems (ext4 and xfs), Rollbaccine adds only 19% overhead, except for the fsync-heavy Filebench Varmail.
title Rollbaccine : Herd Immunity against Storage Rollback Attacks in TEEs [Technical Report]
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2505.04014