TEE is not a Healer: Rollback-Resistant Reliable Storage (Extended Version)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Keshavarzi, Sadegh, Chockler, Gregory, Gotsman, Alexey
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914501188648960
author Keshavarzi, Sadegh
Chockler, Gregory
Gotsman, Alexey
author_facet Keshavarzi, Sadegh
Chockler, Gregory
Gotsman, Alexey
contents Recent advances in secure hardware technologies, such as Intel SGX or ARM TrustZone, offer an opportunity to substantially reduce the costs of Byzantine fault-tolerance by placing the program code and state within a secure enclave known as a Trusted Execution Environment (TEE). However, the protection offered by a TEE only applies during program execution. Once power is switched off, the non-volatile portion of the program state becomes vulnerable to rollback attacks wherein it is undetectably reverted to an older version. In this paper we consider the problem of implementing reliable read/write registers out of failure-prone replicas subject to state rollbacks. To this end, we introduce a new unified model that captures multiple failure types that can affect a TEE-based system and establish tight bounds on the fault-tolerance of register constructions in this model. We consider both the static case, where failure thresholds hold throughout the entire execution, and the dynamic case, where any number of replicas can roll back, provided these failures do not occur too often. Our dynamic register emulation algorithm, TEE-Rex, provides the first correct implementation of a distributed state recovery procedure that requires neither durable storage nor specialized hardware, such as trusted monotonic counters.
format Preprint
id arxiv_https___arxiv_org_abs_2505_18648
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle TEE is not a Healer: Rollback-Resistant Reliable Storage (Extended Version)
Keshavarzi, Sadegh
Chockler, Gregory
Gotsman, Alexey
Distributed, Parallel, and Cluster Computing
Recent advances in secure hardware technologies, such as Intel SGX or ARM TrustZone, offer an opportunity to substantially reduce the costs of Byzantine fault-tolerance by placing the program code and state within a secure enclave known as a Trusted Execution Environment (TEE). However, the protection offered by a TEE only applies during program execution. Once power is switched off, the non-volatile portion of the program state becomes vulnerable to rollback attacks wherein it is undetectably reverted to an older version. In this paper we consider the problem of implementing reliable read/write registers out of failure-prone replicas subject to state rollbacks. To this end, we introduce a new unified model that captures multiple failure types that can affect a TEE-based system and establish tight bounds on the fault-tolerance of register constructions in this model. We consider both the static case, where failure thresholds hold throughout the entire execution, and the dynamic case, where any number of replicas can roll back, provided these failures do not occur too often. Our dynamic register emulation algorithm, TEE-Rex, provides the first correct implementation of a distributed state recovery procedure that requires neither durable storage nor specialized hardware, such as trusted monotonic counters.
title TEE is not a Healer: Rollback-Resistant Reliable Storage (Extended Version)
topic Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2505.18648