TriHaRd: Higher Resilience for TEE Trusted Time

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bettinger, Matthieu, Mokhtar, Sonia Ben, Felber, Pascal, Rivière, Etienne, Schiavoni, Valerio, Simonet-Boulogne, Anthony
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866908705633599488
author Bettinger, Matthieu
Mokhtar, Sonia Ben
Felber, Pascal
Rivière, Etienne
Schiavoni, Valerio
Simonet-Boulogne, Anthony
author_facet Bettinger, Matthieu
Mokhtar, Sonia Ben
Felber, Pascal
Rivière, Etienne
Schiavoni, Valerio
Simonet-Boulogne, Anthony
contents Accurately measuring time passing is critical for many applications. However, in Trusted Execution Environments (TEEs) such as Intel SGX, the time source is outside the Trusted Computing Base: a malicious host can manipulate the TEE's notion of time, jumping in time or affecting perceived time speed. Previous work (Triad) proposes protocols for TEEs to maintain a trustworthy time source by building a cluster of TEEs that collaborate with each other and with a remote Time Authority to maintain a continuous notion of passing time. However, such approaches still allow an attacker to control the operating system and arbitrarily manipulate their own TEE's perceived clock speed. An attacker can even propagate faster passage of time to honest machines participating in Triad's trusted time protocol, causing them to skip to timestamps arbitrarily far in the future. We propose TriHaRd, a TEE trusted time protocol achieving high resilience against clock speed and offset manipulations, notably through Byzantine-resilient clock updates and consistency checks. We empirically show that TriHaRd mitigates known attacks against Triad.
format Preprint
id arxiv_https___arxiv_org_abs_2512_10732
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle TriHaRd: Higher Resilience for TEE Trusted Time
Bettinger, Matthieu
Mokhtar, Sonia Ben
Felber, Pascal
Rivière, Etienne
Schiavoni, Valerio
Simonet-Boulogne, Anthony
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Accurately measuring time passing is critical for many applications. However, in Trusted Execution Environments (TEEs) such as Intel SGX, the time source is outside the Trusted Computing Base: a malicious host can manipulate the TEE's notion of time, jumping in time or affecting perceived time speed. Previous work (Triad) proposes protocols for TEEs to maintain a trustworthy time source by building a cluster of TEEs that collaborate with each other and with a remote Time Authority to maintain a continuous notion of passing time. However, such approaches still allow an attacker to control the operating system and arbitrarily manipulate their own TEE's perceived clock speed. An attacker can even propagate faster passage of time to honest machines participating in Triad's trusted time protocol, causing them to skip to timestamps arbitrarily far in the future. We propose TriHaRd, a TEE trusted time protocol achieving high resilience against clock speed and offset manipulations, notably through Byzantine-resilient clock updates and consistency checks. We empirically show that TriHaRd mitigates known attacks against Triad.
title TriHaRd: Higher Resilience for TEE Trusted Time
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2512.10732