KingsGuard: Enclave Data Protection Under Real-World TEE Vulnerabilities

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Allaqband, Saltanat Firdous, S, Deepanjali, G, Rohit Srinivas R, Gosain, Devashish, Rebeiro, Chester
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913093119901696
author Allaqband, Saltanat Firdous
S, Deepanjali
G, Rohit Srinivas R
Gosain, Devashish
Rebeiro, Chester
author_facet Allaqband, Saltanat Firdous
S, Deepanjali
G, Rohit Srinivas R
Gosain, Devashish
Rebeiro, Chester
contents Trusted Execution Environments (TEEs) have emerged as a cornerstone for securing sensitive computations by providing isolated enclaves protected from untrusted software. However, their security guarantees are undermined by vulnerabilities in both the enclave code and the underlying hardware design, which can allow sensitive data to leak despite strong isolation guarantees. This paper presents KINGSGUARD, a novel TEE design that systematically monitors and controls the propagation of sensitive data within an enclave. By enforcing fine-grained data flow tracking and checks in hardware, our approach ensures that sensitive data does not leave the enclave boundary, thus bridging the gap between the idealized threat models of TEEs and their practical realizations. Additionally, to balance security with practical functionality, we introduce controlled declassification at enclave boundaries, allowing intentional release of data to the outside world. Our implementation of KINGSGUARD on a RISC-V processor has a 10.8% hardware area overhead when synthesized on FPGA and a 5.69% performance overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2605_00613
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle KingsGuard: Enclave Data Protection Under Real-World TEE Vulnerabilities
Allaqband, Saltanat Firdous
S, Deepanjali
G, Rohit Srinivas R
Gosain, Devashish
Rebeiro, Chester
Cryptography and Security
Trusted Execution Environments (TEEs) have emerged as a cornerstone for securing sensitive computations by providing isolated enclaves protected from untrusted software. However, their security guarantees are undermined by vulnerabilities in both the enclave code and the underlying hardware design, which can allow sensitive data to leak despite strong isolation guarantees. This paper presents KINGSGUARD, a novel TEE design that systematically monitors and controls the propagation of sensitive data within an enclave. By enforcing fine-grained data flow tracking and checks in hardware, our approach ensures that sensitive data does not leave the enclave boundary, thus bridging the gap between the idealized threat models of TEEs and their practical realizations. Additionally, to balance security with practical functionality, we introduce controlled declassification at enclave boundaries, allowing intentional release of data to the outside world. Our implementation of KINGSGUARD on a RISC-V processor has a 10.8% hardware area overhead when synthesized on FPGA and a 5.69% performance overhead.
title KingsGuard: Enclave Data Protection Under Real-World TEE Vulnerabilities
topic Cryptography and Security
url https://arxiv.org/abs/2605.00613