REVIEW 2 major objections 1 minor 98 references
CCX: Enabling Unmodified Intel SGX Applications on Arm CCA
T0 review · 2 major / 1 minor · reviewed 2026-05-11 · grok-4.3
Pith's one-line read CCX enables existing Intel SGX applications to run unmodified on Arm CCA with comparable security guarantees.
desk verdict CCX emulates SGX inside Arm CCA firmware to run unmodified binaries, but the security equivalence claim rests on thin evidence. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The CCX framework that recreates SGX execution semantics and APIs inside Arm CCA firmware.
What would settle it
An existing SGX application that either fails to execute on the CCX prototype, requires source code changes, or shows a security issue not present under native Intel SGX.
Extended reading notes
Core claim
CCX redesigns SGX functionality within Arm CCA firmware, adapting SGX abstractions to CCA's architecture design while preserving full compatibility with existing applications originally developed for SGX. The prototype, implemented on QEMU and a Nitrogen8M development board, executes existing SGX applications without source code changes, provides security guarantees comparable to Intel SGX, and achieves performance improvements in the evaluated settings.
Load-bearing premise
SGX functionality and execution semantics can be faithfully recreated inside Arm CCA firmware without introducing new attack surfaces or breaking compatibility for real-world applications.
Editorial extensions
If this is right
- Existing SGX applications can be deployed on Arm-based confidential computing systems without developer changes.
- Security properties remain comparable to those of Intel SGX for cloud services.
- Performance gains appear in the tested settings due to the firmware redesign.
- Applications such as secure payments and privacy-preserving communication become portable across the two platforms.
Reading between the lines
- This approach could make Arm CCA more immediately usable for teams already invested in SGX codebases.
- Similar firmware bridges might later connect SGX applications to other emerging confidential computing technologies.
- Developers could maintain a single SGX codebase while targeting both Intel and Arm deployments.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents CCX, a framework that redesigns SGX functionality inside Arm CCA firmware to enable existing SGX applications to execute unmodified on Arm CCA platforms. It reports a prototype implementation running on both QEMU and a real Nitrogen8M development board, claiming full application compatibility, security guarantees comparable to native Intel SGX, and performance improvements over the evaluated settings.
Significance. If the security equivalence and compatibility claims are substantiated, the work would have clear practical significance for migrating SGX-based confidential-computing workloads to Arm-based cloud systems, addressing a real portability barrier as Arm adoption grows.
major comments (2)
- [Abstract] Abstract: the central claim of 'security guarantees comparable to Intel SGX' is load-bearing yet unsupported by any TCB comparison, threat-model mapping, or analysis of how SGX primitives (e.g., EREPORT, EGETKEY, attestation) are realized inside CCA firmware without enlarging the attack surface or altering the trust model.
- [Abstract] Abstract / Evaluation: the statement that CCX achieves 'performance improvements in our evaluated settings' is not accompanied by any quantitative metrics, baselines, or workload descriptions, rendering the performance claim impossible to assess.
minor comments (1)
- The manuscript would benefit from an explicit section detailing the CCA firmware interfaces and trapping mechanisms used to emulate SGX instruction semantics.
Simulated Author's Rebuttal
We thank the referee for the constructive feedback on the abstract claims. We address each major comment below and will revise the manuscript to strengthen the presentation of our security and performance arguments.
read point-by-point responses
-
Referee: [Abstract] Abstract: the central claim of 'security guarantees comparable to Intel SGX' is load-bearing yet unsupported by any TCB comparison, threat-model mapping, or analysis of how SGX primitives (e.g., EREPORT, EGETKEY, attestation) are realized inside CCA firmware without enlarging the attack surface or altering the trust model.
Authors: We acknowledge that the abstract states the comparability claim without inline details. The full manuscript describes the redesign of SGX abstractions (including EREPORT, EGETKEY, and attestation) inside CCA firmware and argues that the trust model is preserved because CCX runs within the CCA realm without adding new privileged code. However, we agree an explicit TCB size comparison and threat-model mapping would make the claim more robust. In the revision we will add a concise TCB comparison table and a short threat-model subsection that maps each SGX primitive to its CCA realization, showing no enlargement of the attack surface. revision: yes
-
Referee: [Abstract] Abstract / Evaluation: the statement that CCX achieves 'performance improvements in our evaluated settings' is not accompanied by any quantitative metrics, baselines, or workload descriptions, rendering the performance claim impossible to assess.
Authors: The abstract is intentionally brief and therefore omits the concrete numbers. The evaluation section reports results on both QEMU and the Nitrogen8M board for unmodified SGX applications (cryptographic workloads, secure database queries, and privacy-preserving analytics), using native Arm execution and a prior SGX-on-CCA baseline. We will revise the abstract to include representative quantitative figures (e.g., percentage overhead reductions) and name the workloads and baselines so the claim can be assessed directly from the abstract. revision: yes
Circularity Check
No circularity: engineering implementation with no derivations or self-referential claims
full rationale
The paper describes the design and implementation of the CCX framework for porting SGX applications to Arm CCA. It contains no equations, fitted parameters, predictions, or mathematical derivations that could reduce to their inputs by construction. No self-citations are invoked to justify uniqueness theorems, ansatzes, or load-bearing premises. The central claims rest on the existence of a working prototype (QEMU and hardware) and compatibility evaluation, which are independent engineering artifacts rather than tautological restatements of inputs. This is a standard non-circular engineering paper.
Assumptions & free parameters
assumptions (1)
- domain assumption Arm CCA isolation primitives are sufficient to host an SGX-compatible execution environment without loss of security properties.
invented entities (1)
-
CCX firmware layer
Cite this review
Pith. "Pith review of CCX: Enabling Unmodified Intel SGX Applications on Arm CCA." pith.science (2026). https://pith.science/paper/2605.07548
@misc{pith2026260507548,
author = {Pith},
title = {Pith review of: CCX: Enabling Unmodified Intel SGX Applications on Arm CCA},
year = {2026},
howpublished = {\url{https://pith.science/paper/2605.07548}},
note = {Machine review of arXiv:2605.07548}
}
read the original abstract
Novel confidential computing technologies such as Intel TDX, AMD SEV, and Arm CCA have recently emerged. In practice, due to its minimal trust boundaries, Intel SGX still remains widely used for enclave-based applications in cloud environments, including confidential cloud services, privacy-preserving communication, secure payment processing, and privacy-focused advertising. With the growing adoption of Arm CPUs in cloud systems, however, existing SGX applications face a significant portability challenge: they are tightly coupled to SGX-specific APIs and execution semantics. In this paper, we present the design and implementation of CCX, a framework that enables existing SGX applications to run on Arm CCA without source code modification. To this end, CCX redesigns SGX functionality within Arm CCA firmware, adapting SGX abstractions to CCA's architecture design while preserving full compatibility with existing applications originally developed for SGX. We implemented a prototype of CCX on both the QEMU emulator and a Nitrogen8M development board. Our evaluation shows that CCX is capable of executing existing SGX applications without requiring source code changes, while providing security guarantees comparable to Intel SGX and achieving performance improvements in our evaluated settings.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[1]
https://github.com/Mbed-TLS/mbedtls
Mbed TLS . https://github.com/Mbed-TLS/mbedtls. Accessed: 2025- 08-25
work page 2025
-
[2]
https://documentation- service.arm.com/static/69cb945ac1586b7c59b1c00c?token=
Realm Management Monitor specification . https://documentation- service.arm.com/static/69cb945ac1586b7c59b1c00c?token=. Accessed: 2026-05-06
work page 2026
-
[3]
https://github.com/utds3lab/ sgx-nbench
The nbench benchmark ported to SGX. . https://github.com/utds3lab/ sgx-nbench. Accessed: 2025-08-25
work page 2025
-
[4]
https://github.com/ARM-software/arm-trusted- firmware
Trusted Firmware-A . https://github.com/ARM-software/arm-trusted- firmware. Accessed: 2025-08-25
work page 2025
-
[5]
https://github.com/asterinas/hyperenclave
HyperEnclave. https://github.com/asterinas/hyperenclave. Accessed: 2025-08-25
work page 2025
-
[6]
https://github.com/intel/linux-sgx
Linux-SGX. https://github.com/intel/linux-sgx. Accessed: 2025-08-25
work page 2025
-
[7]
https://github.com/ AMDESE/linux-svsm
Linux SVSM (Secure VM Service Module). https://github.com/ AMDESE/linux-svsm. Accessed: 2025-08-25
work page 2025
-
[8]
https://github.com/openenclave/openenclave
Open Enclave SDK. https://github.com/openenclave/openenclave. Ac- cessed: 2025-08-25
work page 2025
Show all 98 references
-
[9]
https://github.com/dsc-sgx/sgx-kmeans
sgx-kmeans. https://github.com/dsc-sgx/sgx-kmeans. Accessed: 2025- 08-25
2025
-
[10]
https://github.com/yerzhan7/SGX SQLite
SGX SQLite. https://github.com/yerzhan7/SGX SQLite. Accessed: 2025-08-25
2025
-
[11]
https://www.math.utah.edu/ ∼mayer/linux/bmark.html, 2017
NBench. https://www.math.utah.edu/ ∼mayer/linux/bmark.html, 2017. Accessed: 2025-08-25
2017
-
[12]
https://documentation-service.arm.com/ static/610aaec33d73a34b640e333b?token=, 2021
Arm CCA Security Model 1.0. https://documentation-service.arm.com/ static/610aaec33d73a34b640e333b?token=, 2021. Accessed: 2025-08- 25
2021
-
[13]
https: //developer.arm.com/documentation/den0129/latest/, 2023
Arm Realm Management Extension (RME) System Architecture. https: //developer.arm.com/documentation/den0129/latest/, 2023. Accessed: 2025-08-25
2023
-
[14]
AWS & ARM Partnership
Amazon Web Services. AWS & ARM Partnership. https:// www.arm.com/partners/aws, 2022. Accessed: 2025-08-25
2022
-
[15]
The Security Design of the AWS Nitro System: AWS Whitepaper
Amazon Web Services. The Security Design of the AWS Nitro System: AWS Whitepaper. https://docs.aws.amazon.com/pdfs/whitepapers/ latest/security-design-of-aws-nitro-system/security-design-of-aws- nitro-system.pdf, 2024. Accessed: 2025-08-25
2024
-
[16]
Strengthening VM isolation with integrity protection and more
AMD. Strengthening VM isolation with integrity protection and more. White Paper, 2020
2020
-
[17]
Inno- vative technology for cpu based attestation and sealing
Ittai Anati, Shay Gueron, Simon Johnson, and Vincent Scarlata. Inno- vative technology for cpu based attestation and sealing. InInternational Workshop on Hardware and Architectural Support for Security and Privacy (HASP), 2013
2013
-
[18]
TaLoS: Efficient TLS Termination Inside SGX Enclaves for Existing Applications
Aublin, Pierre-Louis and Kelbert, Florian and O’keeffe, Dan and Muthukumaran, Divya and Priebe, Christian and Lind, Joshua and Krahn, Robert and Fetzer, Christof and Eyers, David and Pietzuch, Peter. TaLoS: Efficient TLS Termination Inside SGX Enclaves for Existing Application...
2017
-
[19]
CURE: A Security Architecture with CUstomizable and Resilient Enclaves
Raad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig, Matthias Klimmek, Ahmad-Reza Sadeghi, and Emmanuel Stapf. CURE: A Security Architecture with CUstomizable and Resilient Enclaves. In USENIX Security Symposium, 2021
2021
-
[20]
OPENCCA: An Open Framework to Enable Arm CCA Research
Andrin Bertschi and Shweta Shinde. OPENCCA: An Open Framework to Enable Arm CCA Research. Inieee-eurospw, 2025
2025
-
[21]
CustomProcessingUnit: Reverse Engineering and Customization of Intel Microcode
Pietro Borrello, Catherine Easdon, Martin Schwarzl, Roland Czerny, and Michael Schwarz. CustomProcessingUnit: Reverse Engineering and Customization of Intel Microcode. InIEEE Security and Privacy Workshops (SPW), 2023
2023
-
[22]
SANCTUARY: ARMing TrustZone with User- space Enclaves
Ferdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi, and Emmanuel Stapf. SANCTUARY: ARMing TrustZone with User- space Enclaves. InSymposium on Network and Distributed System Security (NDSS), 2019
2019
-
[23]
Software Grand Exposure: SGX Cache Attacks Are Practical
Ferdinand Brasser, Urs M ¨uller, Alexandra Dmitrienko, Kari Kostiainen, Srdjan Capkun, and Ahmad-Reza Sadeghi. Software Grand Exposure: SGX Cache Attacks Are Practical. InUSENIX Workshop on Offensive Technologies (WOOT), 2017
2017
-
[24]
Insecure until proven updated: Analyzing AMD sev’s remote attestation
Robert Buhren, Christian Werling, and Jean-Pierre Seifert. Insecure until proven updated: Analyzing AMD sev’s remote attestation. InACM Conference on Computer and Communications Security (CCS), 2019
2019
-
[25]
SGX-Step: A Practical Attack Framework for Precise Enclave Execution Control
Jo Van Bulck, Frank Piessens, and Raoul Strackx. SGX-Step: A Practical Attack Framework for Precise Enclave Execution Control. InWorkshop on System Software for Trusted Execution (SysTEX), 2017
2017
-
[26]
A Systematic Evaluation of Transient Execution Attacks and Defenses
Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Ben- jamin von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. A Systematic Evaluation of Transient Execution Attacks and Defenses. InUSENIX Security Symposium, 2019
2019
-
[27]
AnyTEE: An Open and Interoperable Software Defined TEE Framework.IEEE Access, 2025
David Cerdeira, Jos ´e Martins, Nuno Santos, and Sandro Pinto. AnyTEE: An Open and Interoperable Software Defined TEE Framework.IEEE Access, 2025
2025
-
[28]
Securing Data Analytics on SGX with Randomization
Swarup Chandra, Vishal Karande, Zhiqiang Lin, Latifur Khan, Murat Kantarcioglu, and Bhavani Thuraisingham. Securing Data Analytics on SGX with Randomization. InEuropean Symposium on Research in Computer Security (ESORICS), 2017
2017
-
[29]
SgxPectre: Stealing Intel Secrets From SGX Enclaves via Speculative Execution.IEEE Symposium on Security and Privacy (S&P), 2020
Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten-Hwang Lai. SgxPectre: Stealing Intel Secrets From SGX Enclaves via Speculative Execution.IEEE Symposium on Security and Privacy (S&P), 2020
2020
-
[30]
Intel TDX Demystified: A Top-Down Approach.ACM Computing Surveys (CSUR), 56(9), 2024
Pau-Chen Cheng, Wojciech Ozga, Enriquillo Valdez, Salman Ahmed, Zhongshu Gu, Hani Jamjoom, Hubertus Franke, and James Bottomley. Intel TDX Demystified: A Top-Down Approach.ACM Computing Surveys (CSUR), 56(9), 2024
2024
-
[31]
Secret Key Recovery in a Global-Scale End-to-End Encryption System
Graeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman, and Raluca Ada Popa. Secret Key Recovery in a Global-Scale End-to-End Encryption System. InSymposium on Operating Systems Design and Implementation (OSDI), 2024
2024
-
[32]
AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX Enclaves
Scott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao, Cedric Xing, Ilya Alexandrovich, Taesoo Kim, Frank Piessens, Mona Vij, and Mark Silberstein. AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX Enclaves. InUSENIX Security Sympo...
2023
-
[33]
Technology
Cosmian. Technology. https://cosmian.com/technology/, 2024. Ac- cessed: 2025-08-25
2024
-
[34]
Intel SGX Explained
Victor Costan and Srinivas Devadas. Intel SGX Explained. Technical report, IACR Cryptology ePrint Archive, 2016. https://eprint.iacr.org/ 2016/086
2016
-
[35]
Lebedev, and Srinivas Devadas
Victor Costan, Ilia A. Lebedev, and Srinivas Devadas. Sanctum: Minimal Hardware Extensions for Strong Software Isolation. InUSENIX Security Symposium, 2016
2016
-
[36]
Abu-Ghazaleh, and Dmitry Ponomarev
Dmitry Evtyushkin, Ryan Riley, Nael B. Abu-Ghazaleh, and Dmitry Ponomarev. BranchScope: A New Side-Channel Attack on Directional Branch Predictor. InConference on Architectural Support for Program- ming Languages and Operating Systems (ASPLOS), 2018
2018
-
[37]
Komodo: Using verification to disentangle secure-enclave hard- ware from software
Andrew Ferraiuolo, Andrew Baumann, Chris Hawblitzel, and Bryan Parno. Komodo: Using verification to disentangle secure-enclave hard- ware from software. InSymposium on Operating Systems Principles (SOSP), 2017
2017
-
[38]
Block Building inside SGX
Flashbots. Block Building inside SGX. https://writings.flashbots.net/ block-building-inside-sgx#our-sepolia-sgx-builder, 2023. Accessed: 2025-08-25
2023
-
[39]
Anthony C. J. Fox, Gareth Stockwell, Shale Xiong, Hanno Becker, Dominic P. Mulligan, Gustavo Petri, and Nathan Chong. A Verification Methodology for the Arm® Confidential Computing Architecture: From a Secure Specification to Safe Implementations.ACM SIGPLAN Conference on Obje...
2023
-
[40]
SGX- LAPD: Thwarting Controlled Side Channel Attacks via Enclave Ver- ifiable Page Faults
Yangchun Fu, Erick Bauman, Raul Quinonez, and Zhiqiang Lin. SGX- LAPD: Thwarting Controlled Side Channel Attacks via Enclave Ver- ifiable Page Faults. InSymposium on Recent Advances in Intrusion Detection (RAID), 2017
2017
-
[41]
Tau VM: the first Google Compute Engine VM running on an ARM chip
Google. Tau VM: the first Google Compute Engine VM running on an ARM chip. https://cloud.google.com/blog/products/compute/tau-t2a-is- first-compute-engine-vm-on-an-arm-chip, 2022. Accessed: 2025-08-25
2022
-
[42]
Cache Attacks on Intel SGX
Johannes G ¨otzfried, Moritz Eckert, Sebastian Schinzel, and Tilo M ¨uller. Cache Attacks on Intel SGX. InACM European Workshop on System Security (EuroSec), 2017
2017
-
[43]
ARM-Based Servers Market Summary
Grand View Research. ARM-Based Servers Market Summary. https://www.grandviewresearch.com/industry-analysis/arm-based- servers-market-report, 2025. Accessed: 2025-08-27
2025
-
[44]
TrustShadow: Secure Execution of Unmodified Applications with ARM TrustZone
Le Guan, Peng Liu, Xinyu Xing, Xinyang Ge, Shengzhi Zhang, Meng Yu, and Trent Jaeger. TrustShadow: Secure Execution of Unmodified Applications with ARM TrustZone. InACM International Conference on Mobile Systems, Applications, and Services (MobiSys), 2017
2017
-
[45]
Switchpoline: A Software Mitigation for Spectre-BTB and Spectre-BHB on ARMv8
Lorenz Hetterich, Markus Bauer, Michael Schwarz, and Christian Rossow. Switchpoline: A Software Mitigation for Spectre-BTB and Spectre-BHB on ARMv8. InACM Symposium on Information, Com- puter and Communications Security (ASIACCS), 2024
2024
-
[46]
Branch Different - Spectre Attacks on Apple Silicon
Lorenz Hetterich and Michael Schwarz. Branch Different - Spectre Attacks on Apple Silicon. InDetection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), 2022. 14
2022
-
[47]
Using innovative instructions to create trustwor- thy software solutions
Matthew Hoekstra, Reshma Lal, Pradeep Pappachan, Vinay Phegade, and Juan del Cuvillo. Using innovative instructions to create trustwor- thy software solutions. InInternational Workshop on Hardware and Architectural Support for Security and Privacy (HASP), 2013
2013
-
[48]
HiveTEE: Scalable and Fine- grained Isolated Domains with RME and MTE Co-assisted.IEEE Transactions on Information Forensics and Security, 2026
Haoyang Huang and Fengwei Zhangy. HiveTEE: Scalable and Fine- grained Isolated Domains with RME and MTE Co-assisted.IEEE Transactions on Information Forensics and Security, 2026
2026
-
[49]
Bluethunder: A 2-level Directional Predictor Based Side-Channel Attack against SGX.IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(1), 2020
Tianlin Huo, Xiaoni Meng, Wenhao Wang, Chunliang Hao, Pei Zhao, Jian Zhai, and Mingshu Li. Bluethunder: A 2-level Directional Predictor Based Side-Channel Attack against SGX.IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(1), 2020
2020
-
[50]
Intel® Software Guard Extensions (Intel® SGX)
Intel. Intel® Software Guard Extensions (Intel® SGX). https: //cdrdv2-public.intel.com/671581/intel-sgx-developer-guide.pdf, 2018. Accessed: 2025-08-25
2018
-
[51]
11th generation intel® core™ processors
Intel. 11th generation intel® core™ processors. https://cdrdv2.intel.com/ v1/dl/getContent/634648, 2020. Accessed: 2025-08-25
2020
-
[52]
Intel SGX Protects German Electronic Patient Records
Intel. Intel SGX Protects German Electronic Patient Records. https://www.intel.com/content/www/us/en/newsroom/news/intel-sgx- protects-german-electronic-patient-records.html#gs.heuo6x, 2021. Accessed: 2025-08-25
2021
-
[53]
Microsoft Protects $25B in Customer Payments
Intel. Microsoft Protects $25B in Customer Payments. https://www.intel.com/content/www/us/en/security/resources/microsoft- azure-confidential-computing-brief.html, 2023. Accessed: 2025-08-25
2023
-
[54]
Securing Your Trust Boundary with Intel SGX and Intel TDX
Intel. Securing Your Trust Boundary with Intel SGX and Intel TDX. https://www.intel.com/content/www/us/en/content-details/ 816053/securing-your-trust-boundary-with-intel-sgx-and-intel- tdx.html?DocID=816053, 2024. Accessed: 2025-08-25
2024
-
[55]
HyperEnclave: An Open and Cross- platform Trusted Execution Environment
Yuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen, Zhengde Zhai, Shoumeng Yan, and Zhengyu He. HyperEnclave: An Open and Cross- platform Trusted Execution Environment. InUSENIX Annual Technical Conference (ATC), 2022
2022
-
[56]
Spectre Attacks: Ex- ploiting Speculative Execution
Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. Spectre Attacks: Ex- ploiting Speculative Execution. InIEEE Symposium on Security and Privacy (S&P), 2019
2019
-
[57]
Reverse Engineering x86 Processor Microcode
Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, and Thorsten Holz. Reverse Engineering x86 Processor Microcode. InUSENIX Security Symposium, 2017
2017
-
[58]
Keystone: an open framework for architecting trusted execution environments
Dayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic, and Dawn Song. Keystone: an open framework for architecting trusted execution environments. InEuropean Conference on Computer Systems (EuroSys), 2020
2020
-
[59]
Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing
Sangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, and Marcus Peinado. Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing. InUSENIX Security Symposium, 2017
2017
-
[60]
Design and Verification of the Arm Confidential Compute Architecture
Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. Design and Verification of the Arm Confidential Compute Architecture. InSymposium on Operating Systems Design and Implementation (OSDI), 2022
2022
-
[61]
Hans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez, Jan- Erik Ekberg, and N. Asokan. PAC it up: Towards Pointer Integrity using ARM Pointer Authentication. InUSENIX Security Symposium, 2019
2019
-
[62]
EL3XIR: Fuzzing COTS Secure Monitors
Christian Lindenmeier, Mathias Payer, and Marcel Busch. EL3XIR: Fuzzing COTS Secure Monitors. InUSENIX Security Symposium, 2024
2024
-
[63]
Meltdown: Reading Kernel Memory from User Space
Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. Meltdown: Reading Kernel Memory from User Space. InUSENIX Security Symposium, 2018
2018
-
[64]
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA.arXiv, 2025
Shiqi Liu, Yongpeng Gao, Mingyang Zhang, and Jie Wang. NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA.arXiv, 2025
2025
-
[65]
Shiqi Liu, Zhouqi Jiang, Jie Wang, Wei Zhou, Kun Sun, Zhaohui Chen, and Yulai Xie. More granular, less trust: Enforcing intra-process isolation with arm cca in an untrusted management environment.IEEE Transactions on Information Forensics and Security, 20:12507–12522, 2025
2025
-
[66]
Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R
Frank McKeen, Ilya Alexandrovich, Alex Berenzon, Carlos V . Rozas, Hisham Shafi, Vedvyas Shanbhogue, and Uday R. Savagaonkar. In- novative instructions and software model for isolated execution. In International Workshop on Hardware and Architectural Support for Security and P...
2013
-
[67]
Azure Virtual Machines with Ampere Altra ARM-based processors generally available
Microsoft. Azure Virtual Machines with Ampere Altra ARM-based processors generally available. https://azure.microsoft.com/en-us/ blog/azure-virtual-machines-with-ampere-altra-arm-based-processors- generally-available/, 2022. Accessed: 2025-08-25
2022
-
[68]
CacheZoom: How SGX Amplifies the Power of Cache Attacks
Ahmad Moghimi, Gorka Irazoqui, and Thomas Eisenbarth. CacheZoom: How SGX Amplifies the Power of Cache Attacks. InConference on Cryptographic Hardware and Embedded Systems (CHES), 2017
2017
-
[69]
Privacy-preserving digital ads infrastructure: An overview of Anonym’s technology
Mozilla. Privacy-preserving digital ads infrastructure: An overview of Anonym’s technology. https://blog.mozilla.org/en/products/anonym- technology-overview/, 2025. Accessed: 2025-08-25
2025
-
[70]
Mulligan, Gustavo Petri, Nick Spinale, Gareth Stockwell, and Hugo J
Dominic P. Mulligan, Gustavo Petri, Nick Spinale, Gareth Stockwell, and Hugo J. M. Vincent. Confidential Computing - a brave new world. In International Symposium on Secure and Private Execution Environment Design (SEED), 2021
2021
-
[71]
NGINX. nginx. https://nginx.org/en/, 2024. Accessed: 2025-08-25
2024
-
[72]
Everything You Should Know About Intel SGX Performance on Virtualized Systems.ACM on Measurement and Analysis of Computing Systems (POMACS), 2019
Tu Dinh Ngoc, Bao Bui, Stella Bitchebe, Alain Tchana, Valerio Schi- avoni, Pascal Felber, and Daniel Hagimont. Everything You Should Know About Intel SGX Performance on Virtualized Systems.ACM on Measurement and Analysis of Computing Systems (POMACS), 2019
2019
-
[73]
A Survey of Published Attacks on Intel SGX
Alexander Nilsson, Pegah Nikbakht Bideh, and Joakim Brorsson. A Survey of Published Attacks on Intel SGX. Technical report, arXiv,
-
[74]
https://arxiv.org/abs/2006.13598
2006
-
[75]
Demystifying Arm TrustZone: A Comprehensive Survey.ACM Computing Surveys (CSUR), 51(6), 2019
Sandro Pinto and Nuno Santos. Demystifying Arm TrustZone: A Comprehensive Survey.ACM Computing Surveys (CSUR), 51(6), 2019
2019
-
[76]
Tarnhelm: Isolated, Transparent & Confiden- tial Execution of Arbitrary Code in ARM’s TrustZone
Davide Quarta, Michele Ianni, Aravind Machiry, Yanick Fratantonio, Eric Gustafson, Davide Balzarotti, Martina Lindorfer, Giovanni Vigna, and Christopher Kruegel. Tarnhelm: Isolated, Transparent & Confiden- tial Execution of Arbitrary Code in ARM’s TrustZone. InResearch on Offe...
2021
-
[77]
Flip Feng Shui: Hammering a needle in the software stack
Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuf- frida, and Herbert Bos. Flip Feng Shui: Hammering a needle in the software stack. InUSENIX Security Symposium, 2016
2016
-
[78]
Portal: Fast and secure device access with arm cca for modern arm mobile system- on-chips (socs)
Fan Sang, Jaehyuk Lee, Xiaokuan Zhang, and Taesoo Kim. Portal: Fast and secure device access with arm cca for modern arm mobile system- on-chips (socs). InIEEE Symposium on Security and Privacy (S&P), 2025
2025
-
[79]
BarriCCAde: Isolating Closed-Source Drivers with ARM CCA
Matti Schulze, Christian Lindenmeier, and Jonas R ¨ockl. BarriCCAde: Isolating Closed-Source Drivers with ARM CCA. InIEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2024
2024
-
[80]
Exploiting the DRAM rowhammer bug to gain kernel privileges
Mark Seaborn and Thomas Dullien. Exploiting the DRAM rowhammer bug to gain kernel privileges. https://googleprojectzero.blogspot.com/ 2015/03/exploiting-dram-rowhammer-bug-to-gain.html, 2015
2015
-
[81]
Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX
Youren Shen, Hongliang Tian, Yu Chen, Kang Chen, Runji Wang, Yi Xu, Yubin Xia, and Shoumeng Yan. Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX. InConference on Architectural Support for Programming Languages and Operating Systems (ASPLOS), 2020
2020
-
[82]
Technology preview: Private contact discovery for Signal
Signal. Technology preview: Private contact discovery for Signal. https: //signal.org/blog/private-contact-discovery/, 2017. Accessed: 2025-08- 25
2017
-
[83]
ACAI: Protecting Accelerator Execution with Arm Confidential Computing Architecture
Supraja Sridhara, Andrin Bertschi, Benedict Schl ¨uter, Mark Kuhne, Fabio Aliberti, and Shweta Shinde. ACAI: Protecting Accelerator Execution with Arm Confidential Computing Architecture. InUSENIX Security Symposium, 2024
2024
-
[84]
Kalodner, Vrushali Kulkarni, Daniela Oliveira, and Donald E
Chia-Che Tsai, Kumar Saurabh Arora, Nehal Bandi, Bhushan Jain, William Jannen, Jitin John, Harry A. Kalodner, Vrushali Kulkarni, Daniela Oliveira, and Donald E. Porter. Cooperation and security isolation of library OSes for multi-process applications. InEuropean Conference on ...
2014
-
[85]
Porter, and Mona Vij
Chia-Che Tsai, Donald E. Porter, and Mona Vij. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. InUSENIX Annual Technical Conference (ATC), 2017
2017
-
[86]
CAGE: Comple- menting Arm CCA with GPU Extensions
Chenxu Wang, Fengwei Zhang, Yunjie Deng, Kevin Leach, Jiannong Cao, Zhenyu Ning, Shoumeng Yan, and Zhengyu He. CAGE: Comple- menting Arm CCA with GPU Extensions. InSymposium on Network and Distributed System Security (NDSS), 2024
2024
-
[87]
The Road to Trust: Building Enclaves within Confidential VMs
Wenhao Wang, Linke Song, Benshan Mei, Shuang Liu, Shijun Zhao, Shoumeng Yan, XiaoFeng Wang, Dan Meng, and Rui Hou. The Road to Trust: Building Enclaves within Confidential VMs. InSymposium on Network and Distributed System Security (NDSS), 2025
2025
-
[88]
Intel Software Guard Extensions Applications: A Survey.ACM Computing Surveys (CSUR), 55(14s), 2023
Newton Carlos Will and Carlos Alberto Maziero. Intel Software Guard Extensions Applications: A Survey.ACM Computing Surveys (CSUR), 55(14s), 2023. 15
2023
-
[89]
Cordeiro
Tong Wu, Shale Xiong, Edoardo Manino, Gareth Stockwell, and Lu- cas C. Cordeiro. Verifying Components of Arm ® Confidential Com- puting Architecture with ESBMC. InStatic Analysis Symposium, 2024
2024
-
[90]
One bit flips, one cloud flops: cross-VM row hammer attacks and privilege escalation
Yuan Xiao, Xiaokuan Zhang, Yinqian Zhang, and Radu Teodorescu. One bit flips, one cloud flops: cross-VM row hammer attacks and privilege escalation. InUSENIX Security Symposium, 2016
2016
-
[91]
UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems
Huaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao, Yier Jin, Haobo Li, Ming Yang, Ping Jiang, and Junzhou Luo. UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems. 2026
2026
-
[92]
The HitchHiker’s Guide to High-Assurance System Observability Protection with Efficient Permission Switches
Chuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad, Fengwei Zhang, Hai Jin, and Zhenkai Liang. The HitchHiker’s Guide to High-Assurance System Observability Protection with Efficient Permission Switches. In ACM Conference on Computer and Communications Security (CCS), 2024
2024
-
[93]
Enabling Execution Assurance of Federated Learning at Untrusted Participants
Xiaoli Zhang, Fengting Li, Zeyu Zhang, Qi Li, Cong Wang, and Jianping Wu. Enabling Execution Assurance of Federated Learning at Untrusted Participants. InIEEE Conference on Computer Communications (IN- FOCOM), 2020
2020
-
[94]
SHELTER: Ex- tending Arm CCA with Isolation in User Space
Yiming Zhang, Yuxin Hu, Zhenyu Ning, Fengwei Zhang, Xiapu Luo, Haoyang Huang, Shoumeng Yan, and Zhengyu He. SHELTER: Ex- tending Arm CCA with Isolation in User Space. InUSENIX Security Symposium, 2023
2023
-
[95]
vSGX: Virtualizing SGX Enclaves on AMD SEV
Shixuan Zhao, Mengyuan Li, Yinqian Zhang, and Zhiqiang Lin. vSGX: Virtualizing SGX Enclaves on AMD SEV. InIEEE Symposium on Security and Privacy (S&P), 2022
2022
-
[96]
MPTEE: bringing flexible and efficient memory protection to intel SGX
Wenjia Zhao, Kangjie Lu, Yong Qi, and Saiyu Qi. MPTEE: bringing flexible and efficient memory protection to intel SGX. InEuropean Conference on Computer Systems (EuroSys), 2020
2020
-
[97]
RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Prim- itives
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Peng Liu, Shengzhi Zhang, Jiayun Chen, Shaowen Xu, and Zhenyu Song. RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Prim- itives. 2025
2025
-
[98]
FlexClave: An Extensible and Secure Trusted Execution Environment Framework.IEEE Transactions on Computers, 2026
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shaowen Xu, Jiayun Chen, Nan Jiang, Zhicong Zhang, Zhenyu Song, Haichao Du, Yamin Xie, et al. FlexClave: An Extensible and Secure Trusted Execution Environment Framework.IEEE Transactions on Computers, 2026. 16 APPENDIX In this appendix, w...
2026
Reviewed May 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.