Integrating Byzantine fault-tolerant (BFT) replication with trusted execution environments (TEEs) offers an unprecedented degree of resilience and confidentiality. Nevertheless, vulnerabilities in both the underlying infrastructure and the application software still exist, which means that for long-running services there typically is a substantial risk that eventually the number of faulty or compromised replicas exceeds a system’s fault-tolerance threshold. We address this issue with Naboris, the first approach in the area of confidential computing to provide long-term resilience for critical BFT services. To achieve this, Naboris combines (1) proactive recovery of replicas to remove faults with (2) support for software upgrades to patch newly discovered vulnerabilities at runtime. For both of these procedures, Naboris afterwards provides remote entities with verifiable evidence that they actually took place. We implement Naboris using AMD SEV-SNP and show that its performance overhead is low compared to the state of the art in recovery procedures.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

TEE-Assisted Recovery and Upgrades for Long-Running BFT Services

  • Ines Messadi,
  • Markus Elias Gerber,
  • Tobias Distler,
  • Rüdiger Kapitza

摘要

Integrating Byzantine fault-tolerant (BFT) replication with trusted execution environments (TEEs) offers an unprecedented degree of resilience and confidentiality. Nevertheless, vulnerabilities in both the underlying infrastructure and the application software still exist, which means that for long-running services there typically is a substantial risk that eventually the number of faulty or compromised replicas exceeds a system’s fault-tolerance threshold. We address this issue with Naboris, the first approach in the area of confidential computing to provide long-term resilience for critical BFT services. To achieve this, Naboris combines (1) proactive recovery of replicas to remove faults with (2) support for software upgrades to patch newly discovered vulnerabilities at runtime. For both of these procedures, Naboris afterwards provides remote entities with verifiable evidence that they actually took place. We implement Naboris using AMD SEV-SNP and show that its performance overhead is low compared to the state of the art in recovery procedures.