发表机构
University of British Columbia; SUSTech; Research Institute of Trustworthy Autonomous Systems of SUSTech; City University of Hong Kong; National University of Singapore(不列颠哥伦比亚大学; 南方科技大学; 南方科技大学可信自主系统研究院; 香港城市大学; 新加坡国立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出Raftel,首个面向任意部分TEE部署的HotStuff风格BFT协议,通过双法定人数和TEE领导者快速路径,在WAN中实现625 TPS,优于HotStuff。
AI 中文摘要
本文在通用部分TEE模型下重新审视了TEE辅助的BFT共识,在该模型中,任意子集的副本在TEE内执行,而其余副本在没有硬件信任保证的情况下运行。我们表明,异构信任改变了法定人数形成和容错性的结构。特别是,我们推导出了一个严格的韧性界限 f < max {n/3, m/2},其中 n 是副本总数,m 是启用TEE的副本数量。该结果揭示了一个尖锐的阈值现象:只有当TEE超过部署的三分之二时,它们才能提高容错性。在此特征的指导下,我们引入了两个协议原则:(1)一种双法定人数构造,安全地结合了仅TEE和混合法定人数,以及(2)一种TEE领导者快速路径,利用硬件强制的不可双重声明来减少共识和视图变更延迟。我们在Raftel中实现了这些想法,据我们所知,这是第一个专门为任意部分TEE部署设计的HotStuff风格BFT协议,并在chained-Raftel中实现,这是一种流水线变体,进一步加速了混合信任执行。我们在Intel SGX之上实现了这两种协议,并在LAN和WAN环境中进行了评估。我们的结果表明,Raftel在WAN设置中实现了高达625 TPS的吞吐量,延迟低于670毫秒,在吞吐量上比HotStuff高出高达308 TPS,同时接近完全TEE辅助协议的性能。
英文摘要
This paper revisits TEE-assisted BFT under a universal partial-TEE model, where an arbitrary subset of replicas execute inside TEEs while the remaining replicas operate without hardware trust guarantees. We show that heterogeneous trust changes the structure of quorum formation and fault tolerance. In particular, we derive a tight resilience bound f < max {n/3, m/2}, where n is the total number of replicas and m is the number of TEE-enabled replicas. The result reveals a sharp threshold phenomenon: TEEs improve fault tolerance only once they exceed two-thirds of the deployment. Guided by this characterization, we introduce two protocol principles: (1) a dual-quorum construction that safely combines TEE-only and mixed quorums, and (2) a TEE-leader fast path that leverages hardware-enforced non-equivocation to reduce both consensus and view-change latency. We realize these ideas in Raftel, which is, to our knowledge, the first HotStuff-style BFT protocol designed explicitly for arbitrary partial-TEE deployments, and in chained-Raftel, a pipelined variant that further accelerates mixed-trust execution. We implement both protocols atop Intel SGX and evaluate them in LAN and WAN environments. Our results show that Raftel achieves up to 625 TPS with sub-670 ms latency in WAN settings, outperforming HotStuff by up to 308 TPS in throughput while approaching the performance of fully TEE-assisted protocols.
CommentsAccepted to EuroSys 2027