arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.11411cs.CR

“他们并不关心这个”:对现实世界中TEE构建可复现性的系统性研究

"They don't care about this": A Systematic Study of TEE Build Reproducibility in the Wild

Annika Wilde, Marco Gutfleisch, Felix Reichmann, Anirban Chakraborty, Yuval Yarom, M. Angela Sasse, Ghassan Karame

首次发表
浏览论文内容

中文总结 AI 辅助

本研究通过分析115个TEE部署,发现91%不可复现,并通过访谈揭示技术及生态系统级障碍,主张需整体开发方法实现可复现性。

中文摘要 AI 辅助

可信执行环境(TEE)已成为现代云计算的基石,为代码和数据提供强大的机密性和完整性保证。该信任模型的一个关键组成部分是远程证明,它使外部实体能够通过加密测量来验证在TEE内执行的代码的真实性和完整性。然而,远程证明的有效性从根本上取决于验证者将报告的测量结果追溯到原始源代码的能力——这一属性只能通过可复现的构建来保证。在本文中,我们通过对115个TEE部署的技术分析来研究TEE构建的可复现性。我们的分析涵盖了流行的TEE,如Intel SGX、Intel TDX和AMD SEV,并揭示了一个惊人的事实:其中91%的部署不可复现,80%未能同时提供源代码和参考构建,而这两者是实现可复现性的两个基本前提。为了探究根本原因,我们联系了50个SGX项目的维护者,并成功从工业界和学术界招募了12名开发者进行访谈。在我们的参与者中,只有一人报告称可复现性是开发过程中的优先事项,这有效地证实了我们的技术发现。除了可以轻易解决的技术障碍(例如,二进制文件中包含的时间戳)之外,我们还识别出更广泛的生态系统级挑战,例如在涉及多个利益相关者的项目中缺乏对构建环境的控制。我们认为,在TEE中实现可复现性需要一种超越单个开发者的整体开发方法,并要求更强的承诺——而不是将TEE视为一种“安全徽章”。

英文摘要

Trusted Execution Environments (TEEs) have become a cornerstone of modern cloud computing, providing strong confidentiality and integrity guarantees for both code and data. A critical component of this trust model is remote attestation, which enables external entities to verify the authenticity and integrity of code executing within a TEE through cryptographic measurements. However, the effectiveness of remote attestation fundamentally depends on the verifier's ability to trace the reported measurement back to the original source code - a property that can only be guaranteed through reproducible builds. In this paper, we investigate the reproducibility of TEE builds through a technical analysis of 115 TEE deployments. Our analysis spans popular TEEs such as Intel SGX, Intel TDX, and AMD SEV, and reveals that a striking 91% of those deployments were not reproducible, with 80% failing to provide both source code and a reference build, the two essential prerequisites for reproducibility. To explore the root causes, we contacted the maintainers of 50 SGX projects and managed to recruit 12 developers from industry and academia for interviews. Only one of our participants reported that reproducibility is a priority during development, effectively confirming our technical findings. Beyond technical barriers (e.g., timestamps included in the binary) that can be readily addressed, we identify broader ecosystem-level challenges, such as the lack of control over the build environment in projects involving multiple stakeholders. We argue that achieving reproducibility in TEEs requires a holistic development approach that extends beyond individual developers and calls for stronger commitments - rather than treating TEEs as a "security badge".

发表机构

  • Ruhr University Bochum(鲁尔大学波鸿分校)
  • LMU Munich(慕尼黑大学)
  • Max Planck Institute for Security and Privacy(马克斯·普朗克安全与隐私研究所)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑