arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.04480cs.CR

可证明审计:基于属性的专有工作负载证明,无需披露工件

Attestable Audit: Property-Based Attestation for Proprietary Workloads without Artifact Disclosure

  • Acompany Co., Ltd.(Acompany有限公司)

机构由 AI 辅助整理,请以论文原文为准。

Takuma Imamura

AI总结:

针对专有工作负载的远程证明中验证者无法自行推导参考值的问题,提出结合可证明构建与可证明审计的架构,通过TEE内自动化审计绑定源代码摘要,在不披露工件的前提下实现属性验证,并在Intel SGX上验证了可行性。

AI中文摘要:

可信执行环境(TEE)通过远程证明向远程对等方证明代码和数据的完整性:TEE通过使用硬件绑定的密钥对其配置信息(包括在其中加载的代码的测量值(加密摘要))进行签名来发布证明报告。验证者通过将这些测量值与参考值进行匹配来评估报告。然而,当被测量的工件是专有的时,验证者无法自行推导参考值:它只能确认具有给定测量值的某个东西正在TEE内运行——而不能确认程序按预期行为——从而迫使完全信任参考值提供者。我们提出了一种架构,在不披露工件的情况下弥合这一差距,该架构组合了两个TEE工作负载:可证明构建(Hugenroth等人,2025),它将源代码摘要绑定到构建工件测量值;以及可证明审计(本文提出),它将相同的源代码摘要绑定到在TEE内执行的自动化审计(模糊测试、静态分析、AI代码审计、形式化方法)的判定结果。两者都是机密计算证明的实例:将TEE证明视为硬件支持的知识零知识证明。链接这两个证书使验证者能够得出结论,即正在运行的工件是由满足已审计属性的源代码构建的,而无需披露源代码或构建工件。在带有Gramine库操作系统的Intel SGX上运行Bandit安全分析器对Python代码进行的概念验证实现,证明了该方法的实用性。

英文摘要:

Trusted Execution Environments (TEEs) prove the integrity of code and data to a remote peer through remote attestation: the TEE issues an attestation report by signing, with a hardware-bound key, its configuration information, including measurements (cryptographic digests) of the code loaded inside it. A verifier appraises the report by matching these measurements against reference values. When the measured artifact is proprietary, however, the verifier cannot derive the reference values itself: it can only confirm that something with a given measurement is running inside the TEE---not that the program behaves as expected---forcing full trust in the reference value provider. We propose an architecture that closes this gap without disclosing the artifact, composing two TEE workloads: attestable build (Hugenroth et al., 2025), which binds a source code digest to a build artifact measurement, and attestable audit (proposed in this paper), which binds the same source code digest to the verdicts of automated audits---fuzzing, static analysis, AI code auditing, formal methods---executed inside a TEE. Both are instances of Confidential Computing Proofs: TEE attestation viewed as a hardware-backed zero-knowledge proof. Chaining the two certificates lets the verifier conclude that the running artifact was built from source code satisfying the audited properties, without disclosing either the source code or the build artifact. A proof-of-concept implementation on Intel SGX with the Gramine Library OS, running the Bandit security analyzer on Python code, demonstrates the practicality of the approach.

补充信息

↑