{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T21:02:36Z","timestamp":1784926956232,"version":"3.55.0"},"publisher-location":"Cham","reference-count":74,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319566191","type":"print"},{"value":"9783319566207","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-56620-7_10","type":"book-chapter","created":{"date-parts":[[2017,3,31]],"date-time":"2017-03-31T02:29:18Z","timestamp":1490927358000},"page":"260-289","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":77,"title":["Formal Abstractions for Attested Execution Secure Processors"],"prefix":"10.1007","author":[{"given":"Rafael","family":"Pass","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Elaine","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Tram\u00e8r","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,4,1]]},"reference":[{"key":"10_CR1","unstructured":"Trusted computing group. http:\/\/www.trustedcomputinggroup.org\/"},{"key":"10_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1007\/3-540-45500-0_4","volume-title":"Theoretical Aspects of Computer Software","author":"M Abadi","year":"2001","unstructured":"Abadi, M., J\u00fcrjens, J.: Formal eavesdropping and its computational interpretation. In: Kobayashi, N., Pierce, B.C. (eds.) TACS 2001. LNCS, vol. 2215, pp. 82\u201394. Springer, Heidelberg (2001). doi: 10.1007\/3-540-45500-0_4"},{"issue":"3","key":"10_CR3","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/s00145-007-0203-0","volume":"20","author":"M Abadi","year":"2007","unstructured":"Abadi, M., Rogaway, P.: Reconciling two views of cryptography (the computational soundness of formal encryption). J. Cryptol. 20(3), 395 (2007)","journal-title":"J. Cryptol."},{"key":"10_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1007\/11555827_22","volume-title":"Computer Security \u2013 ESORICS 2005","author":"P Ad\u00e3o","year":"2005","unstructured":"Ad\u00e3o, P., Bana, G., Herzog, J., Scedrov, A.: Soundness of formal encryption in the presence of key-cycles. In: Vimercati, S.C., Syverson, P., Gollmann, D. (eds.) ESORICS 2005. LNCS, vol. 3679, pp. 374\u2013396. Springer, Heidelberg (2005). doi: 10.1007\/11555827_22"},{"issue":"4","key":"10_CR5","first-page":"18","volume":"3","author":"T Alves","year":"2004","unstructured":"Alves, T., Felton, D.: Trustzone: integrated hardware and software security. Inf. Q. 3(4), 18\u201324 (2004)","journal-title":"Inf. Q."},{"key":"10_CR6","unstructured":"Anati, I., Gueron, S., Johnson, S.P., Scarlata, V.R.: Innovative technology for CPU based attestation and sealing. In: HASP (2013)"},{"key":"10_CR7","unstructured":"ARM Limited: ARM Security Technology Building a Secure System using TrustZone $$\\textregistered $$ Technology, April 2009. Reference no. PRD29-GENC-009492C"},{"key":"10_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-3-662-46494-6_10","volume-title":"Theory of Cryptography","author":"G Asharov","year":"2015","unstructured":"Asharov, G., Beimel, A., Makriyannis, N., Omri, E.: Complete characterization of fairness in secure two-party computation of Boolean functions. In: Dodis, Y., Nielsen, J.B. (eds.) TCC 2015. LNCS, vol. 9014, pp. 199\u2013228. Springer, Heidelberg (2015). doi: 10.1007\/978-3-662-46494-6_10"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Backes, M., Pfitzmann, B., Waidner, M.: A universally composable cryptographic library. IACR Cryptology ePrint Archive, 2003:15 (2003)","DOI":"10.1145\/948109.948140"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Barbosa, M., Portela, B., Scerri, G., Warinschi, B.: Foundations of hardware-based attested computation and application to SGX. In: IEEE European Symposium on Security and Privacy, pp. 245\u2013260 (2016)","DOI":"10.1109\/EuroSP.2016.28"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Baumann, A., Peinado, M., Hunt, G.: Shielding applications from an untrusted cloud with haven. In: OSDI (2014)","DOI":"10.1145\/2799647"},{"key":"10_CR12","unstructured":"Berger, S., C\u00e1ceres, R., Goldman, K.A., Perez, R., Sailer, R., van Doorn, L.: vTPM: virtualizing the trusted platform module. In: USENIX Security (2006)"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Bohl, F., Unruh, D.: Symbolic universal composability. In: IEEE Computer Security Foundations Symposium, pp. 257\u2013271 (2013)","DOI":"10.1109\/CSF.2013.24"},{"key":"10_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1007\/3-540-44598-6_15","volume-title":"Advances in Cryptology \u2014 CRYPTO 2000","author":"D Boneh","year":"2000","unstructured":"Boneh, D., Naor, M.: Timed commitments. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol. 1880, pp. 236\u2013254. Springer, Heidelberg (2000). doi: 10.1007\/3-540-44598-6_15"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Brickell, E., Camenisch, J., Chen, L.: Direct anonymous attestation. In: CCS (2004)","DOI":"10.1145\/1030083.1030103"},{"key":"10_CR16","unstructured":"Brickell, E., Li, J.: Enhanced privacy id from bilinear pairing. IACR Cryptology ePrint Archive, 2009:95 (2009)"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. In: FOCS (2001)","DOI":"10.1109\/SFCS.2001.959888"},{"key":"10_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-3-540-70936-7_4","volume-title":"Theory of Cryptography","author":"R Canetti","year":"2007","unstructured":"Canetti, R., Dodis, Y., Pass, R., Walfish, S.: Universally composable security with global setup. In: Vadhan, S.P. (ed.) TCC 2007. LNCS, vol. 4392, pp. 61\u201385. Springer, Heidelberg (2007). doi: 10.1007\/978-3-540-70936-7_4"},{"key":"10_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/3-540-44647-8_2","volume-title":"Advances in Cryptology \u2014 CRYPTO 2001","author":"R Canetti","year":"2001","unstructured":"Canetti, R., Fischlin, M.: Universally composable commitments. In: Kilian, J. (ed.) CRYPTO 2001. LNCS, vol. 2139, pp. 19\u201340. Springer, Heidelberg (2001). doi: 10.1007\/3-540-44647-8_2"},{"issue":"1","key":"10_CR20","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/s00145-009-9055-0","volume":"24","author":"R Canetti","year":"2011","unstructured":"Canetti, R., Herzog, J.: Universally composable symbolic security analysis. J. Cryptol. 24(1), 83\u2013147 (2011)","journal-title":"J. Cryptol."},{"key":"10_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/978-3-540-45146-4_16","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"R Canetti","year":"2003","unstructured":"Canetti, R., Rabin, T.: Universal composition with joint state. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 265\u2013281. Springer, Heidelberg (2003). doi: 10.1007\/978-3-540-45146-4_16"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Champagne, D., Lee, R.B.: Scalable architectural support for trusted software. In: HPCA (2010)","DOI":"10.1109\/HPCA.2010.5416657"},{"key":"10_CR23","unstructured":"Chen, C., Raj, H., Saroiu, S., Wolman, A.: cTPM: a cloud TPM for cross-device trusted applications. In: NSDI (2014)"},{"key":"10_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-642-42045-0_7","volume-title":"Advances in Cryptology - ASIACRYPT 2013","author":"K-M Chung","year":"2013","unstructured":"Chung, K.-M., Katz, J., Zhou, H.-S.: Functional encryption from (small) hardware tokens. In: Sako, K., Sarkar, P. (eds.) ASIACRYPT 2013. LNCS, vol. 8270, pp. 120\u2013139. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-42045-0_7"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Cleve, R.: Limits on the security of coin flips when half the processors are faulty. In: STOC 1986, pp. 364\u2013369 (1986)","DOI":"10.1145\/12130.12168"},{"key":"10_CR26","unstructured":"Costan, V., Devadas, S.: Intel SGX explained. Manuscript (2015)"},{"key":"10_CR27","unstructured":"Costan, V., Lebedev, I., Devadas, S.: Sanctum: minimal hardware extensions for strong software isolation. In: USENIX Security (2016)"},{"key":"10_CR28","unstructured":"Dinh, T.T.A., Saxena, P., Chang, E.-C., Ooi, B.C., Zhang, C.: M2R: enabling stronger privacy in MapReduce computation. In: USENIX Security (2015)"},{"key":"10_CR29","unstructured":"D\u00f6ttling, N., Mie, T., M\u00fcller-Quade, J., Nilges, T.: Basing obfuscation on simple tamper-proof hardware assumptions. IACR Cryptology ePrint Archive 2011:675 (2011)"},{"issue":"6","key":"10_CR30","doi-asserted-by":"publisher","first-page":"637","DOI":"10.1145\/3812.3818","volume":"28","author":"S Even","year":"1985","unstructured":"Even, S., Goldreich, O., Lempel, A.: A randomized protocol for signing contracts. Commun. ACM 28(6), 637\u2013647 (1985)","journal-title":"Commun. ACM"},{"key":"10_CR31","unstructured":"Ferraiuolo, A., Wang, Y., Rui, X., Zhang, D., Myers, A., Edward, G.S.: Full-processor timing channel protection with applications to secure hardware compartments (2015)"},{"key":"10_CR32","doi-asserted-by":"crossref","unstructured":"Fletcher, C.W., van Dijk, M., Devadas, S.: A secure processor architecture for encrypted computation on untrusted programs. In: STC (2012)","DOI":"10.1145\/2382536.2382540"},{"key":"10_CR33","doi-asserted-by":"crossref","unstructured":"Fletcher, C.W., Ren, L., Kwon, A., van Dijk, M., Stefanov, E., Devadas, S.: RAW Path ORAM: a low-latency, low-area hardware ORAM controller with integrity verification. IACR Cryptology ePrint Archive 2014:431 (2014)","DOI":"10.1109\/FCCM.2015.58"},{"key":"10_CR34","doi-asserted-by":"crossref","unstructured":"Fletcher, C.W., Ren, L., Xiangyao, Y., van Dijk, M., Khan, O., Devadas, S.: Suppressing the oblivious RAM timing channel while making information leakage and program efficiency trade-offs. In: HPCA, pp. 213\u2013224 (2014)","DOI":"10.1109\/HPCA.2014.6835932"},{"key":"10_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"404","DOI":"10.1007\/11681878_21","volume-title":"Theory of Cryptography","author":"J Garay","year":"2006","unstructured":"Garay, J., MacKenzie, P., Prabhakaran, M., Yang, K.: Resource fairness and composability of cryptographic protocols. In: Halevi, S., Rabin, T. (eds.) TCC 2006. LNCS, vol. 3876, pp. 404\u2013428. Springer, Heidelberg (2006). doi: 10.1007\/11681878_21"},{"issue":"6","key":"10_CR36","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1145\/2851486","volume":"59","author":"D Genkin","year":"2016","unstructured":"Genkin, D., Pachmanov, L., Pipman, I., Shamir, A., Tromer, E.: Physical key extraction attacks on PCs. Commun. ACM 59(6), 70\u201379 (2016)","journal-title":"Commun. ACM"},{"key":"10_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-85174-5_3","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"S Goldwasser","year":"2008","unstructured":"Goldwasser, S., Kalai, Y.T., Rothblum, G.N.: One-time programs. In: Wagner, D. (ed.) CRYPTO 2008. LNCS, vol. 5157, pp. 39\u201356. Springer, Heidelberg (2008). doi: 10.1007\/978-3-540-85174-5_3"},{"key":"10_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-00457-5_2","volume-title":"Theory of Cryptography","author":"S Dov Gordon","year":"2009","unstructured":"Dov Gordon, S., Katz, J.: Complete fairness in multi-party computation without an honest majority. In: Reingold, O. (ed.) TCC 2009. LNCS, vol. 5444, pp. 19\u201335. Springer, Heidelberg (2009). doi: 10.1007\/978-3-642-00457-5_2"},{"issue":"6","key":"10_CR39","first-page":"24:1","volume":"58","author":"S Dov Gordon","year":"2011","unstructured":"Dov Gordon, S., Hazay, C., Katz, J., Lindell, Y.: Complete fairness in secure two-party computation. J. ACM 58(6), 24:1\u201324:37 (2011)","journal-title":"J. ACM"},{"key":"10_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1007\/978-3-642-11799-2_19","volume-title":"Theory of Cryptography","author":"V Goyal","year":"2010","unstructured":"Goyal, V., Ishai, Y., Sahai, A., Venkatesan, R., Wadia, A.: Founding cryptography on tamper-proof hardware tokens. In: Micciancio, D. (ed.) TCC 2010. LNCS, vol. 5978, pp. 308\u2013326. Springer, Heidelberg (2010). doi: 10.1007\/978-3-642-11799-2_19"},{"key":"10_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"302","DOI":"10.1007\/978-3-662-53357-4_20","volume-title":"Financial Cryptography and Data Security","author":"D Gupta","year":"2016","unstructured":"Gupta, D., Mood, B., Feigenbaum, J., Butler, K., Traynor, P.: Using intel software guard extensions for efficient two-party secure function evaluation. In: Clark, J., Meiklejohn, S., Ryan, P.Y.A., Wallach, D., Brenner, M., Rohloff, K. (eds.) FC 2016. LNCS, vol. 9604, pp. 302\u2013318. Springer, Heidelberg (2016). doi: 10.1007\/978-3-662-53357-4_20"},{"key":"10_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"367","DOI":"10.1007\/978-3-662-53641-4_15","volume-title":"Theory of Cryptography","author":"C Hazay","year":"2016","unstructured":"Hazay, C., Polychroniadou, A., Venkitasubramaniam, M.: Composable security in the tamper-proof hardware model under minimal complexity. In: Hirt, M., Smith, A. (eds.) TCC 2016. LNCS, vol. 9985, pp. 367\u2013399. Springer, Heidelberg (2016). doi: 10.1007\/978-3-662-53641-4_15"},{"key":"10_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"530","DOI":"10.1007\/978-3-540-45146-4_31","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"O Horvitz","year":"2003","unstructured":"Horvitz, O., Gligor, V.: Weak key authenticity and the computational completeness of formal encryption. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 530\u2013547. Springer, Heidelberg (2003). doi: 10.1007\/978-3-540-45146-4_31"},{"key":"10_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/978-3-540-31987-0_13","volume-title":"Programming Languages and Systems","author":"R Janvier","year":"2005","unstructured":"Janvier, R., Lakhnech, Y., Mazar\u00e9, L.: Completing the picture: soundness of formal encryption in the presence of active adversaries. In: Sagiv, M. (ed.) ESOP 2005. LNCS, vol. 3444, pp. 172\u2013185. Springer, Heidelberg (2005). doi: 10.1007\/978-3-540-31987-0_13"},{"key":"10_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/978-3-540-72540-4_7","volume-title":"Advances in Cryptology - EUROCRYPT 2007","author":"J Katz","year":"2007","unstructured":"Katz, J.: Universally composable multi-party computation using tamper-proof hardware. In: Naor, M. (ed.) EUROCRYPT 2007. LNCS, vol. 4515, pp. 115\u2013128. Springer, Heidelberg (2007). doi: 10.1007\/978-3-540-72540-4_7"},{"key":"10_CR46","unstructured":"Kauer, B.: TPM reset attack. http:\/\/www.cs.dartmouth.edu\/~pkilab\/sparks\/"},{"key":"10_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","author":"P Kocher","year":"1999","unstructured":"Kocher, P., Jaffe, J., Jun, B.: Differential power analysis. In: Wiener, M. (ed.) CRYPTO 1999. LNCS, vol. 1666, pp. 388\u2013397. Springer, Heidelberg (1999). doi: 10.1007\/3-540-48405-1_25"},{"issue":"11","key":"10_CR48","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1145\/356989.357005","volume":"35","author":"D Lie","year":"2000","unstructured":"Lie, D., Thekkath, C., Mitchell, M., Lincoln, P., Boneh, D., Mitchell, J., Horowitz, M.: Architectural support for copy and tamper resistant software. ACM SIGPLAN Not. 35(11), 168\u2013177 (2000)","journal-title":"ACM SIGPLAN Not."},{"key":"10_CR49","doi-asserted-by":"crossref","unstructured":"Maas, M., Love, E., Stefanov, E., Tiwari, M., Shi, E., Asanovic, K., Kubiatowicz, J., Song, D.: Phantom: practical oblivious computation in a secure processor. In: CCS (2013)","DOI":"10.1145\/2508859.2516692"},{"key":"10_CR50","unstructured":"Martignoni, L., Poosankam, P., Zaharia, M., Han, J., McCamant, S., Song, D., Paxson, V., Perrig, A., Shenker, S., Stoica, I.: Cloud terminal: secure access to sensitive applications from untrusted systems. In: USENIX ATC (2012)"},{"key":"10_CR51","doi-asserted-by":"crossref","unstructured":"McKeen, F., Alexandrovich, I., Berenzon, A., Rozas, C.V., Shafi, H., Shanbhogue, V., Savagaonkar, U.R.: Innovative instructions and software model for isolated execution. In: HASP 2013: 10 (2013)","DOI":"10.1145\/2487726.2488368"},{"key":"10_CR52","unstructured":"Mechler, J., Mller-Quade, J., Nilges, T.: Universally composable (non-interactive) two-party computation from untrusted reusable hardware tokens. Cryptology ePrint Archive, Report 2016\/615 (2016). http:\/\/eprint.iacr.org\/2016\/615"},{"issue":"1","key":"10_CR53","doi-asserted-by":"publisher","first-page":"99","DOI":"10.3233\/JCS-2004-12105","volume":"12","author":"D Micciancio","year":"2004","unstructured":"Micciancio, D., Warinschi, B.: Completeness theorems for the Abadi-Rogaway language of encrypted expressions. J. Comput. Secur. 12(1), 99\u2013129 (2004)","journal-title":"J. Comput. Secur."},{"key":"10_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1007\/978-3-540-24638-1_8","volume-title":"Theory of Cryptography","author":"D Micciancio","year":"2004","unstructured":"Micciancio, D., Warinschi, B.: Soundness of formal encryption in the presence of active adversaries. In: Naor, M. (ed.) TCC 2004. LNCS, vol. 2951, pp. 133\u2013151. Springer, Heidelberg (2004). doi: 10.1007\/978-3-540-24638-1_8"},{"key":"10_CR55","unstructured":"Ohrimenko, O., Schuster, F., Fournet, C., Mehta, A., Nowozin, S., Vaswani, K., Costa, M.: Oblivious multi-party machine learning on trusted processors. In: USENIX Security, August 2016"},{"key":"10_CR56","doi-asserted-by":"crossref","unstructured":"Pass, R., Shi, E., Tram\u00e8r, F.: Formal abstractions for attested execution secure processors. IACR Cryptology ePrint Archive 2016:1027 (2016)","DOI":"10.1007\/978-3-319-56620-7_10"},{"key":"10_CR57","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/978-3-662-46666-7_4","volume-title":"Principles of Security and Trust","author":"A Petcher","year":"2015","unstructured":"Petcher, A., Morrisett, G.: The foundational cryptography framework. In: Focardi, R., Myers, A. (eds.) POST 2015. LNCS, vol. 9036, pp. 53\u201372. Springer, Heidelberg (2015). doi: 10.1007\/978-3-662-46666-7_4"},{"key":"10_CR58","doi-asserted-by":"crossref","unstructured":"Petcher, A., Morrisett, G.: A mechanized proof of security for searchable symmetric encryption. In: CSF (2015)","DOI":"10.1109\/CSF.2015.36"},{"key":"10_CR59","unstructured":"Sailer, R., Zhang, X., Jaeger, T., van Doorn, L.: Design and implementation of a TCG-based integrity measurement architecture. In: USENIX Security (2004)"},{"issue":"1","key":"10_CR60","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1145\/2654822.2541949","volume":"42","author":"N Santos","year":"2014","unstructured":"Santos, N., Raj, H., Saroiu, S., Wolman, A.: Using arm trustzone to build a trusted language runtime for mobile applications. SIGARCH Comput. Archit. News 42(1), 67\u201380 (2014)","journal-title":"SIGARCH Comput. Archit. News"},{"key":"10_CR61","unstructured":"Santos, N., Rodrigues, R., Gummadi, K.P., Saroiu, S.: Policy-sealed data: a new abstraction for building trusted cloud services. In: USENIX Security, pp. 175\u2013188 (2012)"},{"key":"10_CR62","doi-asserted-by":"crossref","unstructured":"Schuster, F., Costa, M., Fournet, C., Gkantsidis, C., Peinado, M., Mainar-Ruiz, G., Russinovich, M.: VC3: trustworthy data analytics in the cloud. In: IEEE S&P (2015)","DOI":"10.1109\/SP.2015.10"},{"key":"10_CR63","unstructured":"Shi, E., Perrig, A., Van Doorn, L.: BIND: a fine-grained attestation service for secure distributed systems. In: IEEE S&P (2005)"},{"key":"10_CR64","unstructured":"Shi, E., Zhang, F., Pass, R., Devadas, S., Song, D., Liu, C.: Systematization of knowledge: trusted hardware: life, the composable universe, and everything. Manuscript (2015)"},{"key":"10_CR65","unstructured":"Smith, S.W., Austel, V.: Trusting trusted hardware: towards a formal model for programmable secure coprocessors. In: Proceedings of the 3rd Conference on USENIX Workshop on Electronic Commerce, WOEC 1998, vol. 3 (1998)"},{"key":"10_CR66","doi-asserted-by":"crossref","unstructured":"Suh, G.E., Clarke, D., Gassend, B., Van Dijk, M., Devadas, S.: AEGIS: architecture for tamper-evident and tamper-resistant processing. In: Proceedings of the 17th Annual International Conference on Supercomputing, pp. 160\u2013171. ACM (2003)","DOI":"10.1145\/782814.782838"},{"key":"10_CR67","unstructured":"Szczys, M.: TPM crytography cracked. http:\/\/hackaday.com\/2010\/02\/09\/tpm-crytography-cracked\/"},{"issue":"5","key":"10_CR68","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1145\/384264.379237","volume":"34","author":"D Lie","year":"2000","unstructured":"Lie, D., Thekkath, C., Mitchell, M., Lincoln, P., Boneh, D., Mitchell, J., Horowitz, M.: Architectural support for copy and tamper resistant software. SIGOPS Oper. Syst. Rev. 34(5), 168\u2013177 (2000)","journal-title":"SIGOPS Oper. Syst. Rev."},{"issue":"8","key":"10_CR69","doi-asserted-by":"publisher","first-page":"761","DOI":"10.1145\/358198.358210","volume":"27","author":"K Thompson","year":"1984","unstructured":"Thompson, K.: Reflections on trusting trust. Commun. ACM 27(8), 761\u2013763 (1984)","journal-title":"Commun. ACM"},{"key":"10_CR70","doi-asserted-by":"crossref","unstructured":"Tram\u00e8r, F., Zhang, F., Lin, H., Hubaux, J.-P., Juels, A., Shi, E.: Sealed-glass proofs: using transparent enclaves to prove and sell knowledge. In: IEEE European Symposium on Security and Privacy (2017)","DOI":"10.1109\/EuroSP.2017.28"},{"key":"10_CR71","unstructured":"Yuanzhong, X., Cui, W., Peinado, M.: Controlled-channel attacks: deterministic side channels for untrusted operating systems. In: IEEE S&P (2015)"},{"key":"10_CR72","doi-asserted-by":"crossref","unstructured":"Zhang, D., Yao Wang, G., Suh, E., Myers, A.C.: A hardware design language for timing-sensitive information-flow security. In: ASPLOS (2015)","DOI":"10.1145\/2694344.2694372"},{"key":"10_CR73","doi-asserted-by":"crossref","unstructured":"Zhang, F., Cecchetti, E., Croman, K., Juels, A., Shi, E.: Town crier: an authenticated data feed for smart contracts. In: ACM CCS (2016)","DOI":"10.1145\/2976749.2978326"},{"issue":"5","key":"10_CR74","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1145\/1037947.1024403","volume":"32","author":"X Zhuang","year":"2004","unstructured":"Zhuang, X., Zhang, T., Pande, S.: Hide: an infrastructure for efficiently protecting information leakage on the address bus. SIGARCH Comput. Archit. News 32(5), 72\u201384 (2004)","journal-title":"SIGARCH Comput. Archit. News"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2017"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-56620-7_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:52:40Z","timestamp":1750189960000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-56620-7_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319566191","9783319566207"],"references-count":74,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-56620-7_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"1 April 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Paris","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 April 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 May 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"36","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt2017.di.ens.fr\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}