{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T20:11:57Z","timestamp":1783973517308,"version":"3.55.0"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1109\/tc.2026.3690648","type":"journal-article","created":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T19:35:08Z","timestamp":1777923308000},"page":"2857-2869","source":"Crossref","is-referenced-by-count":0,"title":["Keystone-Vault: Hardware-Assisted Efficient Intra-Enclave Isolation for RISC-V TEEs"],"prefix":"10.1109","volume":"75","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-9624-1265","authenticated-orcid":false,"given":"Tianming","family":"Yan","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, and Hangzhou High-Tech Zone (Binjiang) Institute of Blockchain and Data Security, and School of Cyber Science and Technology, Zhejiang University, and College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-5172-9129","authenticated-orcid":false,"given":"Kun","family":"Yang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, and Hangzhou High-Tech Zone (Binjiang) Institute of Blockchain and Data Security, and School of Cyber Science and Technology, Zhejiang University, and College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-1248-4078","authenticated-orcid":false,"given":"Hongliang","family":"Tian","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9580-5395","authenticated-orcid":false,"given":"Shoumeng","family":"Yan","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, and Hangzhou High-Tech Zone (Binjiang) Institute of Blockchain and Data Security, and School of Cyber Science and Technology, Zhejiang University, and College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intel\u00ae software guard extensions (SGX) overview","year":"2022"},{"key":"ref2","article-title":"AMD memory encryption","year":"2016"},{"key":"ref3","article-title":"Arm confidential compute architecture: Confidential computing for the arm architecture","year":"2021"},{"key":"ref4","article-title":"Intel trust domain extensions","year":"2021"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-77566-9_9"},{"key":"ref7","article-title":"Building a secure system using TrustZone technology","year":"2009"},{"key":"ref8","article-title":"Intel SGX explained","author":"Costan","year":"2016","journal-title":"Cryptology ePrint Archive"},{"key":"ref9","first-page":"2261","article-title":"ReZone: Disarming TrustZone with TEE privilege reduction","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security),","author":"Cerdeira","year":"2022"},{"key":"ref10","article-title":"Downgrade attack on TrustZone","author":"Chen","year":"2017"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2018.8486293"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1080\/01611190802231140"},{"key":"ref13","article-title":"Qualcomm trusted application emulation for fuzzing testing","author":"Fan","year":"2025"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2020.23014"},{"key":"ref15","article-title":"KINIBI TEE: Trusted application exploitation","author":"Berard"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-90307-1_35-1"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3605770.3625212"},{"key":"ref18","first-page":"1677","article-title":"Donky: Domain keys\u2013efficient in-process isolation for RISC-V and x86","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Security),","author":"Schrammel","year":"2020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA45697.2020.00069"},{"key":"ref20","first-page":"3129","article-title":"A hardware-software co-design for efficient intra-enclave isolation","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security),","author":"Gu","year":"2022"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.241301"},{"key":"ref22","first-page":"857","article-title":"Sanctum: Minimal hardware extensions for strong software isolation","volume-title":"Proc. 25th USENIX Secur. Symp. (USENIX Security","author":"Costan","year":"2016"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23068"},{"key":"ref24","first-page":"1073","article-title":"CURE: A security architecture with customizable and resilient enclaves","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Security),","author":"Bahmani","year":"2021"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88428-4_19"},{"key":"ref26","first-page":"275","article-title":"Scalable memory protection in the PENGLAI enclave","volume-title":"Proc. 15th USENIX Symp. Oper. Syst. Des. Implementation (OSDI)","author":"Feng","year":"2021"},{"key":"ref27","first-page":"1149","article-title":"Privilege separating security monitor on RISC-V TEEs","volume-title":"Proc. 32nd USENIX Secur. Symp. (USENIX Security)","author":"Kuhne","year":"2025"},{"key":"ref28","article-title":"Enhanced physical memory protection (ePMP) for RISC-V","year":"2022"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3453933.3454024"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240385"},{"key":"ref31","first-page":"1041","article-title":"Telling your secrets without page faults: Stealthy page table-based attacks on enclaved execution","volume-title":"Proc. 26th USENIX Secur. Symp. (USENIX Security),","author":"Van Bulck","year":"2017"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152706"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23193"},{"key":"ref34","article-title":"Keystone: An open-source secure enclave framework for RISC-V processors","author":"Project"},{"key":"ref35","article-title":"NNoM: A higher-level neural network library for microcontrollers","author":"Ma"},{"key":"ref36","article-title":"Mbed TLS: An open source, portable, easy to use, readable and flexible TLS library, and reference implementation of the PSA cryptography API"},{"key":"ref37","article-title":"mIT License. Stars: 11.9k; Forks: 3.4k","author":"Gamble"},{"key":"ref38","article-title":"SQLite: Official git mirror of the SQLite source tree"},{"key":"ref39","article-title":"Mongoose: Embedded web server, with TCP\/IP network stack, MQTT and WebSocket","author":"Software"},{"key":"ref40","first-page":"645","article-title":"Graphene-SGX: A practical library OS for unmodified applications on SGX","volume-title":"Proc. USENIX Annu. Tech. Conf. (USENIX ATC),","author":"Tsai","year":"2017"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378469"},{"key":"ref42","article-title":"Intel SGX SDK for Linux"},{"key":"ref43","article-title":"Intel 64 and IA-32 architectures software developer\u2019s manual, volume 3: System programming guide"},{"key":"ref44","article-title":"SEV-SNP: Strengthening VM isolation with integrity protection and more"}],"container-title":["IEEE Transactions on Computers"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/12\/11603879\/11506026.pdf?arnumber=11506026","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T20:03:40Z","timestamp":1783973020000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11506026\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":44,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tc.2026.3690648","relation":{},"ISSN":["0018-9340","1557-9956","2326-3814"],"issn-type":[{"value":"0018-9340","type":"print"},{"value":"1557-9956","type":"electronic"},{"value":"2326-3814","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,8]]}}}