# TEEvil: Identity Lease via Trusted Execution Environments

**Authors:** Ivan Puddu, Daniele Lain, Moritz Schneider, Elizaveta Tretiakova,, Sinisa Matetic, Srdjan Capkun

arXiv: 1903.00449 · 2019-05-10

## TL;DR

This paper introduces TEEvil, a novel service enabled by Trusted Execution Environments and cryptocurrencies that allows users to lease their online identities securely and anonymously, raising significant security and societal concerns.

## Contribution

It demonstrates the feasibility of implementing identity lease services using Trusted Execution Environments like Intel SGX and cryptocurrencies like ZCash, highlighting new security and ethical challenges.

## Key findings

- Successfully built a prototype called TEEvil using Intel SGX and ZCash.
- Shows how identity lease can be implemented with fairness and anonymity.
- Discusses potential misuse and mitigation strategies for identity lease services.

## Abstract

We investigate identity lease, a new type of service in which users lease their identities to third parties by providing them with full or restricted access to their online accounts or credentials. We discuss how identity lease could be abused to subvert the digital society, facilitating the spread of fake news and subverting electronic voting by enabling the sale of votes. We show that the emergence of Trusted Execution Environments and anonymous cryptocurrencies, for the first time, allows the implementation of such a lease service while guaranteeing fairness, plausible deniability and anonymity, therefore shielding the users and account renters from prosecution. To show that such a service can be practically implemented, we build an example service that we call TEEvil leveraging Intel SGX and ZCash. Finally, we discuss defense mechanisms and challenges in the mitigation of identity lease services.

## Full text

_Full body text omitted from this summary view._ Fetch the complete paper as Markdown: https://tomesphere.com/paper/1903.00449/full.md

## Figures

7 figures with captions in the complete paper: https://tomesphere.com/paper/1903.00449/full.md

## References

95 references — full list in the complete paper: https://tomesphere.com/paper/1903.00449/full.md

---
Source: https://tomesphere.com/paper/1903.00449