Enforcing Attestable Workflows across Untrusted Networks
Hung Dang, Tue Nguyen

TL;DR
The paper introduces extbackslash codename, a hardware-backed architecture for confidential, high-performance workflows across untrusted networks, achieving low latency and minimal overhead.
Contribution
It presents a split TCB design combining hardware-isolated control and kernel-enforced data plane for efficient, attested, encrypted routing in federated environments.
Findings
Achieves 6 microseconds per packet enforcement cost.
Imposes only 6.1% execution penalty over plaintext.
Initializes a 100-node cluster in under 1.5 seconds.
Abstract
Confidential high-performance computing orchestrates workloads across federated domains, yet existing frameworks rely on high-overhead user-space library operating systems or assume single-host execution. We propose \codename, an architecture federating Trusted Execution Environments via a split Trusted Computing Base (TCB) design. It couples a hardware-isolated Control Plane executing Mutually Attested Key Exchange (\make) with a measured guest-resident extended Berkeley Packet Filter (eBPF) Data Plane. By anchoring cryptographic key release to hardware measurements and executing enforcement in the kernel, \codename\ achieves native-speed encrypted routing. Empirical evaluation demonstrates a steady-state enforcement cost of s per packet, imposing a --s absolute latency overhead. On distributed pipelines, \codename\ incurs just a execution penalty over…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
