Skip to content
Conference Open access

Slice & Dice: Privacy-Preserving Layered Attestation via Active Memory Introspection

2026 · International Conference on Security and Cryptography · pp. 155-168 · 0 citations · 34 references
Computer Science

TL;DR

Slice and Dice proposes a layered attestation architecture for 3-layer systems, in which a minimal and highly privileged programmable firmware layer continuously performs dynamic memory introspection on the untrusted Payload Manager layer (Layer 1).

Abstract

: The rapid adoption of dynamic Payload Managers enables portable, platform-agnostic execution across the cloud/edge continuum. However, these complex execution layers, even when embedded within a Trusted Ex-ecution Environment (TEE), significantly expand the attack surface of the Trusted Computing Base (TCB). Existing layered attestation schemes typically combat this using static, load-time measurements of payloads. Yet, recent vulnerabilities demonstrate that static checks are insufficient to prevent attackers from gaining privileged execution rights while avoiding detection. Slice and Dice proposes a layered attestation architecture for 3-layer systems, in which a minimal and highly privileged programmable firmware layer (Layer 0) continuously performs dynamic memory introspection on the untrusted Payload Manager layer (Layer 1). By inspecting ELF segments during execution, the firmware can detect code modifications in real-time. To complete the cycle of Remote Attestation (RA) and provide evidence to an external verifier in a privacy-preserving manner, we couple the introspection mechanism with Zero-Knowledge Proofs (ZKP) utilizing BBS anonymous credentials.

Read PDF

Similar papers

DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes

This work presents DDRop, a new primitive that exploits the absence of cryptographic freshness to break the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP and demonstrates end-to-end attacks on an up-to-date TDX platform.

ETHZurich, Zúrich, Switzerland et al. · 0 citations
Preprint Sep 2026

TPM-Attest: Hardware-Rooted Integrity Attestation as a Kernel-Level Anti-Cheat Alternative for Linux

TPM-Attest is presented, a hardware-rooted remote attestation framework that uses the Trusted Platform Module (TPM) 2.0 and the Linux Integrity Measurement Architecture (IMA) to prove, cryptographically, that a client booted cleanly and ran only authorised software -- without any kernel driver, without proprietary code...

Anudeep Gedela, A. Technology, Gitam University et al. · 0 citations
Preprint Sep 2026

Type-Directed, Secure-by-Construction Enclave Partitioning for LLVM

Trusted Execution Environments (TEEs) provide hardware-supported isolation through enclaves that protect code and data independently of software abstractions. However, TEEs alone cannot enforce information-flow security. This problem is further aggravated in LLVM-like low-level languages that allow unrestricted pointer...

Wesley B. Nuzzo, Samuel Dodson, Benjamin Houle et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Beyond Static Guarantees: Measuring the Static-Pass Dynamic-Fail Gap in Security-Sensitive and LLM-Generated Python Code

The Static-Pass Dynamic-Fail (SPDF) phenomenon and a three-stage agentic pipeline combining static scanning, LLM-driven Common Weakness Enumeration (CWE) reasoning, and autonomous exploit verification in isolated Docker containers are introduced.

Jessica Pourleyli, Maitreyee Das Urmi, Glaucia Melo · 0 citations
Review Open access Sep 2026

Redefining Trust at the Memory Wall: The Threat Landscape, an Adversary Model and a Conceptual Framework for Secure Processing-in-Memory

Processing-in-Memory (PIM) architectures are transforming system hierarchies by embedding computation within memory and collapsing traditional CPU–memory separation. This co-location enables measured gains in throughput and energy efficiency for data-intensive workloads such as AI inference and graph analytics, but exe...

Sayali Waingankar, Hung T. Q. Le, D. Benhaddou · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.