A Formal Approach to Multi-Layered Privileges for Enclaves

Ganxiang Yang (Shanghai Jotto University)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Trusted Hardware and Execution

Overview

Ganxiang Yang from Shanghai Jotto University presented groundbreaking research on "A Formal Approach to Multi-Layered Privileges for Enclaves" at the NDSS Symposium. This talk addresses a critical limitation of current Trusted Execution Environments (TEEs), commonly known as enclaves: their inherent lack of usability and flexibility. While enclaves offer robust security guarantees by isolating critical data and computations from untrusted software, this stringent isolation often comes at the cost of common features like inter-enclave memory sharing, debugging capabilities, and seamless integration with cloud or virtual machine (VM) environments. Yang's work introduces a novel framework for multi-layered privilege separation within enclaves, enabling the secure and scalable introduction of new features without compromising the fundamental security properties of TEEs.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to TEEs and Enclave Fundamentals
  2. 1:15 Motivation: Current Enclaves' Usability Restrictions and Limitations
  3. 2:45 Review of Existing Feature Extension Approaches and Drawbacks
  4. 4:50 Proposed Inter-Enclave Privilege Design and Advantages
  5. 7:10 Addressing Key Challenges: Security Definition and Scalability
  6. 8:00 Our Formal Approach to Multi-Layered Enclave Privileges

A Formal Approach to Multi-Layered Privileges for Enclaves

Speakers: Ganxiang Yang, Shanghai Jotto University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=ZiJNdjj2qV4

Overview

Ganxiang Yang from Shanghai Jotto University presented groundbreaking research on "A Formal Approach to Multi-Layered Privileges for Enclaves" at the NDSS Symposium. This talk addresses a critical limitation of current Trusted Execution Environments (TEEs), commonly known as enclaves: their inherent lack of usability and flexibility. While enclaves offer robust security guarantees by isolating critical data and computations from untrusted software, this stringent isolation often comes at the cost of common features like inter-enclave memory sharing, debugging capabilities, and seamless integration with cloud or virtual machine (VM) environments. Yang's work introduces a novel framework for multi-layered privilege separation within enclaves, enabling the secure and scalable introduction of new features without compromising the fundamental security properties of TEEs.

The motivation behind this research stems from the observation that real-world applications in secure machine learning, privacy-preserving services, and cloud computing demand more dynamic and interconnected enclave functionalities. Traditional approaches to extending enclave features often introduce significant Trusted Computing Base (TCB) burdens or rely on insecure software implementations. By proposing a formal approach that not only defines but also formally verifies the security properties of multi-layered privilege separation, Yang and his collaborators offer a robust solution that promises to enhance the practicality and versatility of enclaves, making them more adaptable to complex computational scenarios while maintaining rigorous security assurances. This work is pivotal for advancing the utility of confidential computing, bridging the gap between uncompromising security and essential usability.

Background

▶ Watch: Introduction to TEEs and Enclave Fundamentals (0:00)

Trusted Execution Environments (TEEs), often referred to as enclaves, represent a cornerstone technology for protecting sensitive data and computations from untrusted software, including operating systems (OS) and hypervisors. Manufacturers such as Intel (SGX), AMD (SEV), ARM (TrustZone), and RISC-V have developed various TEE implementations that leverage both spatial isolation (separating memory regions) and execution isolation (using secure CPU modes) to safeguard critical assets. These environments are increasingly deployed in cloud computing for scenarios like secure machine learning and privacy-preserving services, where data integrity and confidentiality are paramount.

Despite their strong security guarantees, current enclave designs face significant usability challenges. These include a lack of inter-enclave memory sharing, difficulties with memory introspection for debugging purposes, and incompatibility with common cloud and VM scenarios. For instance, cold boot problems can lead to significantly longer startup times for enclaves compared to normal processes, and their migration across virtual machines remains a complex issue. The root cause of these limitations lies in the fundamental design principle of enclaves: to ensure security, they must maintain strict isolation from all other software components. Introducing new features typically requires granting some form of privilege, which inherently conflicts with this isolation model.

Previous attempts to extend enclave functionality have generally fallen into three categories:

  1. Intra-enclave Compartmentalization: This approach involves introducing a privilege layer inside the enclave code, where the original code is instrumented to call these privileged layers for services. While offering some feature extensibility, it lacks architecture-level protections and heavily relies on the bug-free software implementation of these extensions, potentially expanding the TCB within the enclave itself.
  2. Privilege Mode Extensions: This involves introducing extensions within the machine's existing privilege modes (e.g., OS kernel, hypervisor) by developing trusted modules or trampolines. While providing architectural backing, integrating multiple or varied feature extensions in this manner leads to a heavy TCB burden. Every new feature adds code to a highly privileged component, violating the principle of least privilege and increasing the attack surface. For example, an enclave needing only inter-enclave memory sharing would be forced to trust code related to memory introspection if both are implemented in the privilege mode.
  3. Inter-enclave Privileges: This design proposes placing services inside enclaves themselves, allowing a "parent" enclave to manage "child" enclaves. This approach offers several advantages:
  • Architecture-based Security: Privilege separation can be integrated into firmware extensions, leveraging hardware-backed security.
  • Minimized TCB: Only necessary extensions are included in the TCB for a given child enclave, excluding unused features.
  • Programmable Extensions: Developers can implement and manage feature extensions in user mode within service enclaves, simplifying development and reducing the risk associated with bugs in privilege mode code.

Prior work, such as nested enclaves and Capstone, explored aspects of inter-enclave privilege separation. However, these solutions typically guaranteed only single-layer privilege separation and, crucially, lacked formal security definitions for how privilege separation should behave. This gap meant there was no rigorous proof that a compromised child enclave would not threaten its parent or other more privileged enclaves.

This lack of formalization and multi-layer scalability presented two significant challenges that Yang's research aimed to address:

  1. Security Definition: Formally defining the security properties of parent-child enclave privilege separation, ensuring that a compromised child enclave does not introduce threats to its parent or more privileged ancestors.
  2. Scalability: Enabling and proving the security of multiple layers of privilege separation, as single-layer solutions are insufficient for complex, real-world use cases.

Key Findings

▶ Watch: Review of Existing Feature Extension Approaches and Drawbacks (2:45)

The core contribution of this research is a formal approach to multi-layered privileges for enclaves, directly tackling the usability limitations and scalability challenges inherent in existing TEE designs. The speaker outlined several key findings and contributions:

  1. Formally Verified Security Properties: The work provides a rigorous, mathematically sound definition of security for multi-layered enclave privilege separation. This includes the definition of a security remote computation property encompassing both integrity and confidentiality, which is then formally verified. This verification ensures that even if a less privileged (child) enclave is compromised, it cannot compromise the security guarantees of its more privileged (parent) enclaves. This addresses the critical challenge of providing a trustworthy security foundation for hierarchical enclave structures.
  1. Abstract Enclave Formal Model: To enable formal verification, the researchers developed an abstract enclave formal model. This model distills the complex behaviors of enclaves and their interactions into a set of seven fundamental instructions, allowing for a precise and verifiable representation of the system's state and transitions. This abstraction is crucial for managing the complexity of formal proofs.
  1. Scalability to Unlimited Layers: A significant breakthrough is the proof of security for an unlimited number of privilege separation layers. Previous work was limited to single-layer separation, which is insufficient for many real-world, complex applications. By demonstrating that the security properties hold regardless of the depth of the privilege hierarchy, this research unlocks the potential for highly modular and feature-rich enclave architectures. This addresses the scalability challenge by providing a robust framework for arbitrarily deep privilege trees.
  1. Practical Implementation and Low Overhead: Despite the complexity of the formal verification, the researchers developed an implementation of their multi-layered privilege extensions. Evaluations indicated a low performance overhead, specifically less than 5% overhead in context switch and CPU-intensive operations. This demonstrates the practical viability of their approach, proving that enhanced security and flexibility do not necessarily come at the cost of prohibitive performance degradation.
  1. Robust Threat Model: The work operates under a standard, yet robust, threat model that assumes a malicious OS and excludes side-channel attacks and denial-of-service (DoS) attacks from its scope. The primary concern is the security of a privileged enclave when any of its less privileged ancestor enclaves are compromised, ensuring a strong focus on the integrity and confidentiality within the privilege hierarchy.

These findings collectively represent a significant step forward in confidential computing, offering a blueprint for designing more flexible, secure, and scalable TEEs that can meet the evolving demands of modern cloud and enterprise applications.

Technical Deep Dive

▶ Watch: Proposed Inter-Enclave Privilege Design and Advantages (4:50)

The technical core of Yang's work revolves around formalizing and implementing multi-layered privilege separation for enclaves. The proposed architecture establishes a hierarchical relationship, akin to a parent-child enclave tree, where more privileged enclaves can manage and control less privileged ones. This contrasts sharply with flat enclave models or those relying solely on OS-level privilege separation.

To formally define this system, the researchers first characterized the privilege separation instructions that a parent enclave can execute on its child enclaves. These instructions grant specific control capabilities without exposing the parent to the child's potential vulnerabilities. Key operations include:

  • Launch/Create: A privileged enclave can initiate the creation of a new, less privileged enclave.
  • Enter Execution Tree: It can manage the execution context of its children.
  • Execute: It can trigger the execution of code within a child enclave.
  • Destroy: It has the authority to terminate a child enclave.
  • Inspect Memory Contents: Crucially, a privileged enclave can inspect the memory contents of its less privileged children. This capability is vital for debugging, monitoring, and enabling features like secure inter-enclave memory sharing, while being carefully controlled to prevent unauthorized access.

This hierarchical structure can be visualized as a tree: the underlying Operating System serves as the most privileged software, capable of hosting several most privileged enclaves. These enclaves, in turn, can launch and manage their own less privileged enclaves, forming branches and further layers within the tree. This design enables fine-grained control and compartmentalization of features.

The formalization relies on an abstract enclave formal model, which extracts seven core instructions representing all possible interactions and state transitions within the multi-layered enclave system. This abstraction allows for a mathematically tractable analysis. The central security property defined is the security remote computation property, which encompasses both integrity and confidentiality.

  • Integrity: Ensures that for any adversary, the contents or secret data within an enclave, once created, cannot be modified without authorization.
  • Confidentiality: Guarantees that sensitive data within an enclave remains protected from unauthorized disclosure.

These properties are expressed using first-order logic, providing a precise and unambiguous specification of the desired security guarantees.

The verification process leverages the Z3 prover, a powerful satisfiability modulo theories (SMT) solver, combined with induction proofs. The verification process constructs a proof tree, where the top-level goal is the SI property (Security Remote Computation Property). The bottom layer consists of the basic features provided by the multi-layer privilege extensions, and intermediate lemmas are introduced to bridge the gap and prove the overall security property. This inductive approach is crucial for proving properties across an arbitrary number of layers.

A significant technical challenge addressed was the scalability of formal verification for multi-layered privileges. Introducing new execution flows from a privileged enclave to a non-privileged one drastically increases the verification state space. The speaker noted that if a normal OS can host n processes, the verification complexity for traditional, flat privilege models might be polynomial. However, with the introduction of hierarchical privilege separation, the verification state can explode to a double exponential function of n.

To overcome this computational barrier, without entirely circumventing the inherent complexity, the researchers employed several optimization and induction tricks:

  1. Skolemization: Security properties were redefined using skolemization, which involves replacing existential quantifiers with Skolem functions to unify all security layer properties under a universal quantifier. This simplification helps in managing the complexity of the logical expressions.
  2. Relevant Post Propagation: The Z3 solver was optimized to use relevant post propagation property. This technique allows the solver to focus only on parameters that are relevant or have been modified during specific deductive proof procedures, significantly pruning the search space and speeding up verification.
  3. Induction Proofs: To handle the arbitrary number of layers, induction proofs were extensively used to parameterize all privilege separations. This mathematical technique allows proving a property for an arbitrary n layers by proving it for the base case (e.g., one layer) and then showing that if it holds for k layers, it also holds for k+1 layers. This is essential for guaranteeing scalability without re-verifying each additional layer.

These sophisticated formal methods and optimization strategies were critical in making the multi-layered privilege model formally verifiable and scalable, addressing a long-standing challenge in TEE security.

Demo / Proof of Concept

▶ Watch: Addressing Key Challenges: Security Definition and Scalability (7:10)

While the talk did not feature a live demonstration of the multi-layered enclave system in action, the speaker discussed the implementation and evaluation of their proposed approach. The research team implemented the multi-layered privilege extensions and conducted performance measurements and formal verification timing analysis.

A key aspect of the evaluation was the performance overhead. The results indicated that the introduction of their multi-layered privilege mechanism incurred less than 5% overhead in both context switch operations and CPU-intensive overheads. This low overhead is crucial for practical adoption, demonstrating that the enhanced security and flexibility provided by multi-layered privileges do not come at a prohibitive performance cost for typical enclave workloads.

The formal verification process itself was a significant undertaking. The speaker noted that the verification time for their comprehensive model took approximately 12 hours. This contrasts sharply with previous benchmarks that might complete in around five minutes, underscoring the significantly increased complexity of formally verifying a multi-layered privilege model compared to simpler, single-layer or less comprehensive models. This extended verification time, however, is a testament to the depth and rigor of their formal approach, necessary to provide strong security guarantees for an unlimited number of privilege layers.

Furthermore, the implementation was evaluated using hierarchical determinics and enclaves to demonstrate its capability in introducing multiple feature extensions together within their privileged enclave framework. This evaluation scenario showcased how the parent-child enclave structure could effectively host and manage various functionalities in a secure, compartmentalized manner, proving the practical utility of their design for complex confidential computing applications. The speaker also mentioned the availability of an artifact, implying that the implementation and evaluation setup are available for further inspection and reproducibility.

Defensive Implications

▶ Watch: Our Formal Approach to Multi-Layered Enclave Privileges (8:00)

The formal approach to multi-layered privileges for enclaves presented by Ganxiang Yang has profound implications for defenders operating in the confidential computing landscape. This research provides a robust framework that enables more flexible and secure TEE deployments, addressing long-standing usability issues without sacrificing core security guarantees.

Firstly, this work empowers cloud providers and enterprise security teams to deploy more sophisticated and feature-rich enclave-based services. By allowing the secure integration of features like inter-enclave memory sharing, debugging, and advanced resource management through a hierarchical privilege model, defenders can leverage TEEs for a broader range of applications, including secure machine learning, privacy-preserving analytics, and confidential data processing, with greater confidence. The ability to minimize the TCB for specific features by isolating them in less privileged enclaves directly aligns with the principle of least privilege, significantly reducing the attack surface.

Secondly, the formal verification of security properties offers an unprecedented level of assurance. For critical applications where even a minor vulnerability could have catastrophic consequences, having mathematically proven guarantees that a compromised child enclave cannot affect its parent is invaluable. This reduces reliance on mere informal reasoning or extensive penetration testing, providing a foundational layer of trust that is paramount in high-stakes environments. Defenders can point to this formal verification as a strong argument for the security posture of their enclave deployments.

Thirdly, the programmable nature of extensions within user-mode service enclaves simplifies the development and deployment of new security features or custom enclaves. This means that security teams can more easily introduce tailored defensive mechanisms or integrate third-party security tools into their enclave environments without needing to modify the underlying privileged monitor or OS code. This agility can accelerate the adoption of new security best practices and enable quicker responses to emerging threats.

Finally, the multi-layered architecture inherently supports better compartmentalization and isolation of vulnerabilities. If a specific feature extension within a less privileged enclave is found to have a bug, the formal guarantees ensure that this vulnerability's impact is contained within that specific layer, preventing it from escalating to compromise more critical, higher-privileged enclaves. This containment strategy is a significant advantage for incident response and risk management, allowing defenders to isolate and remediate issues with a reduced blast radius. The capability for privileged enclaves to securely inspect the memory of child enclaves could also be adapted for secure debugging or forensic analysis within the TEE, aiding in post-incident investigation without compromising the confidentiality of the enclave itself.

In essence, this research provides defenders with a powerful tool to build more resilient, adaptable, and formally secure confidential computing infrastructures, bridging the gap between stringent security requirements and the practical demands of modern IT environments.

Key Takeaways

  • Addressing TEE Usability: Current Trusted Execution Environments (TEEs) suffer from usability limitations (e.g., inter-enclave memory sharing, debugging, VM migration) due to their strict isolation, hindering their adoption in complex cloud and privacy-preserving scenarios.
  • Multi-Layered Privilege Separation: The proposed solution introduces a novel concept of multi-layered privilege separation, allowing "parent" enclaves to securely manage and provide services to "child" enclaves, enabling flexible feature extensions without compromising security.
  • Formal Security Guarantees: The research provides a formal definition of the "security remote computation property" (integrity and confidentiality) for hierarchical enclaves, rigorously verified using an abstract enclave formal model, first-order logic, the Z3 prover, and induction proofs.
  • Scalability to Unlimited Layers: A key breakthrough is the proof of security for an unlimited number of privilege layers, overcoming the limitations of previous single-layer solutions and enabling complex, arbitrarily deep privilege hierarchies for real-world applications.
  • Low Performance Overhead: Despite the complexity of the formal verification, the implementation demonstrates low performance overheads, specifically less than 5% for context switches and CPU-intensive operations, making the approach practically viable.
  • Enhanced Confidential Computing: This work paves the way for more practical, feature-rich, and provably secure confidential computing, allowing developers and cloud providers to build more versatile and trustworthy applications in sensitive domains like secure machine learning and privacy protection.

About the Speaker(s)

Ganxiang Yang is a researcher from Shanghai Jotto University, where he presented his work on "A Formal Approach to Multi-Layered Privileges for Enclaves." His research focuses on enhancing the security and usability of Trusted Execution Environments (TEEs) through formal methods and novel architectural designs. He collaborated on this work with Junang, Professor Hungu, and Professor Fang, contributing to the advancement of confidential computing by addressing critical challenges related to privilege separation and scalability in enclave environments.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid formal-methods contribution to TEE security that earns its place at NDSS — hierarchical enclave privilege separation with Z3-verified security properties and sub-5% runtime overhead is the kind of unglamorous-but-necessary foundational work the field needs. Not a flashy exploit drop, but a rigorous answer to a real architectural gap that practitioners building confidential computing stacks will care about.

Heather Calloway (CISO) — WEAK

Technically credible formal verification work on TEE privilege separation, but it never surfaces as a governance, operational, or procurement question. The defensive implications section is written, not derived — it tells defenders what this could mean without telling them what to actually do with it.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025