Skip to main content

CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs

Publication ,  Conference
Zhou, L; Liu, Z; Zhang, F; Reiter, MK
Published in: Leibniz International Proceedings in Informatics, LIPIcs
September 1, 2024

Cryptocurrency introduces usability challenges by requiring users to manage signing keys. Popular signing key management services (e.g., custodial wallets), however, either introduce a trusted party or burden users with managing signing key shares, posing the same usability challenges. TEE (Trusted Execution Environment) is a promising technology to avoid both, but practical implementations of TEEs suffer from various side-channel attacks that have proven hard to eliminate. This paper explores a new approach to side-channel mitigation through economic incentives for TEE-based cryptocurrency wallet solutions. By taking the cost and profit of side-channel attacks into consideration, we designed a Stick-and-Carrot-based cryptocurrency wallet, CrudiTEE1, that leverages penalties (the stick) and rewards (the carrot) to disincentivize attackers from exfiltrating signing keys in the first place. We model the attacker’s behavior using a Markov Decision Process (MDP) to evaluate the effectiveness of the bounty and enable the service provider to adjust the parameters of the bounty’s reward function accordingly.

Duke Scholars

Published In

Leibniz International Proceedings in Informatics, LIPIcs

DOI

ISSN

1868-8969

Publication Date

September 1, 2024

Volume

316

Related Subject Headings

  • 46 Information and computing sciences
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Zhou, L., Liu, Z., Zhang, F., & Reiter, M. K. (2024). CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs. In Leibniz International Proceedings in Informatics, LIPIcs (Vol. 316). https://doi.org/10.4230/LIPIcs.AFT.2024.16
Zhou, L., Z. Liu, F. Zhang, and M. K. Reiter. “CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs.” In Leibniz International Proceedings in Informatics, LIPIcs, Vol. 316, 2024. https://doi.org/10.4230/LIPIcs.AFT.2024.16.
Zhou L, Liu Z, Zhang F, Reiter MK. CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs. In: Leibniz International Proceedings in Informatics, LIPIcs. 2024.
Zhou, L., et al. “CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs.” Leibniz International Proceedings in Informatics, LIPIcs, vol. 316, 2024. Scopus, doi:10.4230/LIPIcs.AFT.2024.16.
Zhou L, Liu Z, Zhang F, Reiter MK. CrudiTEE: A Stick-And-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs. Leibniz International Proceedings in Informatics, LIPIcs. 2024.

Published In

Leibniz International Proceedings in Informatics, LIPIcs

DOI

ISSN

1868-8969

Publication Date

September 1, 2024

Volume

316

Related Subject Headings

  • 46 Information and computing sciences