Arne Hollum

dblp:301/6375 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2024
0009-0005-0688-3953ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Hardware security and side channels · 100%
Software engineering, system software, and programming languages
1 paper
Runtime systems and virtual machines · 77% Operating systems · 23%

Topics — the 3 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels › trusted execution environments
Intel SGX
0.812024
A Comprehensive Trusted Runtime for WebAssembly With Intel SGX · IEEE Trans. Dependable Secur. Comput. 2024
Hardware security and side channels
trusted execution environments
0.812024
A Comprehensive Trusted Runtime for WebAssembly With Intel SGX · IEEE Trans. Dependable Secur. Comput. 2024
Runtime systems and virtual machines › language runtime
webassembly runtime
0.812024
A Comprehensive Trusted Runtime for WebAssembly With Intel SGX · IEEE Trans. Dependable Secur. Comput. 2024

Methods — techniques the papers use, named apart from their topics

attestation · 1.5
YearPublicationVenuePosition
2024 A Comprehensive Trusted Runtime for WebAssembly With Intel SGX
abstract
In real-world scenarios, trusted execution environments (TEEs) frequently host applications that lack the trust of the infrastructure provider, as well as data owners who have specifically outsourced their data for remote processing. We presentTwine, a trusted runtime for running WebAssembly-compiled applications within TEEs, establishing a two-way sandbox.Twineleverages memory safety guarantees of WebAssembly (Wasm) and abstracts the complexity of TEEs, empowering the execution of legacy and language-agnostic applications. It extends the standard WebAssembly system interface (WASI), providing controlled OS services, focusing on I/O. Additionally, through built-in TEE mechanisms,Twinedelivers attestation capabilities to ensure the integrity of the runtime and the OS services supplied to the application. We evaluate its performance using general-purpose benchmarks and real-world applications, showing it compares on par with state-of-the-art solutions. A case study involving fintech companyCredorareveals thatTwinecan be deployed in production with reasonable performance trade-offs, ranging from a 0.7× slowdown to a 1.17× speedup compared to native run time. Finally, we identify performance improvement through library optimisation, showcasing one such adjustment that leads up to$4.1\times$speedup.Twineis open-source and has been upstreamed into the original Wasm runtime, WAMR.
Jämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio Schiavoni, Giovanni Mazzeo, Arne Hollum, Darshan Vaydia
IEEE Trans. Dependable Secur. Comput.6
2023 Enabling Trusted TEE-as-a-Service Models with Privacy Preserving Automatons
abstract
The ideal TEE service model foresees that data owners load their TEE software in an untrusted platform where the specific processing of the business application can take place inside an enclave, shielded against privileged attackers. In this situation, the data owner needs to trust the TEE hardware vendor only. However, it is very common that the enclave software is offered by a third-party that does not share its source code. Therefore, the service provider must be trusted as well. This is not acceptable when privacy requirements are stringent such as in the fintech ecosystem. In this paper, we propose PRIVATON, an approach based on a dual sandbox strategy leveraging TEE technologies with an embedded WebAssembly sandboxed run-time to compute privacy preserving computations modelled as finite state automatons with verifiable proofs of computations. With PRIVATON, the data owner will have the guarantee that even a malicious TEE developer will not be able to get access to the sensitive data. An implementation of PRIVATON was evaluated in the case study provided by the Credora company who is playing the role of a distributed and privacy-preserving credit oracle in the ecosystem of cryptocurrencies trading.
Bala Subramanyan, Arne Hollum, Giovanni Mazzeo, Matthew Ficke, Darshan Vaydia
CloudCom2
2021 Privacy-Preserving Credit Scoring via Functional Encryption
Lorenzo Andolfo, Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Matthew Ficke, Arne Hollum, Darshan Vaydia
ICCSA (8)7