Security Lunch: Wednesday, September 16th, 2026, 12:00PM @ CoDa E160
Title: Pirateship: Append-Only Ledgers for (Mostly) Trusted Execution Environments
Speaker: Shubham Mishra
Abstract:
Distributed ledgers are increasingly relied upon by industry to provide trustworthy accountability, strong integrity protection, and high availability for critical data without centralizing
trust. Recently, distributed append-only logs are opting for a layered approach, combining crash-fault-tolerant (CFT) consensus with hardware-based Trusted Execution Environments (TEEs) for greater resiliency. Unfortunately, hardware TEEs can be subject to
(rare) attacks, undermining the very guarantees that distributed ledgers are carefully designed to achieve. In response, we present Pirateship, a new distributed consensus protocol that cautiously trusts the guarantees of TEEs. Pirateship carefully embeds
a Byzantine fault-tolerant (BFT) protocol inside of a CFT protocol with no additional messages. This is made possible through careful refactoring of both the CFT and BFT protocols such that their structure aligns. Pirateship achieves performance in line with
regular TEE-enabled consensus protocols, while guaranteeing integrity in the face of TEE platform compromises.
Bio:
I am a (soon-to-be-5th-year) Ph.D. student at UC Berkeley working with Prof. Natacha Crooks and Prof. John D. Kubiatowicz. My research interests are in Distributed Systems and Security.
Before this, I graduated from IIT Kharagpur in 2022. I have been working in the intersection of Byzantine Fault Tolerance and Trusted Execution Environments (TEEs), trying to understand how to deal with rare but very possible compromises on TEEs.