# Running Geth within SGX: Our Experience, Learnings and Code | Flashbots

**URL:** https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938
**Category:** Research
**Tags:** privacy, writings, trusted-execution
**Created:** [December 20, 2022, 12:58pm UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938 "2022-12-20T12:58:38Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![metachris](https://collective.flashbots.net/user_avatar/collective.flashbots.net/metachris/32/6_2.png) [@metachris](https://collective.flashbots.net/u/metachris)
#### Post date: [December 20, 2022, 12:58pm UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/1 "2022-12-20T12:58:39Z")

</div>

At Flashbots, we are exploring trusted execution environments (TEEs) such as SGX, as well as other privacy technologies such as Multi-Party Computation and Homomorphic Encryption, as important building blocks for trustless collaboration along the transaction supply chain. This is particularly relevant for applications such as decentralized block building and sharing private orderflow.

In collaboration with [konVera](https://konvera.io/), a software development company with strong expertise in confidential computing, we have achieved a fully working prototype of Geth running inside SGX and syncing with Ethereum mainnet.

> **[Running Geth within SGX: Our Experience, Learnings and Code | Flashbots Writings](https://writings.flashbots.net/geth-inside-sgx)**
>
> We are happy to publish our efforts and a number of key learnings about running Geth inside SGX, for others to reuse, experiment with, and build upon.

You can find the code at [GitHub - flashbots/geth-sgx-gramine: Geth-in-SGX provides an example of running go-ethereum in SGX](https://github.com/flashbots/geth-sgx-gramine).

We hope this is useful to others, and want to invite open research and collaboration! ⭐

---

<div class="post-metadata">

### Author: ![socrates1024](https://collective.flashbots.net/user_avatar/collective.flashbots.net/socrates1024/32/1622_2.png) [@socrates1024](https://collective.flashbots.net/u/socrates1024)
#### Post date: [December 22, 2022, 8:29pm UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/2 "2022-12-22T20:29:58Z")

</div>

Could you say more about the IO leakage you explored? Did you quantify it or demo it on some transactions/applications?

I’m amazed it was possible to run Geth as a whole i side Gramine… that’s a generic approach that swaps out all the system calls.

If the goal is just to assemble blocks without being able to peek at the transactions, why not carve out a much smaller portion of Geth?

Also I’m curious if you looked at the Oasis Sapphire EVM ported to SGX. [oasis-sdk/runtime-sdk/modules/evm at main · oasisprotocol/oasis-sdk · GitHub](https://github.com/oasisprotocol/oasis-sdk/tree/main/runtime-sdk/modules/evm)

---

<div class="post-metadata">

### Author: ![roshan](https://collective.flashbots.net/letter_avatar_proxy/v4/letter/r/58f4c7/32.png) [@roshan](https://collective.flashbots.net/u/roshan)
#### Post date: [December 23, 2022, 5:28am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/3 "2022-12-23T05:28:15Z")

</div>

Agree with the broader point that a subset of geth tailored for a given purpose would be simpler to run inside TEEs. For instance, we run a flashbots relay for Polygon and are exploring stateless clients and witnesses to simulate bundles inside TEEs without having to sync and store a ton of state. The same could work for block builders who simply assemble bundles and transactions into blocks.

The place where full nodes would most likely be necessary is to generate bundles and witnesses in the first place. However, even here, I suspect “state-lite” clients that store only a subset of state that is relevant would be feasible.

---

<div class="post-metadata">

### Author: ![roshan](https://collective.flashbots.net/letter_avatar_proxy/v4/letter/r/58f4c7/32.png) [@roshan](https://collective.flashbots.net/u/roshan)
#### Post date: [December 23, 2022, 5:38am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/4 "2022-12-23T05:38:10Z")

</div>

I’m also very curious about feasibility of eclipse attacks on the node. Seems like a hardened discovery mechanism would be needed that is a lot more fail-closed than the current mechanism.

---

<div class="post-metadata">

### Author: ![metachris](https://collective.flashbots.net/user_avatar/collective.flashbots.net/metachris/32/6_2.png) [@metachris](https://collective.flashbots.net/u/metachris)
#### Post date: [December 23, 2022, 10:52am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/5 "2022-12-23T10:52:08Z")

</div>

We are exploring a range of privacy technologies, and running geth inside SGX is just one of these explorations. Indeed another one is running only EVM inside geth, as well as using MPC and combinations of SGX and MPC.

> [@socrates1024](#):
>
> Also I’m curious if you looked at the Oasis Sapphire EVM ported to SGX. [oasis-sdk/runtime-sdk/modules/evm at main · oasisprotocol/oasis-sdk · GitHub](https://github.com/oasisprotocol/oasis-sdk/tree/main/runtime-sdk/modules/evm)

Fowarded internally, will report back with details.

---

<div class="post-metadata">

### Author: ![metachris](https://collective.flashbots.net/user_avatar/collective.flashbots.net/metachris/32/6_2.png) [@metachris](https://collective.flashbots.net/u/metachris)
#### Post date: [December 23, 2022, 11:04am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/6 "2022-12-23T11:04:47Z")

</div>

> [@socrates1024](#):
>
> Could you say more about the IO leakage you explored? Did you quantify it or demo it on some transactions/applications?

@ra and Frieder could say a bit more about the IO leakage details.

Related to this are covert-channel attacks, which potentially allow attackers to extract confidential information by observing resource usage on the host machine. In particular if user supplied inputs to the program running in the enclave can help leak information, for instance through CPU usage or memory access patterns.

More broadly speaking, our general understanding is that if an attacker has hardware access to the server running the SGX enclaves, it’s only a matter of time until private data is extracted through one of multiple ways (vulnerabilities, side-channel attack, covert-channel attacks, programming errors, etc). If run in such a setup, it’s important to prepare for the eventual breach. There are some ways to mitigate, including include rotating keys, TCB recovery plans, compartmentalization, smart software upgrade processes, etc.

---

<div class="post-metadata">

### Author: ![Nota](https://collective.flashbots.net/user_avatar/collective.flashbots.net/nota/32/1079_2.png) [@Nota](https://collective.flashbots.net/u/Nota)
#### Post date: [February 27, 2023, 8:24am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/7 "2023-02-27T08:24:28Z")

</div>

Awesome! The idea of running Geth in SGX is impressive. I am especially interested in how to verify attestations on-chain. Is there some progress or reference material on this topic?

---

<div class="post-metadata">

### Author: ![dogan](https://collective.flashbots.net/letter_avatar_proxy/v4/letter/d/47e85d/32.png) [@dogan](https://collective.flashbots.net/u/dogan)
#### Post date: [January 12, 2024, 8:24am UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/8 "2024-01-12T08:24:13Z")

</div>

I’m also super curious about this, are there anything I can read?

---

<div class="post-metadata">

### Author: ![odysseus](https://collective.flashbots.net/letter_avatar_proxy/v4/letter/o/cdc98d/32.png) [@odysseus](https://collective.flashbots.net/u/odysseus)
#### Post date: [January 28, 2024, 11:27pm UTC](https://collective.flashbots.net/t/running-geth-within-sgx-our-experience-learnings-and-code-flashbots/938/9 "2024-01-28T23:27:29Z")

</div>

> [@Demystifying remote attestation by taking it on-chain](https://collective.flashbots.net/t/demystifying-remote-attestation-by-taking-it-on-chain/2629):
>
> Remote attestation is a fundamental concept when designing secure protocols using TEEs. One of the best ways to make it clear how this works is with an on-chain demo. This demo is mainly possible through recent projects like Puffer Finance [“RAVE”](https://github.com/PufferFinance/rave/), which are Solidity smart contract implementations of verifiers for SGX remote attestation. We’ll walk through an end to end example, starting from the verifier and working backward. To follow along with the post: [Live instance of the smart contrac…
