Publications Partially Reconfigurable Platforms
Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing
1st GENZERO Workshop, 2026, Singapore
Abstract
How can one tamper with data that does not exist? Motivated by this question, we present the Burning Fetch eXecution (BFX) paradigm. Data in-use is vulnerable, and the current focus on encrypting and/or isolating in-use data has fallen short. Frequently reported breaches of “secure” hardware and indispensable overhead with encryption schemes confirm that trust is the modern bottleneck. This work tackles the gap in existing safeguarding technology by avoiding byte-level decryption until it is immediately fetched by the processor, only to burn it right after. We perform on-the-fetch data decryption, immediately followed by burning, i.e., erasing right after processing cycles. Thus, BFX minimizes the existence of sensitive data in-use. BFX does not demand new processing hardware units nor requires restructuring application software. Three pillars set the BFX paradigm apart: (1) zero-trust multi-party confidentiality with (2) security rooted in transparency, and (3) high performance.
Cite this paper
@inproceedings{BFX_GenZero26,
title = {{Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing}},
author = {Roozkhosh, Shahin and El Mabsout, Bassel and Rodrigues, Cristiano and Carpanedo, Patrick and Hoornaert, Denis and Tan, Su Min and Lubin, Benjamin and Caccamo, Marco and Pinto, Sandro and Mancuso, Renato},
booktitle = {1st GENZERO Workshop},
year = 2026,
pages = {196--205},
publisher = {Springer Nature Singapore},
address = {Singapore},
url = {https://cs-people.bu.edu/rmancuso/files/papers/BFX_GenZero26.pdf}
}
TY - CONF AU - Roozkhosh, Shahin AU - El Mabsout, Bassel AU - Rodrigues, Cristiano AU - Carpanedo, Patrick AU - Hoornaert, Denis AU - Tan, Su Min AU - Lubin, Benjamin AU - Caccamo, Marco AU - Pinto, Sandro AU - Mancuso, Renato TI - Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing T2 - 1st GENZERO Workshop PY - 2026 PB - Springer Nature Singapore CY - Singapore SP - 196 EP - 205 AB - How can one tamper with data that does not exist? Motivated by this question, we present the Burning Fetch eXecution (BFX) paradigm. Data in-use is vulnerable, and the current focus on encrypting and/or isolating in-use data has fallen short. Frequently reported breaches of “secure” hardware and indispensable overhead with encryption schemes confirm that trust is the modern bottleneck. This work tackles the gap in existing safeguarding technology by avoiding byte-level decryption until it is immediately fetched by the processor, only to burn it right after. We perform on-the-fetch data decryption, immediately followed by burning, i.e., erasing right after processing cycles. Thus, BFX minimizes the existence of sensitive data in-use. BFX does not demand new processing hardware units nor requires restructuring application software. Three pillars set the BFX paradigm apart: (1) zero-trust multi-party confidentiality with (2) security rooted in transparency, and (3) high performance. ER -
%0 Conference Paper %A Roozkhosh, Shahin %A El Mabsout, Bassel %A Rodrigues, Cristiano %A Carpanedo, Patrick %A Hoornaert, Denis %A Tan, Su Min %A Lubin, Benjamin %A Caccamo, Marco %A Pinto, Sandro %A Mancuso, Renato %T Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing %B 1st GENZERO Workshop %D 2026 %P 196-205 %I Springer Nature Singapore %C Singapore %X How can one tamper with data that does not exist? Motivated by this question, we present the Burning Fetch eXecution (BFX) paradigm. Data in-use is vulnerable, and the current focus on encrypting and/or isolating in-use data has fallen short. Frequently reported breaches of “secure” hardware and indispensable overhead with encryption schemes confirm that trust is the modern bottleneck. This work tackles the gap in existing safeguarding technology by avoiding byte-level decryption until it is immediately fetched by the processor, only to burn it right after. We perform on-the-fetch data decryption, immediately followed by burning, i.e., erasing right after processing cycles. Thus, BFX minimizes the existence of sensitive data in-use. BFX does not demand new processing hardware units nor requires restructuring application software. Three pillars set the BFX paradigm apart: (1) zero-trust multi-party confidentiality with (2) security rooted in transparency, and (3) high performance.
[
{
"id": "BFX_GenZero26",
"type": "paper-conference",
"title": "Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing",
"author": [
{
"family": "Roozkhosh",
"given": "Shahin"
},
{
"family": "El Mabsout",
"given": "Bassel"
},
{
"family": "Rodrigues",
"given": "Cristiano"
},
{
"family": "Carpanedo",
"given": "Patrick"
},
{
"family": "Hoornaert",
"given": "Denis"
},
{
"family": "Tan",
"given": "Su Min"
},
{
"family": "Lubin",
"given": "Benjamin"
},
{
"family": "Caccamo",
"given": "Marco"
},
{
"family": "Pinto",
"given": "Sandro"
},
{
"family": "Mancuso",
"given": "Renato"
}
],
"container-title": "1st GENZERO Workshop",
"issued": {
"date-parts": [
[
2026
]
]
},
"page": "196-205",
"publisher": "Springer Nature Singapore",
"publisher-place": "Singapore",
"abstract": "How can one tamper with data that does not exist? Motivated by this question, we present the Burning Fetch eXecution (BFX) paradigm. Data in-use is vulnerable, and the current focus on encrypting and/or isolating in-use data has fallen short. Frequently reported breaches of “secure” hardware and indispensable overhead with encryption schemes confirm that trust is the modern bottleneck. This work tackles the gap in existing safeguarding technology by avoiding byte-level decryption until it is immediately fetched by the processor, only to burn it right after. We perform on-the-fetch data decryption, immediately followed by burning, i.e., erasing right after processing cycles. Thus, BFX minimizes the existence of sensitive data in-use. BFX does not demand new processing hardware units nor requires restructuring application software. Three pillars set the BFX paradigm apart: (1) zero-trust multi-party confidentiality with (2) security rooted in transparency, and (3) high performance."
}
]
S. Roozkhosh, B. El Mabsout, C. Rodrigues, P. Carpanedo, D. Hoornaert, S. M. Tan, B. Lubin, M. Caccamo, S. Pinto, and R. Mancuso, “Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing,” in 1st GENZERO Workshop, pp. 196–205, 2026.
Roozkhosh, S., El Mabsout, B., Rodrigues, C., Carpanedo, P., Hoornaert, D., Tan, S. M., Lubin, B., Caccamo, M., Pinto, S., & Mancuso, R. (2026). Burning Fetch Execution: A Framework for Zero-Trust Multi-party Confidential Computing. In 1st GENZERO Workshop (pp. 196–205). Springer Nature Singapore.