arrow
Return

Private Delegated Computations Using Strong Isolation

delete2024-01-01
delete1
delete
OA
AI
M
Mathias Brossard
G
Guilhem Bryant
B
Basma El Gaabouri
X
Xinxin Fan
A
Alexandre Ferreira
E
Edmund Grimley Evans
C
Christopher Haster
E
Evan Johnson
D
Derek Miller
F
Fan Mo
D
Dominic P. Mulligan *
N
Nick Spinale
E
Eric Van Hensbergen
H
Hugo J. M. Vincent
S
Shale Xiong
DOI:10.1109/TETC.2023.3281738delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Computations are now routinely delegated to third-parties. In response, Confidential Computing technologies are being added to microprocessors offering a trusted execution environment (TEE) that provides confidentiality and integrity guarantees to code and data hosted within-even in the face of a privileged attacker. TEEs, along with an attestation protocol, permit remote third-parties to establish a trusted beachhead containing known code and data on an otherwise untrusted machine. Yet, they introduce many new problems, including: how to ease provisioning of computations safely into TEEs; how to develop distributed systems spanning multiple classes of TEE; and what to do about the billions of legacy devices without support for Confidential Computing? Tackling these problems, we introduce Veracruz, a pragmatic framework that eases the design and implementation of complex privacy-preserving, collaborative, delegated computations among a group of mutually mistrusting principals. Veracruz supports multiple isolation technologies and provides a common programming model and attestation protocol across all of them, smoothing deployment of delegated computations over supported technologies. We demonstrate Veracruz in operation, on private in-cloud object detection on encrypted video streaming from a video camera. In addition to supporting hardware-backed TEEs-like AWS Nitro Enclaves and Arm Confidential Computing Architecture Realms-Veracruz also provides pragmatic software TEEs on Armv8-A devices without hardware Confidential Computing capability, using the high-assurance seL4 microkernel and our IceCap framework.
Keywords:
Codes
Smoothing methods
Microprocessors
Object detection
Streaming media
Programming
Isolation technology
Confidential computing
trusted execution environments
Veracruz
IceCap
seL4
software enclaves
attestation

Journal

IEEE Transactions on Emerging Topics in Computing cover
IEEE Transactions on Emerging Topics in Computing
IF:
5.4
Papers:
1.1K
Citations:
3.4K

Organization

A
arm holdings
Scholars:
48
Papers: 34
Citations: 0
University of California System cover
University of California System
Scholars:
37.5W
Papers: 33.7W
Citations: 6.6K
U
University of California San Diego
Scholars:
4.6W
Papers: 3.5W
Citations: 924
I
Imperial College London
Scholars:
8.3W
Papers: 7.3W
Citations: 11.1W
researcher View more organizations