{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:22:52Z","timestamp":1783009372722,"version":"3.54.5"},"publisher-location":"Singapore","reference-count":44,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819624164","type":"print"},{"value":"9789819624171","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-2417-1_12","type":"book-chapter","created":{"date-parts":[[2025,3,3]],"date-time":"2025-03-03T09:52:14Z","timestamp":1740995534000},"page":"217-235","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["SVSM-KMS: Safeguarding Keys for\u00a0Cloud Services with\u00a0Encrypted Virtualization"],"prefix":"10.1007","author":[{"given":"Benshan","family":"Mei","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenhao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongdai","family":"Lin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,3,4]]},"reference":[{"key":"12_CR1","unstructured":"Amazon Key Management Service $$|$$ Manage encryption keys $$|$$ Amazon Web Services (2024). https:\/\/www.amazonaws.cn\/en\/kms\/"},{"key":"12_CR2","unstructured":"Cloud Key Management $$|$$ Google Cloud (2024). https:\/\/cloud.google.com\/security-key-management?hl=zh-cn"},{"key":"12_CR3","unstructured":"Cloudera Navigator Key Trustee Server Overview $$|$$ CDP Private Cloud (2024). https:\/\/docs.cloudera.com\/cdp-private-cloud-base\/7.1.3\/security-key-trustee-server\/topics\/cm-security-kts-overview.html"},{"key":"12_CR4","unstructured":"HashiCorp Vault - Manage Secrets & Protect Sensitive Data (2024). https:\/\/www.hashicorp.com\/products\/vault"},{"key":"12_CR5","unstructured":"JSON-RPC 2.0 specification (2024). https:\/\/www.jsonrpc.org\/specification"},{"key":"12_CR6","unstructured":"Key management (2024). https:\/\/en.wikipedia.org\/wiki\/Key_management"},{"key":"12_CR7","unstructured":"Key management interoperability protocol specification version 2.0 (2024). https:\/\/docs.oasis-open.org\/kmip\/kmip-spec\/v2.0\/os\/kmip-spec-v2.0-os.html"},{"key":"12_CR8","unstructured":"Key Vault $$|$$ Microsoft Azure (2024). https:\/\/azure.microsoft.com\/en-us\/products\/key-vault"},{"key":"12_CR9","unstructured":"Secure VM service module for SEV-SNP guests (2024). https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-technical-docs\/specifications\/58019.pdf"},{"key":"12_CR10","unstructured":"SEV-ES guest-hypervisor communication block standardization (2024). https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-technical-docs\/specifications\/56421.pdf"},{"key":"12_CR11","unstructured":"SEV secure nested paging firmware ABI specification (2024). https:\/\/www.amd.com\/system\/files\/TechDocs\/56860.pdf"},{"key":"12_CR12","doi-asserted-by":"crossref","unstructured":"Abdulsalam, Y.S., Bouamama, J., Benkaouz, Y., Hedabou, M.: Decentralized SGX-based cloud key management. In: International Conference on Network and System Security, pp. 327\u2013341. Springer (2023)","DOI":"10.1007\/978-3-031-39828-5_18"},{"issue":"4","key":"12_CR13","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1109\/MCC.2016.89","volume":"3","author":"B AlBelooshi","year":"2016","unstructured":"AlBelooshi, B., Damiani, E., Salah, K., Martin, T.: Securing cryptographic keys in the cloud: a survey. IEEE Cloud Comput. 3(4), 42\u201356 (2016)","journal-title":"IEEE Cloud Comput."},{"key":"12_CR14","doi-asserted-by":"crossref","unstructured":"An, H., Choi, R., Kim, K.: Blockchain-based decentralized key management system with quantum resistance. In: Information Security Applications: 19th International Conference, WISA 2018, Jeju Island, Korea, 23\u201325 August 2018, Revised Selected Papers 19, pp. 229\u2013240. Springer (2019)","DOI":"10.1007\/978-3-030-17982-3_18"},{"key":"12_CR15","unstructured":"Arm: Evolution of the arm confidential compute architecture (2024). https:\/\/www.youtube.com\/watch?v=1AsvIt7bSLY"},{"key":"12_CR16","doi-asserted-by":"crossref","unstructured":"Arul\u00a0Oli, S., Arockiam, L.: A framework for key management for data confidentiality in cloud environment. In: 2015 International Conference on Computer Communication and Informatics (ICCCI), pp.\u00a01\u20134 (2015)","DOI":"10.1109\/ICCCI.2015.7218116"},{"key":"12_CR17","doi-asserted-by":"crossref","unstructured":"Bartsch, W., et al.: Design rationale for symbiotically secure key management systems in IoT and beyond. In: ICISSP, pp. 583\u2013591 (2023)","DOI":"10.5220\/0011726900003405"},{"key":"12_CR18","doi-asserted-by":"crossref","unstructured":"Bhudia, A., O\u2019Keeffe, D., Sgandurra, D., Hurley-Smith, D.: RansomClave: ransomware key management using SGX. In: Proceedings of the 16th International Conference on Availability, Reliability and Security, pp. 1\u201310 (2021)","DOI":"10.1145\/3465481.3470116"},{"key":"12_CR19","doi-asserted-by":"crossref","unstructured":"Buchade, A.R., Ingle, R.: Key management for cloud data storage: methods and comparisons. In: 2014 Fourth International Conference on Advanced Computing & Communication Technologies, pp. 263\u2013270. IEEE (2014)","DOI":"10.1109\/ACCT.2014.78"},{"key":"12_CR20","unstructured":"Chakrabarti, S., Baker, B., Vij, M.: Intel SGX enabled key manager service with openstack barbican. arXiv preprint arXiv:1712.07694 (2017)"},{"key":"12_CR21","doi-asserted-by":"crossref","unstructured":"Chandramouli, R., Iorga, M., Chokhani, S.: Cryptographic key management issues and challenges in cloud services. Secure Cloud Comput. 1\u201330 (2013)","DOI":"10.1007\/978-1-4614-9278-8_1"},{"issue":"3","key":"12_CR22","doi-asserted-by":"publisher","first-page":"2831","DOI":"10.1109\/COMST.2019.2907650","volume":"21","author":"A Ghosal","year":"2019","unstructured":"Ghosal, A., Conti, M.: Key management systems for smart grid advanced metering infrastructure: a survey. IEEE Commun. Surv. Tutor. 21(3), 2831\u20132848 (2019)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"12_CR23","doi-asserted-by":"crossref","unstructured":"Hashimoto, M.: Overview of memory security technologies. In: 2021 International Symposium on VLSI Technology, Systems and Applications (VLSI-TSA), pp.\u00a01\u20132 (2021)","DOI":"10.1109\/VLSI-TSA51926.2021.9440133"},{"issue":"2","key":"12_CR24","doi-asserted-by":"publisher","first-page":"611","DOI":"10.1016\/j.jnca.2012.12.010","volume":"36","author":"X He","year":"2013","unstructured":"He, X., Niedermeier, M., De Meer, H.: Dynamic key management in wireless sensor networks: a survey. J. Netw. Comput. Appl. 36(2), 611\u2013622 (2013)","journal-title":"J. Netw. Comput. Appl."},{"issue":"2","key":"12_CR25","doi-asserted-by":"publisher","first-page":"843","DOI":"10.1109\/TDSC.2019.2918278","volume":"18","author":"X Hu","year":"2021","unstructured":"Hu, X., et al.: STYX: a hierarchical key management system for elastic content delivery networks on public clouds. IEEE Trans. Dependable Secure Comput. 18(2), 843\u2013857 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"12_CR26","doi-asserted-by":"crossref","unstructured":"Huang, X., Chen, R.: A survey of key management service in cloud. In: 2018 IEEE 9th International Conference on Software Engineering and Service Science (ICSESS), pp. 916\u2013919. IEEE (2018)","DOI":"10.1109\/ICSESS.2018.8663805"},{"key":"12_CR27","unstructured":"Intel: Intel Trust Domain Extensions (2020). https:\/\/cdrdv2-public.intel.com\/773039\/intel-tdx-module-1.5-td-partitioning-spec-354807001.pdf"},{"key":"12_CR28","doi-asserted-by":"crossref","unstructured":"Jin, W., Geng, K., Yu, M., Guo, Y., Li, F.: Efficiently managing large-scale keys in HDFS. In: 2021 IEEE 23rd International Conference on High Performance Computing & Communications; 7th International Conference on Data Science & Systems; 19th International Conference on Smart City; 7th International Conference on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC\/DSS\/SmartCity\/DependSys), pp. 353\u2013360. IEEE (2021)","DOI":"10.1109\/HPCC-DSS-SmartCity-DependSys53884.2021.00071"},{"key":"12_CR29","doi-asserted-by":"crossref","unstructured":"Karande, V., Bauman, E., Lin, Z., Khan, L.: SGX-Log: securing system logs with SGX. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 19\u201330 (2017)","DOI":"10.1145\/3052973.3053034"},{"key":"12_CR30","unstructured":"Kuan, S.: Improving the security of KMS on a cloud platform using trusted hardware. Master\u2019s thesis, Aalto University, School of Science (2018)"},{"key":"12_CR31","doi-asserted-by":"crossref","unstructured":"Kuzminykh, I., Ghita, B., Shiaeles, S.: Comparative analysis of cryptographic key management systems. In: International Conference on Next Generation Wired\/Wireless Networking, pp. 80\u201394. Springer (2020)","DOI":"10.1007\/978-3-030-65729-1_8"},{"key":"12_CR32","doi-asserted-by":"crossref","unstructured":"Lei, S., Zishan, D., Jindi, G.: Research on key management infrastructure in cloud computing environment. In: 2010 Ninth International Conference on Grid and Cloud Computing, pp. 404\u2013407. IEEE (2010)","DOI":"10.1109\/GCC.2010.84"},{"key":"12_CR33","doi-asserted-by":"crossref","unstructured":"Luo, S., Hua, Z., Xia, Y.: TZ-KMS: a secure key management service for joint cloud computing with arm trustzone. In: 2018 IEEE Symposium on Service-Oriented System Engineering (SOSE), pp. 180\u2013185. IEEE (2018)","DOI":"10.1109\/SOSE.2018.00030"},{"issue":"4","key":"12_CR34","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1109\/MM.2021.3086541","volume":"41","author":"M Mattioli","year":"2021","unstructured":"Mattioli, M.: Rome to Milan, AMD continues its tour of Italy. IEEE Micro 41(4), 78\u201383 (2021)","journal-title":"IEEE Micro"},{"key":"12_CR35","doi-asserted-by":"crossref","unstructured":"Mofrad, S., Zhang, F., Lu, S., Shi, W.: A comparison study of Intel SGX and AMD memory encryption technology. In: Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy. HASP \u201918. Association for Computing Machinery, New York (2018)","DOI":"10.1145\/3214292.3214301"},{"key":"12_CR36","doi-asserted-by":"crossref","unstructured":"Ning, Z., Zhang, F., Shi, W., Shi, W.: Position paper: challenges towards securing hardware-assisted execution environments. In: Proceedings of the Hardware and Architectural Support for Security and Privacy. HASP \u201917. Association for Computing Machinery, New York (2017)","DOI":"10.1145\/3092627.3092633"},{"key":"12_CR37","doi-asserted-by":"crossref","unstructured":"Oruganti, R., Churi, P.: Systematic survey on cryptographic methods used for key management in cloud computing. In: International Conference on Innovative Computing and Communications: Proceedings of ICICC 2021, vol. 2, pp. 445\u2013460. Springer (2022)","DOI":"10.1007\/978-981-16-2597-8_38"},{"key":"12_CR38","doi-asserted-by":"crossref","unstructured":"Park, M., et al.: An SGX-based key management framework for data centric networking. In: International Workshop on Information Security Applications, pp. 370\u2013382 (2019)","DOI":"10.1007\/978-3-030-39303-8_28"},{"issue":"6","key":"12_CR39","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3291047","volume":"51","author":"S Pinto","year":"2019","unstructured":"Pinto, S., Santos, N.: Demystifying arm trustzone: a comprehensive survey. ACM Comput. Surv. (CSUR) 51(6), 1\u201336 (2019)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"12_CR40","doi-asserted-by":"crossref","unstructured":"Qin, H., et al.: Protecting encrypted virtual machines from nested page fault controlled channel. In: Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy, pp. 165\u2013175 (2023)","DOI":"10.1145\/3577923.3583659"},{"key":"12_CR41","unstructured":"AMD SEV-SNP: strengthening VM isolation with integrity protection and more. White Paper, p.\u00a08 (2020)"},{"key":"12_CR42","unstructured":"Shakevsky, A., Ronen, E., Wool, A.: Trust dies in darkness: shedding light on Samsung\u2019s TrustZone keymaster design. In: 31st USENIX Security Symposium (USENIX Security 22), pp. 251\u2013268 (2022)"},{"key":"12_CR43","doi-asserted-by":"crossref","unstructured":"Valadares, D.C.G., da\u00a0Silva, M.S.L., Brito, A.E.M., Salvador, E.M.: Achieving data dissemination with security using FIWARE and Intel software guard extensions (SGX). In: 2018 IEEE Symposium on Computers and Communications (ISCC), pp.\u00a01\u20137. IEEE (2018)","DOI":"10.1109\/ISCC.2018.8538590"},{"key":"12_CR44","doi-asserted-by":"crossref","unstructured":"Wei, C., Li, J., Li, W., Yu, P., Guan, H.: STYX: a trusted and accelerated hierarchical SSL key management and distribution system for cloud based CDN application. In: Proceedings of the 2017 Symposium on Cloud Computing, pp. 201\u2013213 (2017)","DOI":"10.1145\/3127479.3127482"}],"container-title":["Lecture Notes in Computer Science","Science of Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-2417-1_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,6]],"date-time":"2025-09-06T07:07:23Z","timestamp":1757142443000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-2417-1_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819624164","9789819624171"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-2417-1_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"4 March 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SciSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Science of Cyber Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"scisec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.scisec.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}