{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:24:32Z","timestamp":1750220672281,"version":"3.41.0"},"reference-count":29,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2020,12,14]],"date-time":"2020-12-14T00:00:00Z","timestamp":1607904000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2020,12,14]]},"abstract":"<jats:p>With organizational data practices coming under increasing scrutiny, demand is growing for mechanisms that can assist organizations in meeting their data-management obligations. TEEs (trusted execution environments) provide hardware-based mechanisms with various security properties for assisting computation and data management. TEEs are concerned with the confidentiality and integrity of data, code, and the corresponding computation. Because the main security properties come from hardware, certain protections and guarantees can be offered even if the host privileged software stack is vulnerable.<\/jats:p>","DOI":"10.1145\/3442632.3448126","type":"journal-article","created":{"date-parts":[[2021,1,26]],"date-time":"2021-01-26T23:06:15Z","timestamp":1611702375000},"page":"78-114","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Enclaves in the Clouds"],"prefix":"10.1145","volume":"18","author":[{"given":"Jatinder","family":"Singh","sequence":"first","affiliation":[{"name":"University of Cambridge"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jennifer","family":"Cobbe","sequence":"additional","affiliation":[{"name":"University of Cambridge"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Do Le","family":"Quoc","sequence":"additional","affiliation":[{"name":"TU Dresden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zahra","family":"Tarkhani","sequence":"additional","affiliation":[{"name":"University of Cambridge"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,1,26]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Cloud Computing Security, 185-199; https:\/\/dl.acm.org\/doi\/10","author":"Alder F.","year":"2018","unstructured":"Alder, F., Asokan, N., Kurnikov, A., Paverd, A., Steiner, M. 2018. S-FaaS: trustworthy and accountable function-as-a-service using Intel SGX. In Proceedings of the ACM SIGSAC Conference on Cloud Computing Security, 185-199; https:\/\/dl.acm.org\/doi\/10.1145\/3338466.3358916."},{"key":"e_1_2_1_2_1","unstructured":"Amazon. AWS GDPR Data Processing Addendum; https:\/\/d1.awsstatic.com\/legal\/aws-gdpr\/AWS_GDPR_DPA.pdf."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy. ACM.","author":"Anati I.","year":"2013","unstructured":"Anati, I., Gueron, S., Johnson, S., Scarlata, V. 2013. Innovative technology for CPU-based attestation and sealing. In Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy. ACM."},{"volume-title":"Cryptography and competition policy: issues with \"trusted computing.\" In Proceedings of the 22nd Annual Symposium on Principles of Distributed Computing, 3?10","author":"Anderson R.","key":"e_1_2_1_4_1","unstructured":"Anderson, R. 2003. Cryptography and competition policy: issues with \"trusted computing.\" In Proceedings of the 22nd Annual Symposium on Principles of Distributed Computing, 3?10."},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 12th Usenix Symposium on Operating Systems Design and Implementation, 689-703; https:\/\/dl.acm.org\/doi\/10","author":"Arnautov S.","year":"2016","unstructured":"Arnautov, S., Trach, B., Gregor, F., Knauth, T., Martin, A., Priebe, C., Lind, J., Muthukumaran, D., O'Keeffe, D., Stillwell, M., et al. 2016. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th Usenix Symposium on Operating Systems Design and Implementation, 689-703; https:\/\/dl.acm.org\/doi\/10.5555\/3026877.3026930."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1080\/23738871.2020.1745860"},{"key":"e_1_2_1_7_1","unstructured":"European Commission. What is personal data? https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-personal-data_en."},{"key":"e_1_2_1_8_1","first-page":"2984002","article-title":"Automatic enforcement of expressive security policies using enclaves. In Proceedings of the ACM SIGPLAN International Conference on Object-oriented Programming","volume":"1145","author":"Gollamudi A.","year":"2016","unstructured":"Gollamudi, A., Chong, S. 2016. Automatic enforcement of expressive security policies using enclaves. In Proceedings of the ACM SIGPLAN International Conference on Object-oriented Programming, Systems, Languages and Applications, 494-513; https:\/\/dl.acm.org\/doi\/10.1145\/2983990.2984002.","journal-title":"Systems, Languages and Applications, 494-513; https:\/\/dl.acm.org\/doi\/10."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053034"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3423211.3425687"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3314129"},{"key":"e_1_2_1_13_1","unstructured":"Linux Foundation. 2020. Confidential Computing Consortium. https:\/\/confidentialcomputing.io\/."},{"key":"e_1_2_1_14_1","unstructured":"Microsoft. Online Services Data Protection Addendum; https:\/\/www.microsoft.com\/en-us\/licensing\/product-licensing\/products."},{"key":"e_1_2_1_15_1","volume-title":"Virtualization-based security (VBS) memory enclaves: data protection through isolation","author":"Microsoft","year":"2018","unstructured":"Microsoft. 2018. Virtualization-based security (VBS) memory enclaves: data protection through isolation; https:\/\/www.microsoft.com\/security\/blog\/2018\/06\/05\/virtualization-based-security-vbs-memory-enclaves-data-protection-through-isolation\/."},{"key":"e_1_2_1_16_1","unstructured":"Microsoft. 2020. Azure confidential computing; https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/."},{"volume-title":"2021. Cloud Computing Law","author":"Millard C. J.","key":"e_1_2_1_17_1","unstructured":"Millard, C. J., ed. 2021. Cloud Computing Law, second edition. Oxford University Press."},{"key":"e_1_2_1_18_1","unstructured":"Nilsson A. Bideh P. N. Brorsson J. 2020. A survey of published attacks on Intel SGX. arXiv:2006.13598."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 26th Usenix Conference on Security Symposium; https:\/\/dl.acm.org\/doi\/10","author":"Ohrimenko O.","year":"2016","unstructured":"Ohrimenko, O., Schuster, F., Fournet, C., Mehta, A., Nowozin, S., Vaswani, K., Costa, M. 2016. Oblivious multi-party machine learning on trusted processors. In Proceedings of the 26th Usenix Conference on Security Symposium; https:\/\/dl.acm.org\/doi\/10.5555\/3241094.3241143."},{"key":"e_1_2_1_20_1","unstructured":"Open Enclave SDK. 2019; https:\/\/github.com\/openenclave\/openenclave."},{"key":"e_1_2_1_21_1","volume-title":"Trusted computing: promise and risk","author":"Schoen S. D.","year":"2003","unstructured":"Schoen, S. D. 2003. Trusted computing: promise and risk. Electronic Frontier Foundation; https:\/\/www.eff.org\/files\/20031001_tc.pdf."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.10"},{"volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Schwarz M.","key":"e_1_2_1_23_1","unstructured":"Schwarz, M., Weiser, S., Gruss, D. 2019. Practical enclave malware with Intel SGX. In Detection of Intrusions and Malware, and Vulnerability Assessment, Springer International Publishing, 177?196."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2018.3011052"},{"key":"e_1_2_1_25_1","unstructured":"Skillern R. 2018. Intel architecture enables new IBM cloud service with enhanced container security. Intel IT Peer Network; https:\/\/itpeernetwork.intel.com\/intel-ibm-cloud-container-security."},{"key":"e_1_2_1_26_1","unstructured":"Tarkhani Z. Madhavapeddy A. 2020. Sirius: enabling system-wide isolation for trusted execution environments. arXiv preprint arXiv:2009.01869."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the 2017 Usenix Annual Technical Conference, 645-658; https:\/\/dl.acm.org\/doi\/10","author":"Tsai C.-C.","year":"2017","unstructured":"Tsai, C.-C., Porter, D. E., Vij, M. 2017. Graphene-SGX: a practical library OS for unmodified applications on SGX. In Proceedings of the 2017 Usenix Annual Technical Conference, 645-658; https:\/\/dl.acm.org\/doi\/10.5555\/3154690.3154752."},{"key":"e_1_2_1_28_1","unstructured":"U.S. Department of Defense. 1985. Department of Defense Trusted Computer System Evaluation Criteria."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363206"},{"volume-title":"The Platform Society: Public Values in a Connective World","author":"van Dijck J.","key":"e_1_2_1_30_1","unstructured":"van Dijck, J., Poell, T., de Waal, M. 2018. The Platform Society: Public Values in a Connective World. Oxford University Press."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442632.3448126","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442632.3448126","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:03:03Z","timestamp":1750197783000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442632.3448126"}},"subtitle":["Legal considerations and broader implications"],"short-title":[],"issued":{"date-parts":[[2020,12,14]]},"references-count":29,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2020,12,14]]}},"alternative-id":["10.1145\/3442632.3448126"],"URL":"https:\/\/doi.org\/10.1145\/3442632.3448126","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2020,12,14]]},"assertion":[{"value":"2021-01-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}