{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T14:40:42Z","timestamp":1773931242547,"version":"3.50.1"},"reference-count":29,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2021,4,26]],"date-time":"2021-04-26T00:00:00Z","timestamp":1619395200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/P024394\/1,EP\/R033501\/1"],"award-info":[{"award-number":["EP\/P024394\/1,EP\/R033501\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2021,5]]},"abstract":"<jats:p>\n            Trusted Execution Environments ('TEEs') or 'secure enclaves' aim at enabling more secure computation and data management. There is much enthusiasm for this technology, not least as we see increasing legal and regulatory attention on issues of security, privacy, and data management and use. With cloud providing the infrastructure for underpinning applications, data processing and analytics\/ML, access to enclaves and enclave-backed technologies are increasingly being offered by service (cloud) providers - with the technology described as enabling\n            <jats:bold>confidential computing<\/jats:bold>\n            . This paper provides a high-level overview of the common security properties provided by enclaves, and considers how such technology, in being offered by cloud providers, relates to organizational legal and regulatory concerns. Focusing on data protection regulations, we explore the aspects of TEEs that might assist compliance, and who stands to benefit from the deployment of such technology in a service provision context.\n          <\/jats:p>","DOI":"10.1145\/3447543","type":"journal-article","created":{"date-parts":[[2021,4,26]],"date-time":"2021-04-26T14:14:22Z","timestamp":1619446462000},"page":"42-51","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Enclaves in the clouds"],"prefix":"10.1145","volume":"64","author":[{"given":"Jatinder","family":"Singh","sequence":"first","affiliation":[{"name":"University of Cambridge, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jennifer","family":"Cobbe","sequence":"additional","affiliation":[{"name":"University of Cambridge, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Do Le","family":"Quoc","sequence":"additional","affiliation":[{"name":"TU Dresden, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zahra","family":"Tarkhani","sequence":"additional","affiliation":[{"name":"Cambridge University Computer Laboratory, Cambridge, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,4,26]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the ACM SIGSAC Conf. Cloud Computing Security","author":"Alder F.","year":"2018","unstructured":"Alder , F. , Asokan , N. , Kurnikov , A. , Paverd , A. , Steiner M. S- Faa S : Trustworthy and accountable function-as-a-service using Intel SGX . In Proceedings of the ACM SIGSAC Conf. Cloud Computing Security , 2018 , 185--199; https:\/\/dl.acm.org\/doi\/10.1145\/3338466.3358916. Alder, F., Asokan, N., Kurnikov, A., Paverd, A., Steiner M. S-FaaS: Trustworthy and accountable function-as-a-service using Intel SGX. In Proceedings of the ACM SIGSAC Conf. Cloud Computing Security, 2018, 185--199; https:\/\/dl.acm.org\/doi\/10.1145\/3338466.3358916."},{"key":"e_1_2_1_2_1","unstructured":"Amazon. AWS GDPR Data Processing Addendum; https:\/\/d1.awsstatic.com\/legal\/aws-gdpr\/AWS_GDPR_DPA.pdf.  Amazon. AWS GDPR Data Processing Addendum; https:\/\/d1.awsstatic.com\/legal\/aws-gdpr\/AWS_GDPR_DPA.pdf."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 2nd Intern. Workshop on Hardware and Architectural Support for Security and Privacy. ACM.","author":"Anati I.","unstructured":"Anati , I. , Gueron , S. , Johnson , S. , Scarlata , V. Innovative technology for CPU-based attestation and sealing . In Proceedings of the 2nd Intern. Workshop on Hardware and Architectural Support for Security and Privacy. ACM. Anati, I., Gueron, S., Johnson, S., Scarlata, V. Innovative technology for CPU-based attestation and sealing. In Proceedings of the 2nd Intern. Workshop on Hardware and Architectural Support for Security and Privacy. ACM."},{"key":"e_1_2_1_4_1","first-page":"10","article-title":"Cryptography and competition policy: issues with \"trusted computing.\" In Proceedings of the 22nd Annual Symp","volume":"3","author":"Anderson R","year":"2003","unstructured":"Anderson , R . Cryptography and competition policy: issues with \"trusted computing.\" In Proceedings of the 22nd Annual Symp . Principles of Distributed Computing , 2003 , 3 -- 10 . Anderson, R. Cryptography and competition policy: issues with \"trusted computing.\" In Proceedings of the 22nd Annual Symp. Principles of Distributed Computing, 2003, 3--10.","journal-title":"Principles of Distributed Computing"},{"key":"e_1_2_1_5_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th Usenix Symp. Operating Systems Design and Implementation","author":"Arnautov S.","year":"2016","unstructured":"Arnautov , S. et al . SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th Usenix Symp. Operating Systems Design and Implementation , 2016 , 689--703; https:\/\/dl.acm.org\/doi\/10.5555\/3026877.3026930. Arnautov, S. et al. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th Usenix Symp. Operating Systems Design and Implementation, 2016, 689--703; https:\/\/dl.acm.org\/doi\/10.5555\/3026877.3026930."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1080\/23738871.2020.1745860"},{"key":"e_1_2_1_7_1","unstructured":"European Commission. What is personal data? https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-personal-data_en.  European Commission. What is personal data? https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-personal-data_en."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2983990.2984002"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the 2017 ACM Asia Conf. Computer and Communications Security, 19--30","author":"Karande V.","unstructured":"Karande , V. , Bauman , E. , Lin , Z. , Khan , L. SGX- Log : Securing system logs with SGX . In Proceedings of the 2017 ACM Asia Conf. Computer and Communications Security, 19--30 . Karande, V., Bauman, E., Lin, Z., Khan, L. SGX-Log: Securing system logs with SGX. In Proceedings of the 2017 ACM Asia Conf. Computer and Communications Security, 19--30."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3423211.3425687"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of WWW '19: The World Wide Web Conf.; https:\/\/dl.acm.org\/doi\/10","author":"Le Quoc D.","unstructured":"Le Quoc , D. , Gregor , F. , Singh , J. , Fetzer , C. SGX- PySpark : Secure distributed data analytics . In Proceedings of WWW '19: The World Wide Web Conf.; https:\/\/dl.acm.org\/doi\/10 .1145\/3308558.3314129. Le Quoc, D., Gregor, F., Singh, J., Fetzer, C. SGX-PySpark: Secure distributed data analytics. In Proceedings of WWW '19: The World Wide Web Conf.; https:\/\/dl.acm.org\/doi\/10.1145\/3308558.3314129."},{"key":"e_1_2_1_13_1","volume-title":"Confidential Computing Consortium","author":"Linux Foundation","year":"2020","unstructured":"Linux Foundation . Confidential Computing Consortium , 2020 ; https:\/\/confidentialcomputing.io\/. Linux Foundation. Confidential Computing Consortium, 2020; https:\/\/confidentialcomputing.io\/."},{"key":"e_1_2_1_14_1","unstructured":"Microsoft. Online Services Data Protection Addendum; https:\/\/www.microsoft.com\/en-us\/licensing\/product-licensing\/products.  Microsoft. Online Services Data Protection Addendum; https:\/\/www.microsoft.com\/en-us\/licensing\/product-licensing\/products."},{"key":"e_1_2_1_15_1","volume-title":"Virtualization-based security (VBS) memory enclaves: Data protection through isolation","author":"Microsoft","year":"2018","unstructured":"Microsoft . Virtualization-based security (VBS) memory enclaves: Data protection through isolation , 2018 ; http:\/\/bit.ly\/3ps8rF2 Microsoft. Virtualization-based security (VBS) memory enclaves: Data protection through isolation, 2018; http:\/\/bit.ly\/3ps8rF2"},{"key":"e_1_2_1_16_1","volume-title":"Azure confidential computing","author":"Microsoft","year":"2020","unstructured":"Microsoft . Azure confidential computing , 2020 ; https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute Microsoft. Azure confidential computing, 2020; https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1093\/oso\/9780198716662.001.0001"},{"key":"e_1_2_1_18_1","volume-title":"A survey of published attacks on Intel SGX","author":"Nilsson A.","year":"2006","unstructured":"Nilsson , A. , Bideh , P.N. , Brorsson , J. 2020. A survey of published attacks on Intel SGX ; arXiv: 2006 .13598. Nilsson, A., Bideh, P.N., Brorsson, J. 2020. A survey of published attacks on Intel SGX; arXiv:2006.13598."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 26th Usenix Conf. Security Symposium","author":"Ohrimenko O.","unstructured":"Ohrimenko , O. , Schuster , F. , Fournet , C. , Mehta , A. , Nowozin , S. , Vaswani , K. , Costa , M. Oblivious multi-party machine learning on trusted processors . In Proceedings of the 26th Usenix Conf. Security Symposium , 2016; https:\/\/dl.acm.org\/doi\/10.5555\/3241094.3241143. Ohrimenko, O., Schuster, F., Fournet, C., Mehta, A., Nowozin, S., Vaswani, K., Costa, M. Oblivious multi-party machine learning on trusted processors. In Proceedings of the 26th Usenix Conf. Security Symposium, 2016; https:\/\/dl.acm.org\/doi\/10.5555\/3241094.3241143."},{"key":"e_1_2_1_20_1","unstructured":"Open Enclave SDK. 2019; https:\/\/github.com\/openenclave\/openenclave.  Open Enclave SDK. 2019; https:\/\/github.com\/openenclave\/openenclave."},{"key":"e_1_2_1_21_1","volume-title":"Trusted computing: promise and risk","author":"Schoen S.D.","year":"2003","unstructured":"Schoen , S.D. Trusted computing: promise and risk . Electronic Frontier Foundation , 2003 ; https:\/\/www.eff.org\/files\/20031001_tc.pdf. Schoen, S.D. Trusted computing: promise and risk. Electronic Frontier Foundation, 2003; https:\/\/www.eff.org\/files\/20031001_tc.pdf."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 2015 IEEE Symp. Security and Privacy; https:\/\/ieeexplore.ieee.org\/document\/7163017","author":"Schuster F.","unstructured":"Schuster , F. , Costa , M. , Fournet , C. , Gkantsidis , C. , Peinado , M. , Mainar-Ruiz , G. , Russinovich , M. VC3 : Trustworthy data analytics in the cloud using SGX . In Proceedings of the 2015 IEEE Symp. Security and Privacy; https:\/\/ieeexplore.ieee.org\/document\/7163017 . Schuster, F., Costa, M., Fournet, C., Gkantsidis, C., Peinado, M., Mainar-Ruiz, G., Russinovich, M. VC3: Trustworthy data analytics in the cloud using SGX. In Proceedings of the 2015 IEEE Symp. Security and Privacy; https:\/\/ieeexplore.ieee.org\/document\/7163017."},{"key":"e_1_2_1_23_1","first-page":"196","article-title":"Practical enclave malware with Intel SGX. In Detection of Intrusions and Malware, and Vulnerability Assessment","volume":"177","author":"Schwarz M.","year":"2019","unstructured":"Schwarz , M. , Weiser , S. , Gruss , D . Practical enclave malware with Intel SGX. In Detection of Intrusions and Malware, and Vulnerability Assessment . Springer International Publishing , 2019 , 177 -- 196 . Schwarz, M., Weiser, S., Gruss, D. Practical enclave malware with Intel SGX. In Detection of Intrusions and Malware, and Vulnerability Assessment. Springer International Publishing, 2019, 177--196.","journal-title":"Springer International Publishing"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2018.3011052"},{"key":"e_1_2_1_25_1","volume-title":"Intel architecture enables new IBM cloud service with enhanced container security. Intel IT Peer Network","author":"Skillern R.","year":"2018","unstructured":"Skillern , R. Intel architecture enables new IBM cloud service with enhanced container security. Intel IT Peer Network , 2018 ; https:\/\/itpeernetwork.intel.com\/intel-ibm-cloud-container-security. Skillern, R. Intel architecture enables new IBM cloud service with enhanced container security. Intel IT Peer Network, 2018; https:\/\/itpeernetwork.intel.com\/intel-ibm-cloud-container-security."},{"key":"e_1_2_1_26_1","volume-title":"Sirius: enabling system-wide isolation for trusted execution environments. 2020","author":"Tarkhani Z.","year":"2009","unstructured":"Tarkhani , Z. , Madhavapeddy , A. Sirius: enabling system-wide isolation for trusted execution environments. 2020 ; arXiv: 2009 .01869. Tarkhani, Z., Madhavapeddy, A. Sirius: enabling system-wide isolation for trusted execution environments. 2020; arXiv:2009.01869."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the 2017 Usenix Annual Technical Conf., 645--658; https:\/\/dl.acm.org\/doi\/10","author":"Tsai C.-C.","unstructured":"Tsai , C.-C. , Porter , D. E. , Vij , M. Graphene - SGX : A practical library OS for unmodified applications on SGX . In Proceedings of the 2017 Usenix Annual Technical Conf., 645--658; https:\/\/dl.acm.org\/doi\/10 .5555\/3154690.3154752. Tsai, C.-C., Porter, D. E., Vij, M. Graphene-SGX: A practical library OS for unmodified applications on SGX. In Proceedings of the 2017 Usenix Annual Technical Conf., 645--658; https:\/\/dl.acm.org\/doi\/10.5555\/3154690.3154752."},{"key":"e_1_2_1_28_1","unstructured":"U.S. Department of Defense. 1985. DoD Trusted Computer System Evaluation Criteria.  U.S. Department of Defense. 1985. DoD Trusted Computer System Evaluation Criteria."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 2019 ACM SIGSAC Conf. Computer and Communications Security, 1741--1758; https:\/\/dl.acm.org\/doi\/10","author":"Van Bulck J.","year":"1953","unstructured":"Van Bulck , J. , Oswald , D. , Marin , E. , Aldoseri , A. , Garcia , F.D. , Piessens , F. A tale of two worlds: Assessing the vulnerability of enclave shielding runtimes . In Proceedings of the 2019 ACM SIGSAC Conf. Computer and Communications Security, 1741--1758; https:\/\/dl.acm.org\/doi\/10 .1145\/33 1953 5.3363206. Van Bulck, J., Oswald, D., Marin, E., Aldoseri, A., Garcia, F.D., Piessens, F. A tale of two worlds: Assessing the vulnerability of enclave shielding runtimes. In Proceedings of the 2019 ACM SIGSAC Conf. Computer and Communications Security, 1741--1758; https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3363206."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1093\/oso\/9780190889760.001.0001"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447543","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3447543","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:25:10Z","timestamp":1750195510000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447543"}},"subtitle":["Legal considerations and broader implications"],"short-title":[],"issued":{"date-parts":[[2021,4,26]]},"references-count":29,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2021,5]]}},"alternative-id":["10.1145\/3447543"],"URL":"https:\/\/doi.org\/10.1145\/3447543","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,26]]},"assertion":[{"value":"2021-04-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}