{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:08:43Z","timestamp":1782968923796,"version":"3.54.5"},"reference-count":11,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,8,31]],"date-time":"2023-08-31T00:00:00Z","timestamp":1693440000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>Confidential Computing (CC) fundamentally improves our security posture by drastically reducing the attack surface of systems. While traditional systems encrypt data at rest and in transit, CC extends this protection to data in use. It provides a novel, clearly defined security boundary, isolating sensitive data within trusted execution environments during computation. This means services can be designed that segment data based on least-privilege access principles, while all other code in the system sees only encrypted data. Crucially, the isolation is rooted in novel hardware primitives, effectively rendering even the cloud-hosting infrastructure and its administrators incapable of accessing the data. This approach creates more resilient systems capable of withstanding increasingly sophisticated cyber threats, thereby reinforcing data protection and sovereignty in an unprecedented manner.<\/jats:p>","DOI":"10.1145\/3623461","type":"journal-article","created":{"date-parts":[[2023,9,7]],"date-time":"2023-09-07T23:44:26Z","timestamp":1694130266000},"page":"44-48","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Confidential Computing: Elevating Cloud Security and Privacy"],"prefix":"10.1145","volume":"21","author":[{"given":"Mark","family":"Russinovich","sequence":"first","affiliation":[{"name":"Microsoft Azure"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,9,7]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"An architecture for trustworthy and transparent digital supply chains","author":"Birkholz H.","unstructured":"Birkholz, H., Delignat-Lavaud, A., Fournet, C., Deshpande, Y., Lasker, S. 2022. An architecture for trustworthy and transparent digital supply chains. IETF SCITT Working Group; https:\/\/datatracker.ietf.org\/doc\/draft-ietf-scitt-architecture\/."},{"key":"e_1_2_1_2_1","volume-title":"a framework for building confidential verifiable replicated services","author":"CCF","year":"2019","unstructured":"CCF: a framework for building confidential verifiable replicated services. 2019. GitHub; https:\/\/github.com\/microsoft\/CCF."},{"key":"e_1_2_1_3_1","unstructured":"Confidential Computing Consortium; https:\/\/confidentialcomputing.io."},{"key":"e_1_2_1_4_1","unstructured":"Delignat-Lavaud A. Russinovich M. Vaswani K. 2023. Unlocking the potential of privacy-preserving AI with Azure confidential computing on NVIDIA H100. Microsoft Azure Confidential Computing Blog; https:\/\/techcommunity.microsoft.com\/t5\/azure-confidential-computing\/unlocking-the-potential-of-privacy-preserving-ai-with-azure\/ba-p\/3776838."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the 25th Usenix Security Symposium; https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity16\/sec16_paper_ohrimenko.pdf.","author":"Ohrimenko O.","year":"2016","unstructured":"Ohrimenko, O., Schuster, F., Fournet, C., Mehta, A., Nowozin, S., Vaswani, K., Costa, M. 2016. Oblivious multi-party machine learning on trusted processors. Proceedings of the 25th Usenix Security Symposium; https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity16\/sec16_paper_ohrimenko.pdf."},{"key":"e_1_2_1_7_1","unstructured":"Opaque. 2018. RISE Lab UC Berkeley; https:\/\/rise.cs.berkeley.edu\/projects\/opaque\/."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00025"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Russinovich M. Costa M. Fournet C. Chisnall D. Delignat-Lavaud A. Clebsch S. Vaswani K. Bhatia V. 2021. Toward confidential cloud computing. Communications of the ACM 64(6) 54?61; https:\/\/dl.acm.org\/doi\/10.1145\/3453930.","DOI":"10.1145\/3453930"},{"key":"e_1_2_1_10_1","unstructured":"Sanctum Secure Processor. 2017. MIT CSAIL; https:\/\/www.csail.mit.edu\/research\/sanctum-secure-processor."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.10"}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623461","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3623461","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:51:00Z","timestamp":1750287060000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623461"}},"subtitle":["Working toward a more secure and innovative future"],"short-title":[],"issued":{"date-parts":[[2023,8,31]]},"references-count":11,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3623461"],"URL":"https:\/\/doi.org\/10.1145\/3623461","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,31]]},"assertion":[{"value":"2023-09-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}