{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T23:11:30Z","timestamp":1781046690929,"version":"3.54.1"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2024,4,30]],"date-time":"2024-04-30T00:00:00Z","timestamp":1714435200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2024,4,30]]},"abstract":"<jats:p>Secure computation via MPC\/homomorphic encryption versus hardware enclaves presents tradeoffs involving deployment, security, and performance. Regarding performance, it matters a lot which workload you have in mind. For simple workloads such as simple summations, low-degree polynomials, or simple machine-learning tasks, both approaches can be ready to use in practice, but for rich computations such as complex SQL analytics or training large machine-learning models, only the hardware enclave approach is at this moment practical enough for many real-world deployment scenarios.<\/jats:p>","DOI":"10.1145\/3664295","type":"journal-article","created":{"date-parts":[[2024,5,24]],"date-time":"2024-05-24T13:10:47Z","timestamp":1716556247000},"page":"108-132","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Confidential Computing or Cryptographic Computing?"],"prefix":"10.1145","volume":"22","author":[{"given":"Raluca Ada","family":"Popa","sequence":"first","affiliation":[{"name":"UC Berkeley"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,5,24]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Anjuna. 2022. Confidential computing pioneer Anjuna makes cloud safe enough for even government and defense agencies; https:\/\/www.anjuna.io\/press\/israels-ministry-of-defense-selects-anjuna-security-software-to-lockdown-sensitive-data-in-public-clouds."},{"key":"e_1_2_1_2_1","unstructured":"Confidential Computing Consortium; https:\/\/confidentialcomputing.io."},{"key":"e_1_2_1_3_1","unstructured":"Confidential Computing Summit 2024; https:\/\/www.confidentialcomputingsummit.com."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483562"},{"key":"e_1_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Delignat-Lavaud A. Fournet C. Vaswani K. Clebsch S. Riechert M. Costa M. Russinovich M. 2023. Why should I trust your code? acmqueue 21(4); https:\/\/queue.acm.org\/detail.cfm?id=3623460.","DOI":"10.1145\/3623460"},{"key":"e_1_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Dhanuskodi G. Guha S. Krishnan V. Manjunatha A. Nertney R. O'Connor M. Rogers P. 2023. Creating the first confidential GPUs. acmqueue 21(4); https:\/\/queue.acm.org\/detail.cfm?id=3623391.","DOI":"10.1145\/3623393.3623391"},{"key":"e_1_2_1_7_1","volume-title":"Galois team wraps up the Jana project","author":"Galois 0.","year":"2020","unstructured":"Galois. 2020. Galois team wraps up the Jana project; https:\/\/galois.com\/blog\/2020\/10\/galois-team-wraps-up-the-jana-project\/."},{"key":"e_1_2_1_8_1","unstructured":"Galois. 2024. Jana: private data as a service; https:\/\/galois.com\/project\/jana-private-data-as-a-service\/."},{"key":"e_1_2_1_10_1","unstructured":"Google Cloud. Confidential VM overview; https:\/\/cloud.google.com\/confidential-computing\/confidential-vm\/docs\/confidential-vm-overview."},{"key":"e_1_2_1_11_1","unstructured":"Google Cloud. Encrypt workload data in-use with confidential Google Kubernetes engine nodes; https:\/\/cloud.google.com\/kubernetes-engine\/docs\/how-to\/confidential-gke-nodes."},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Kaplan D. 2023. Hardware VM isolation in the cloud. acmqueue 21(4); https:\/\/queue.acm.org\/detail.cfm?id=3623392.","DOI":"10.1145\/3623392"},{"key":"e_1_2_1_13_1","volume-title":"Usenix Symposium on Operating Systems Design and Implementation; https:\/\/www.usenix.org\/conference\/osdi21\/presentation\/kumar.","author":"Kumar S.","year":"2021","unstructured":"Kumar, S., Culler, D. E., Popa, R. A. 2021. MAGE: nearly zero-cost virtual memory for secure computation. Usenix Symposium on Operating Systems Design and Implementation; https:\/\/www.usenix.org\/conference\/osdi21\/presentation\/kumar."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00045"},{"key":"e_1_2_1_15_1","unstructured":"MPC Deployments; https:\/\/mpc.cs.berkeley.edu."},{"key":"e_1_2_1_16_1","unstructured":"Nvidia Confidential Computing; https:\/\/www.nvidia.com\/en-us\/data-center\/solutions\/confidential-computing\/."},{"key":"e_1_2_1_17_1","unstructured":"Opaque; https:\/\/opaque.co."},{"key":"e_1_2_1_18_1","volume-title":"30th Usenix Security Symposium; https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/poddar.","author":"Poddar R.","year":"2021","unstructured":"Poddar, R., Kalra, S., Yanai, A., Deng, R., Popa, R. A., Hellerstein, J. 2021. Senate: a maliciously secure MPC platform for collaborative analytics. 30th Usenix Security Symposium; https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/poddar."},{"key":"e_1_2_1_19_1","unstructured":"RISELab; https:\/\/rise.cs.berkeley.edu."},{"key":"e_1_2_1_20_1","unstructured":"SecureValueRecovery2. Github; https:\/\/github.com\/signalapp\/SecureValueRecovery2."},{"key":"e_1_2_1_21_1","unstructured":"Signal; https:\/\/signal.org\/blog\/building-faster-oram\/."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 31st Usenix Security Symposium; https:\/\/www.usenix.org\/system\/files\/sec22-watson.pdf.","author":"Watson J.-L.","year":"2022","unstructured":"Watson, J.-L., Wagh, S., Popa, R. A. 2022. Piranha: a GPU platform for secure computation. Proceedings of the 31st Usenix Security Symposium; https:\/\/www.usenix.org\/system\/files\/sec22-watson.pdf."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664295","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664295","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:06:15Z","timestamp":1750291575000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664295"}},"subtitle":["Tradeoffs between cryptography and hardware enclaves"],"short-title":[],"issued":{"date-parts":[[2024,4,30]]},"references-count":22,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,4,30]]}},"alternative-id":["10.1145\/3664295"],"URL":"https:\/\/doi.org\/10.1145\/3664295","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,30]]},"assertion":[{"value":"2024-05-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}