{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T14:29:13Z","timestamp":1787063353869,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,12,15]]},"DOI":"10.1145\/3721462.3770778","type":"proceedings-article","created":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T19:56:49Z","timestamp":1765223809000},"page":"369-382","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Full Trust Alchemist: Reforging Attestation for Cloud-based Confidential Workloads"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4148-7631","authenticated-orcid":false,"given":"Anna","family":"Galanou","sequence":"first","affiliation":[{"name":"TU Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3276-8820","authenticated-orcid":false,"given":"Florian","family":"Lubitz","sequence":"additional","affiliation":[{"name":"TU Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7760-4690","authenticated-orcid":false,"given":"Hajeong","family":"Jeon","sequence":"additional","affiliation":[{"name":"RWTH Aachen, Aachen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8240-5420","authenticated-orcid":false,"given":"Christof","family":"Fetzer","sequence":"additional","affiliation":[{"name":"TU Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8116-7763","authenticated-orcid":false,"given":"R\u00fcdiger","family":"Kapitza","sequence":"additional","affiliation":[{"name":"FAU Erlangen-Nuremberg, Erlangen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,12,14]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2020. PC Client Platform TPM Profile for TPM 2.0 Version 1.04 Revision 37. Technical Report. Trusted Computing Group (TCG). https:\/\/trustedcomputinggroup.org\/wp-content\/uploads\/PC-Client-Specific-Platform-TPM-Profile-for-TPM-2p0-v1p04_r0p37_pub-1.pdf Describes TPM-based roots of trust including Root of Trust for Measurement (RTM) and Reporting (RTR)."},{"key":"e_1_3_2_2_2_1","unstructured":"Advanced Micro Devices. 2020. AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More. https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/epyc-business-docs\/white-papers\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3564648"},{"key":"e_1_3_2_2_4_1","volume-title":"Arm CCA Reference Software Stack: Guest Linux in Realm. Arm Limited. https:\/\/developer.arm.com\/documentation\/den0127\/latest\/Arm-CCA-reference-software-stack\/Guest-Linux-in-Realm DEN0127","author":"Arm Limited","year":"2025","unstructured":"Arm Limited 2025. Arm CCA Reference Software Stack: Guest Linux in Realm. Arm Limited. https:\/\/developer.arm.com\/documentation\/den0127\/latest\/Arm-CCA-reference-software-stack\/Guest-Linux-in-Realm DEN0127; Accessed: 2025-09-14."},{"key":"e_1_3_2_2_5_1","volume-title":"Arm CCA Reference Software Stack: KVM Support for Arm CCA. Arm Limited. https:\/\/developer.arm.com\/documentation\/den0127\/300\/Arm-CCA-reference-software-stack\/KVM-support-for-Arm-CCADEN0127\/300","author":"Arm Limited","year":"2025","unstructured":"Arm Limited 2025. Arm CCA Reference Software Stack: KVM Support for Arm CCA. Arm Limited. https:\/\/developer.arm.com\/documentation\/den0127\/300\/Arm-CCA-reference-software-stack\/KVM-support-for-Arm-CCADEN0127\/300; Accessed: 2025-09-14."},{"key":"e_1_3_2_2_6_1","unstructured":"Microsoft Azure. 2024. Deploy confidential containers on Azure Kubernetes Service. https:\/\/learn.microsoft.com\/en-us\/azure\/aks\/deploy-confidential-containers-default-policy"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2023.3302956"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","unstructured":"Marcus Brandenburger Christian Cachin Matthias Lorenz and R\u00fcdiger Kapitza. 2017. Rollback and Forking Detection for Trusted Execution Environments Using Lightweight Collective Memory. In 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). 157\u2013168. 10.1109\/DSN.2017.45","DOI":"10.1109\/DSN.2017.45"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627187"},{"key":"e_1_3_2_2_10_1","unstructured":"Google Cloud. 2023. Confidential Kubernetes. https:\/\/kubernetes.io\/blog\/2023\/07\/06\/confidential-kubernetes\/"},{"key":"e_1_3_2_2_11_1","unstructured":"Codecov. 2021. Post-Mortem \/ Root Cause Analysis (April 2021). https:\/\/about.codecov.io\/apr-2021-post-mortem\/"},{"key":"e_1_3_2_2_12_1","unstructured":"Confidential Computing Consortium. 2024. The CIA Triad for Confidential Computing. https:\/\/confidentialcomputing.io\/2024\/04\/10\/the-cia-triad-for-confidential-computing\/"},{"key":"e_1_3_2_2_13_1","unstructured":"Cybersecurity and Infrastructure Security Agency. 2020. Emergency Directive 21-01: SolarWinds Orion Code Compromise. https:\/\/cyber.dhs.gov\/ed\/21-01\/"},{"key":"e_1_3_2_2_14_1","unstructured":"NVD National Vulnerability Database. 2024. CVE-2024-3094: Backdoor in XZ Utils. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-3094"},{"key":"e_1_3_2_2_15_1","volume-title":"Swiss cheese to cheddar: securing AMD SEV-SNP early boot. https:\/\/www.decentriq.com\/article\/swiss-cheese-to-cheddar-securing-amd-sev-snp-early-boot Accessed on","year":"2025","unstructured":"Decentriq. 2024. Swiss cheese to cheddar: securing AMD SEV-SNP early boot. https:\/\/www.decentriq.com\/article\/swiss-cheese-to-cheddar-securing-amd-sev-snp-early-boot Accessed on February 02, 2025."},{"key":"e_1_3_2_2_16_1","unstructured":"Ansible Documentation. 2023. Security Best Practices \u2014 Ansible Tower Administration Guide. https:\/\/docs.ansible.com\/ansible-tower\/latest\/html\/administration\/security_best_practices.html Accessed: 2025-03-13."},{"key":"e_1_3_2_2_17_1","unstructured":"Kubernetes Documentation. 2024. Network Policies. https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/network-policies\/ Accessed: 2025-03-13."},{"key":"e_1_3_2_2_18_1","unstructured":"eBPF Top. 2024. Practical Guide to LSM BPF. https:\/\/www.ebpf.top\/en\/post\/lsm_bpf_intro\/ Accessed: 2025-03-10."},{"key":"e_1_3_2_2_19_1","unstructured":"eBPF.io. 2024. What is eBPF? An Introduction and Deep Dive into the eBPF Technology. https:\/\/ebpf.io\/what-is-ebpf\/ Accessed: 2025-03-10."},{"key":"e_1_3_2_2_20_1","unstructured":"eSecurity Planet. 2023. Multi-Tenancy Cloud Security: Definition & Best Practices. (2023). https:\/\/www.esecurityplanet.com\/cloud\/multi-tenancy-cloud-security\/"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13677-015-0042-8"},{"key":"e_1_3_2_2_22_1","volume-title":"Linux Plumbers Conference 2024","author":"Fang Peter","year":"2024","unstructured":"Peter Fang, Chuanxiao Dong, and Jiewen Yao. 2024. Intel TD Partitioning and vTPM on COCONUT-SVSM. Linux Plumbers Conference 2024. https:\/\/lpc.events\/event\/18\/contributions\/1918\/attachments\/1632\/3406\/02-lpc2024_mc_tdp_vtpm.pdf Presentation."},{"key":"e_1_3_2_2_23_1","volume-title":"Arm's Confidential Compute Architecture Reference Attestation Token. Internet-Draft draft-ffm-rats-cca-token-02. IETF. https:\/\/datatracker.ietf.org\/doc\/draft-ffm-rats-cca-token\/ Work in Progress","author":"Frost Simon","year":"2026","unstructured":"Simon Frost, Thomas Fossati, and Giridhar Mandyam. 2025. Arm's Confidential Compute Architecture Reference Attestation Token. Internet-Draft draft-ffm-rats-cca-token-02. IETF. https:\/\/datatracker.ietf.org\/doc\/draft-ffm-rats-cca-token\/ Work in Progress; Expires 2026-03-06."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3590140.3629124"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","unstructured":"Stefan Gast Hannes Weissteiner Robin Schr\u00f6der and Daniel Gruss. 2025. CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNP. 10.14722\/ndss.2025.241038","DOI":"10.14722\/ndss.2025.241038"},{"key":"e_1_3_2_2_26_1","unstructured":"Noah H. 2024. Kubernetes Network Security: Exploring Cilium & Istio. https:\/\/medium.com\/@noah_h\/on-kubernetes-network-security-exploring-cilium-and-istio-implementations-ba687b685d26 Accessed: 2025-03-13."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"crossref","unstructured":"Daniel Hugenroth Mario Lins Ren\u00e9 Mayrhofer and Alastair Beresford. 2025. Attestable builds: compiling verifiable binaries on untrusted systems using trusted execution environments. arXiv:2505.02521 [cs.CR] https:\/\/arxiv.org\/abs\/2505.02521","DOI":"10.1145\/3719027.3765128"},{"key":"e_1_3_2_2_28_1","unstructured":"IMA Documentation. 2025. IMA and EVM Concepts. https:\/\/ima-doc.readthedocs.io\/en\/latest\/ima-concepts.html Accessed: 2025-03-10."},{"key":"e_1_3_2_2_29_1","unstructured":"Intel Corporation. 2022. Intel\u00ae Trust Domain Extensions. https:\/\/cdrdv2-public.intel.com\/690419\/TDX-Whitepaper-February2022.pdf"},{"key":"e_1_3_2_2_30_1","unstructured":"Intel Corporation. 2023. Intel Trust Domain Extensions (TDX) Architecture Specification. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-trust-domain-extensions.html. Accessed: 2025-09-14."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3686261"},{"key":"e_1_3_2_2_32_1","volume-title":"A Review of the SolarWinds Attack on Orion Platform using Persistent Threat Agents and Techniques for Gaining Unauthorized Access. arXiv preprint arXiv:2308.10294 (August","author":"Kruti Antigoni","year":"2023","unstructured":"Antigoni Kruti, Usman Butt, and Rejwan Bin Sulaiman. 2023. A Review of the SolarWinds Attack on Orion Platform using Persistent Threat Agents and Techniques for Gaining Unauthorized Access. arXiv preprint arXiv:2308.10294 (August 2023). https:\/\/arxiv.org\/pdf\/2308.10294"},{"key":"e_1_3_2_2_33_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Li Mengyuan","year":"2021","unstructured":"Mengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li, and Yueqiang Cheng. 2021. CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side Channel. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 717\u2013732. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/li-mengyuan"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486976"},{"key":"e_1_3_2_2_35_1","unstructured":"Linode. 2023. Use Cloud-Init to Automatically Configure and Secure Your Servers. https:\/\/www.linode.com\/docs\/guides\/configure-and-secure-servers-with-cloud-init\/ Accessed: 2025-03-13."},{"key":"e_1_3_2_2_36_1","unstructured":"Linux Kernel. 2024. TDX Guest Attestation Documentation. https:\/\/docs.kernel.org\/virt\/coco\/tdx-guest.html. Accessed: 2025-09-14."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD60044.2023.00073"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEED51797.2021.00025"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627112"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560620"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD53861.2021.00013"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER-C62648.2024.00023"},{"key":"e_1_3_2_2_43_1","volume-title":"Linux Security: Keeping Linux Machines Secure with Less Tinkering. https:\/\/www.puppet.com\/blog\/linux-security Accessed: 2025-03-13.","year":"2024","unstructured":"Puppet. 2024. Linux Security: Keeping Linux Machines Secure with Less Tinkering. https:\/\/www.puppet.com\/blog\/linux-security Accessed: 2025-03-13."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765209"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3453930"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3115438"},{"key":"e_1_3_2_2_47_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security '25)","author":"Shi Jiacheng","year":"2025","unstructured":"Jiacheng Shi, Jiongyi Gu, Yubin Xia, and Haibo Chen. 2025. Serverless Functions Made Confidential and Efficient with Split Containers. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security '25). USENIX Association. https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity25\/sec25cycle1-prepub-121-shi-jiacheng.pdf"},{"key":"e_1_3_2_2_48_1","unstructured":"Xupeng Li Xuheng Li Christoffer Dall Ronghui Gu Jason Nieh and Yousuf Sait. Enabling Realms with the Arm Confidential Compute Architecture. https:\/\/www.usenix.org\/sites\/default\/files\/login2023_cca.pdf"},{"key":"e_1_3_2_2_49_1","volume-title":"Breaking Down the Codecov Attack: Finding a Malicious Needle in a Code Haystack. CyberArk Blog (April","author":"Stoler Nimrod","year":"2021","unstructured":"Nimrod Stoler. 2021. Breaking Down the Codecov Attack: Finding a Malicious Needle in a Code Haystack. CyberArk Blog (April 2021). https:\/\/www.cyberark.com\/resources\/blog\/breaking-down-the-codecov-attack-finding-a-malicious-needle-in-a-code-haystack"},{"key":"e_1_3_2_2_50_1","unstructured":"SUSE. 2024. Security and Hardening Guide | Understanding Linux audit. https:\/\/documentation.suse.com\/de-de\/sles\/15-SP6\/html\/SLES-all\/cha-audit-comp.html. Accessed on February 7 2025."},{"key":"e_1_3_2_2_51_1","unstructured":"Tetrate. 2023. Simplify Kubernetes Security with the Service Mesh. https:\/\/tetrate.io\/blog\/simplify-kubernetes-security-with-the-service-mesh\/ Accessed: 2025-03-13."},{"key":"e_1_3_2_2_52_1","unstructured":"The Linux Kernel Documentation. 2025. BPF Documentation -The Linux Kernel Documentation. https:\/\/docs.kernel.org\/bpf\/ Accessed: 2025-03-10."},{"key":"e_1_3_2_2_53_1","unstructured":"The Linux Kernel Documentation. 2025. Linux Security Modules: General Security Hooks for Linux. https:\/\/docs.kernel.org\/security\/lsm.html Accessed: 2025-03-10."},{"key":"e_1_3_2_2_54_1","unstructured":"The Linux Kernel Documentation. 2025. LSM BPF Programs - The Linux Kernel Documentation. https:\/\/docs.kernel.org\/bpf\/prog_lsm.html Accessed: 2025-03-10."},{"key":"e_1_3_2_2_55_1","volume-title":"Gerald Budigiri, Mykyta Petik, and Eddy Truyen.","author":"G\u00fclmez Merve","year":"2021","unstructured":"Merve G\u00fclmez, Gianluca Scopelliti, Christoph Baumann, Jan Tobias M\u00fchlberg, Gerald Budigiri, Mykyta Petik, and Eddy Truyen. 2021. The Trust Model for Multi-Tenant 5G Telecom Systems running Virtualized Multi-component services. In MSCA ITN EID 5GhOSTS Public Deliverable. https:\/\/lirias.kuleuven.be\/retrieve\/702952"},{"key":"e_1_3_2_2_56_1","unstructured":"TuxCare. 2025. AppArmor vs SELinux: Compare the Differences in Linux Security. https:\/\/tuxcare.com\/blog\/selinux-vs-apparmor\/ Accessed: 2025-03-13."},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2023.3237100"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2749469.2750422"},{"key":"e_1_3_2_2_59_1","volume-title":"VeriSMo: A Verified Security Module for Confidential VMs. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24)","author":"Zhou Ziqiao","year":"2024","unstructured":"Ziqiao Zhou, Anjali, Weiteng Chen, Sishuai Gong, Chris Hawblitzel, and Weidong Cui. 2024. VeriSMo: A Verified Security Module for Confidential VMs. In 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24). USENIX Association, Santa Clara, CA, 599\u2013614. https:\/\/www.usenix.org\/conference\/osdi24\/presentation\/zhou"}],"event":{"name":"Middleware '25: 26th International Middleware Conference","location":"Vanderbilt University Nashville TN USA","acronym":"MIDDLEWARE '25","sponsor":["IFIP","Usenix"]},"container-title":["Proceedings of the 26th International Middleware Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3721462.3770778","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,2]],"date-time":"2026-02-02T06:15:27Z","timestamp":1770012927000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3721462.3770778"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,14]]},"references-count":59,"alternative-id":["10.1145\/3721462.3770778","10.1145\/3721462"],"URL":"https:\/\/doi.org\/10.1145\/3721462.3770778","relation":{},"subject":[],"published":{"date-parts":[[2025,12,14]]},"assertion":[{"value":"2025-12-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}