Authors:
Tommaso Cucinotta
1
;
Davide Cherubini
2
and
Eric Jul
3
Affiliations:
1
Alcatel-Lucent, Ireland
;
2
Alcatel-Lucent Ireland, Ireland
;
3
Alcatel Lucent, Ireland
Keyword(s):
Security, Cloud Computing, Confidentiality.
Related
Ontology
Subjects/Areas/Topics:
Cloud Computing
;
Cloud Computing Architecture
;
Cloud Computing Enabling Technology
;
Fundamentals
;
Mobile Cloud Computing and Services
;
Security Issues in Mobile Systems Software and Hardware
;
Security, Privacy, and Compliance Management
;
Services Science
;
Services Security and Reliability
Abstract:
In this paper, we present Confidential Domain of Execution (CDE), a mechanism for achieving confidential execution of software in an otherwise untrusted environment, e.g., at a Cloud Service Provider. This is achieved by using an isolated execution environment in which any communication with the outside untrusted world is forcibly encrypted by trusted hardware. The mechanism can be useful to overcome the challenging issues in guaranteeing confidential execution in virtualized infrastructures, including cloud computing and virtualized network functions, among other scenarios. Moreover, the proposed mechanism does not suffer from the performance drawbacks typical of other solutions proposed for secure computing, as highlighted by the presented novel validation results.