CRC: Fully General Model of Confidential Remote Computing
Kubilay Ahmet K\"u\c{c}\"uk, Andrew Martin

TL;DR
The paper introduces CRC, a comprehensive model for confidential remote computing that leverages hardware security, trusted software control, and attestation evidence to enhance trustworthiness in remote digital services.
Contribution
It presents a novel, unified CRC model integrating hardware primitives, trusted software, and attestation, offering a new framework for secure remote computing systems.
Findings
CRC balances decentralization and transparency overhead.
The model demonstrates effective use of hardware-based security primitives.
Lessons learned inform future research directions.
Abstract
Digital services have been offered through remote systems for decades. The questions of how these systems can be built in a trustworthy manner and how their security properties can be understood are given fresh impetus by recent hardware developments, allowing a fuller, more general, exploration of the possibilities than has previously been seen in the literature. Drawing on and consolidating the disparate strains of research, technologies and methods employed throughout the adaptation of confidential computing, we present a novel, dedicated Confidential Remote Computing (CRC) model. CRC proposes a compact solution for next-generation applications to be built on strong hardware-based security primitives, control of secure software products' trusted computing base, and a way to make correct use of proofs and evidence reports generated by the attestation mechanisms. The CRC model…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Advanced Malware Detection Techniques · Cloud Data Security Solutions
