Galanou A, Lubitz F, Jeon H, Fetzer C, Kapitza R (2025)
Publication Language: English
Publication Type: Conference contribution, Original article
Publication year: 2025
Publisher: Association for Computing Machinery
Series: Proceedings of the 26th International Middleware Conference
City/Town: New York, NY, USA
Pages Range: 369–382
Event location: Vanderbilt University, Nashville, TN, USA
Open Access Link: https://doi.org/10.1145/3721462.3770778
Although confidential virtual machines (CVMs) offer strong isolation in untrusted cloud environments, their attestation mechanisms are restricted to static boot-time measurements. This means they cannot capture the detailed post-boot state necessary for real-world deployments. Modern workloads demand context-specific trust decisions that vary across verifiers, operational stages and workloads, like software supply chains or cloud-native workload deployments.In this paper, we present a flexible policy-driven attestation and configuration architecture that enables verifier-specific evidence generation across different stages of a CVM's lifecycle, without requiring changes to the guest OS or container workflows as previous approaches. Our system uses eBPF and Linux Security Module hooks to capture in-guest signals under dynamic policies, allowing flexible and context-aware attestation of runtime properties or post-boot configuration state. We demonstrate its utility in two use cases: (i) attesting confidential build pipelines with cryptographically linked Software Bill of Materials and artifacts, and (ii) enabling verifiable post-boot contextualization for multi-tenant CVMs. Built on AMD SEV-SNP, our prototype achieves low overhead and seamless integration, offering a practical trust layer that advances attestation for secure software supply chains and dynamic cloud workloads.
APA:
Galanou, A., Lubitz, F., Jeon, H., Fetzer, C., & Kapitza, R. (2025). Full Trust Alchemist: Reforging Attestation for Cloud-based Confidential Workloads. In Association for Computing Machinery (Eds.), Proceedings of the Proceedings of the 26th International Middleware Conference (pp. 369–382). Vanderbilt University, Nashville, TN, USA, US: New York, NY, USA: Association for Computing Machinery.
MLA:
Galanou, Anna, et al. "Full Trust Alchemist: Reforging Attestation for Cloud-based Confidential Workloads." Proceedings of the Proceedings of the 26th International Middleware Conference, Vanderbilt University, Nashville, TN, USA Ed. Association for Computing Machinery, New York, NY, USA: Association for Computing Machinery, 2025. 369–382.
BibTeX: Download