Trusted Cloud Enclaves and Security Governance for High-Assurance Cloud Computing

Fuente: Zenodo
Enregistré dans:
Détails bibliographiques
Auteur principal: Bolignano, Dominique
Format: Recurso digital
Langue:anglais
Publié: Zenodo 2026
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866901876682784768
author Bolignano, Dominique
author_facet Bolignano, Dominique
contents <p><span>Cloud computing infrastructures have become the dominant platform for modern digital systems. Governments, industries and technology companies increasingly rely on cloud environments to host critical workloads, including financial systems, industrial platforms and artificial intelligence infrastructures.</span></p> <p><span>However, the migration of sensitive workloads to the cloud raises a fundamental challenge: how to trust the infrastructure executing these workloads.</span></p> <p><span>Traditional security approaches address only part of this problem. Cryptographic mechanisms protect sensitive data, while Trusted Execution Environments aim to isolate computations. Organizational frameworks and sovereign cloud initiatives improve operational governance of cloud infrastructures.</span></p> <p><span>Despite these advances, the core architectural challenge remains unresolved: establishing strong trust guarantees for workloads executed on complex infrastructures that cannot be entirely verified.</span></p> <p><span>In previous work we introduced the concept of Trusted Security Governance Platforms (TSGP), programmable trust anchors capable of governing security-critical operations across complex digital ecosystems.</span></p> <p><span>This paper introduces ProvenCloud, an architecture applying these principles to cloud infrastructures through the concept of Trusted Cloud Enclaves (TCE).</span></p> <p><span>Trusted Cloud Enclaves establish controlled execution perimeters around compute environments such as virtual machines, container clusters or bare-metal nodes. These enclaves act as trusted governance components mediating interactions between sensitive workloads and the surrounding infrastructure.</span></p> <p><span>By concentrating security-critical functions within minimal and strongly verifiable components, the architecture enables independent governance of infrastructure interactions while drastically reducing the trusted computing base of the execution environment</span><span>.</span></p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19443532
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Trusted Cloud Enclaves and Security Governance for High-Assurance Cloud Computing
Bolignano, Dominique
Trusted Cloud Enclave
Cloud Security
Trusted Security Governance Platform
Reference Monitor
High-Assurance Systems
Confidential Computing
Secure Cloud Architecture
Security Governance
Supply Chain Security
Infrastructure Security
Secure Execution Environments
<p><span>Cloud computing infrastructures have become the dominant platform for modern digital systems. Governments, industries and technology companies increasingly rely on cloud environments to host critical workloads, including financial systems, industrial platforms and artificial intelligence infrastructures.</span></p> <p><span>However, the migration of sensitive workloads to the cloud raises a fundamental challenge: how to trust the infrastructure executing these workloads.</span></p> <p><span>Traditional security approaches address only part of this problem. Cryptographic mechanisms protect sensitive data, while Trusted Execution Environments aim to isolate computations. Organizational frameworks and sovereign cloud initiatives improve operational governance of cloud infrastructures.</span></p> <p><span>Despite these advances, the core architectural challenge remains unresolved: establishing strong trust guarantees for workloads executed on complex infrastructures that cannot be entirely verified.</span></p> <p><span>In previous work we introduced the concept of Trusted Security Governance Platforms (TSGP), programmable trust anchors capable of governing security-critical operations across complex digital ecosystems.</span></p> <p><span>This paper introduces ProvenCloud, an architecture applying these principles to cloud infrastructures through the concept of Trusted Cloud Enclaves (TCE).</span></p> <p><span>Trusted Cloud Enclaves establish controlled execution perimeters around compute environments such as virtual machines, container clusters or bare-metal nodes. These enclaves act as trusted governance components mediating interactions between sensitive workloads and the surrounding infrastructure.</span></p> <p><span>By concentrating security-critical functions within minimal and strongly verifiable components, the architecture enables independent governance of infrastructure interactions while drastically reducing the trusted computing base of the execution environment</span><span>.</span></p>
title Trusted Cloud Enclaves and Security Governance for High-Assurance Cloud Computing
topic Trusted Cloud Enclave
Cloud Security
Trusted Security Governance Platform
Reference Monitor
High-Assurance Systems
Confidential Computing
Secure Cloud Architecture
Security Governance
Supply Chain Security
Infrastructure Security
Secure Execution Environments
url https://doi.org/10.5281/zenodo.19443532