Cloudy with a Chance of Betrayal: A Critical Examination of Confidential Computing in Public Clouds

Wednesday 09 April 2025


In a world where data is king, ensuring its security and confidentiality has become a top priority. With the rise of cloud computing, storing sensitive information online has become increasingly common. However, this shift has also introduced new challenges in protecting that data from unauthorized access.


To combat these concerns, researchers have been exploring ways to create virtual environments within the cloud that can securely store and process sensitive information. One such approach is the use of Confidential Virtual Machines (CVMs), which aim to provide an isolated and secure space for executing workloads.


The paper in question delves into the world of CVMs, specifically focusing on their limitations and challenges. The authors analyze four major cloud providers – Amazon Web Services, Microsoft Azure, Google Cloud Platform, and IBM Cloud – examining their Confidential Computing offerings. They found that while these solutions claim to provide secure execution environments, they often fall short in meeting the promises.


One of the main issues is the lack of control over critical components within the CVMs. Cloud providers retain significant influence over key aspects, such as firmware and software updates, which can compromise the security of the virtual environment. Furthermore, the authors discovered that some solutions rely on unverifiable components, further eroding trust.


The study also highlights the importance of remote attestation, a mechanism used to verify the integrity and authenticity of the CVMs. However, current implementations often fail to provide sufficient evidence or transparency, making it difficult for users to ensure their data is being handled correctly.


The authors propose a new taxonomy to evaluate CVM solutions, taking into account factors such as identity establishment, runtime measurements, and customizability. This framework aims to provide a more comprehensive understanding of the strengths and weaknesses of each offering.


The findings suggest that current Confidential Computing solutions are not yet ready for widespread adoption. While they may offer some level of security, they often lack transparency and control, leaving users vulnerable to potential risks.


In light of these discoveries, researchers emphasize the need for more robust and transparent CVM solutions that can truly guarantee the confidentiality and integrity of sensitive data. The development of such technologies will be crucial in ensuring the continued trustworthiness of cloud-based services.


Ultimately, this study serves as a wake-up call for both researchers and cloud providers to rethink their approaches to Confidential Computing. By acknowledging the limitations and challenges, we can work towards creating more secure and reliable virtual environments that can confidently store and process sensitive information.


Cite this article: “Cloudy with a Chance of Betrayal: A Critical Examination of Confidential Computing in Public Clouds”, The Science Archive, 2025.


Cloud Computing, Confidential Virtual Machines, Cloud Security, Data Protection, Virtual Environments, Secure Execution, Remote Attestation, Integrity, Authentication, Transparency


Reference: Jana Eisoldt, Anna Galanou, Andrey Ruzhanskiy, Nils Küchenmeister, Yewgenij Baburkin, Tianxiang Dai, Ivan Gudymenko, Stefan Köpsell, Rüdiger Kapitza, “SoK: A cloudy view on trust relationships of CVMs — How Confidential Virtual Machines are falling short in Public Cloud” (2025).


Leave a Reply