Using recursive attestation to scale trust in modern heterogeneous cloud architectures
File(s) fractos-attestation.pdf (738.38 KB)
Published version
Author(s)
Jing, Yaoxin
Steiner, Michael
Vahldiek-Oberwagner, Anjo
Vij, Mona
Vilanova, Lluis
Type
Conference Paper
Abstract
Modern cloud infrastructures are increasingly complex, driven by heterogeneity, disaggregation, and dynamic service composition—exposing critical limits in traditional attestation models. These models struggle to scale when trust must span multiple domains and elastic services. We present scale-out attestation, a paradigm decoupling platform trust verification from app-level attestation. Our design introduces a recursive attestation framework leveraging abstract service identities and trusted deployment workflows: a single infrastructure agent verifies platforms via abstract policies, while services derive instance-agnostic identities enabling secure recursive dependency attestation. We implement the system on FractOS, a distributed OS for disaggregated data centers, and plan to extend Confidential Containers for practical deployment. Evaluation shows strong security with minimal overhead, enabling scalable confidential computing across heterogeneous and dynamic cloud environments.
Date Issued
2025-10-11
Date Acceptance
2025-08-04
Citation
APSys '25: Proceedings of the 16th ACM SIGOPS Asia-Pacific Workshop on Systems, 2025, pp.185-193
ISBN
979-8-4007-1572-3
Start Page
185
End Page
193
Journal / Book Title
APSys '25: Proceedings of the 16th ACM SIGOPS Asia-Pacific Workshop on Systems
Copyright Statement
Copyright © 2025 Copyright held by the owner/author(s). This work is licensed under Creative Commons Attribution International 4.0 (http://creativecommons.org/licenses/by/4.0/)
License URL
Source
16th ACM SIGOPS Asia-Pacific Workshop on Systems
Publication Status
Published
Start Date
2025-10-12
Finish Date
2025-10-13
Coverage Spatial
Seoul, Korea
