Intel(r) Software Guard Extensions (SGX) was originally released on client platforms and later extended to single socket server platforms. As developers have become familiar with the capabilities of the technology, the applicability of this capability in the cloud has been tested. Various Cloud Service Providers (CSPs) are demonstrating the value of using SGX based Trusted Execution Environments (TEE) to create a new paradigm of Confidential Cloud Computing. This paper describes the additional platform enhancements we believe are necessary to deliver a user programmable Trusted Execution Environment that scales to cloud usages, performs and is secure on multi-package platforms.
翻译:Intel® 软件防护扩展(SGX)最初发布于客户端平台,随后扩展到单路服务器平台。随着开发者对该技术功能日益熟悉,其在云环境中的适用性已得到验证。多家云服务提供商正展示基于SGX的可信执行环境在构建新型机密云计算范式方面的价值。本文阐述了我们认为必要的额外平台增强方案,旨在提供可扩展至云应用场景、具备高性能且能在多封装平台上安全运行的用户可编程可信执行环境。