INTCC: A Framework for Interactive Confidential Computing

๐Ÿ“… 2026-09-28
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This study addresses the inherent tension between data confidentiality and dynamic debugging in traditional confidential computing. We propose an interactive confidential computing paradigm that decouples Trusted Execution Environment (TEE) logic into an interaction controller and a verifiable runtime, pioneering the exclusion of unmeasurable humanโ€“computer interactions from the trusted computing base. Built upon AMD SEV-SNP and Confidential Containers, the system enables secure dynamic execution by integrating proxy scheduling, lattice-based information flow control, and privacy-preserving verification mechanisms. Experimental evaluations on large language model fine-tuning and analytical workloads demonstrate performance overheads of merely 5% to 17%, effectively reconciling stringent security guarantees with practical interactivity requirements.
๐Ÿ“ Abstract
Confidential computing leverages Trusted Execution Environments (TEEs) to ensure the confidentiality and integrity of data in use. However, TEEs rely on remote attestation to guarantee the integrity of their initial memory state. This model is fundamentally at odds with interactive development workflows. In scenarios like LLM fine-tuning and exploratory data analysis, data processors need human-in-the-loop capabilities, including dynamic code injection, intermediate state inspection, and hyperparameter tuning, all of which inherently violate the static, one-time integrity guarantees of traditional remote attestation. To reconcile this tension, we propose the interactive confidential computing paradigm, a system architecture enabling untrusted data processors to execute dynamic, non-deterministic operations within TEEs without compromising data confidentiality. Driven by the insight that inherently unmeasurable human interaction must be excluded from the Trusted Computing Base (TCB), we logically partition the TEE into an interactive controller and a verifiable runtime. To realize this paradigm, we present INTCC, a framework featuring three key mechanisms: (1) a proxy-based dispatch system to preserve the native development experience; (2) a fine-grained information flow control mechanism based on a security lattice to prevent data leakage; and (3) a privacy-preserving verifiable execution mechanism to guarantee the runtime compliance of dynamic workflows. We implement INTCC on AMD SEV-SNP using Confidential Containers and evaluate it across diverse real-world workloads. Our experiments demonstrate that INTCC effectively balances security and interactivity, incurring a practical overhead of less than 5% for LLM fine-tuning and under 17% for data analysis relative to baseline execution.
Problem

Research questions and friction points this paper is trying to address.

Confidential Computing
Trusted Execution Environments
Remote Attestation
Interactive Workflows
Human-in-the-loop
Innovation

Methods, ideas, or system contributions that make the work stand out.

Confidential Computing
Trusted Execution Environment
Interactive Workflow
Information Flow Control
Verifiable Execution
๐Ÿ’ผ Related Jobs
No related jobs found.