发表机构
SUSTech(南方科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对传统TEE远程证明与交互式开发工作流的冲突,该研究提出INTCC交互式机密计算框架,通过逻辑划分TEE和三大核心机制,在保障数据机密性的同时支持动态交互操作,且开销处于实用水平。
AI 中文摘要
机密计算利用可信执行环境(Trusted Execution Environments,TEEs)保障使用中数据的机密性与完整性。然而,TEEs依赖远程证明来确保其初始内存状态的完整性,该模式与交互式开发工作流存在根本性冲突。在大语言模型(LLM)微调、探索性数据分析等场景中,数据处理方需要人在回路能力,包括动态代码注入、中间状态检查和超参数调优,而这些操作本质上都违背了传统远程证明的静态一次性完整性保证。\n为调和这一矛盾,我们提出交互式机密计算范式,这是一种支持不可信数据处理方在不损害数据机密性的前提下,在TEEs内执行动态、非确定性操作的系统架构。基于“本质上不可度量的人类交互必须被排除在可信计算基(Trusted Computing Base,TCB)之外”的核心洞见,我们将TEE在逻辑上划分为交互式控制器和可验证运行时。为实现该范式,我们提出INTCC框架,它包含三大核心机制:(1)基于代理的调度系统,可保留原生开发体验;(2)基于安全格的细粒度信息流控制机制,用于防止数据泄露;(3)隐私保护的可验证执行机制,用于保障动态工作流的运行时合规性。我们基于机密容器在AMD SEV-SNP上实现了INTCC,并在多种真实工作负载下对其进行评估。实验表明,INTCC有效平衡了安全性与交互性:与基线执行相比,其在LLM微调任务中的实际开销低于5%,在数据分析任务中的开销低于17%。
英文摘要
Confidential computing leverages Trusted Execution Environments (TEEs) to ensure the confidentiality and integrity of data in use. However, TEEs rely on remote attestation to guarantee the integrity of their initial memory state. This model is fundamentally at odds with interactive development workflows. In scenarios like LLM fine-tuning and exploratory data analysis, data processors need human-in-the-loop capabilities, including dynamic code injection, intermediate state inspection, and hyperparameter tuning, all of which inherently violate the static, one-time integrity guarantees of traditional remote attestation. To reconcile this tension, we propose the interactive confidential computing paradigm, a system architecture enabling untrusted data processors to execute dynamic, non-deterministic operations within TEEs without compromising data confidentiality. Driven by the insight that inherently unmeasurable human interaction must be excluded from the Trusted Computing Base (TCB), we logically partition the TEE into an interactive controller and a verifiable runtime. To realize this paradigm, we present INTCC, a framework featuring three key mechanisms: (1) a proxy-based dispatch system to preserve the native development experience; (2) a fine-grained information flow control mechanism based on a security lattice to prevent data leakage; and (3) a privacy-preserving verifiable execution mechanism to guarantee the runtime compliance of dynamic workflows. We implement INTCC on AMD SEV-SNP using Confidential Containers and evaluate it across diverse real-world workloads. Our experiments demonstrate that INTCC effectively balances security and interactivity, incurring a practical overhead of less than 5% for LLM fine-tuning and under 17% for data analysis relative to baseline execution.