Confidential Analytics with Scylla

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

While security concerns of data at rest and in transit have been addressed over the years using standard cryptographic measures, those surrounding data in use have garnered significant attention in recent times. In response, various trusted execution environments (TEEs) have been proposed and are on offer from leading public cloud providers. With development and re-programming efforts, availability, threat models, pricing, performance, etc., differing between various TEEs themselves and also with viable alternatives such as software solutions like partially homomorphic encryption (PHE) to protect data in use, it is imperative to have a system that is independent of these several varying dimensions while also efficiently achieving end-to-end confidentiality guarantees on data processing.We propose Scylla, a mechanism-agnostic confidential analytics framework, built on top of the popular Spark data analytics engine. Scylla utilizes a customizable combination of TEEs and PHE schemes to achieve end-to-end confidentiality guarantees with prime performance. Our evaluation shows that Scylla's query execution times are 1.91× faster than state-of-the-art system Opaque providing similar guarantees. Scylla's novel general architecture enables integrating latest TEEs such as AWS Nitro, AMD SEV-SNP, and Intel TDX with zero rebuilding efforts.

Original languageEnglish
Title of host publicationSoCC 2025 - Proceedings of the 2025 ACM Symposium on Cloud Computing
PublisherAssociation for Computing Machinery, Inc
Pages29-44
Number of pages16
ISBN (Electronic)9798400722769
DOIs
Publication statusPublished - 13 Jan 2026
Event2025 ACM Symposium on Cloud Computing, SoCC 2025 - Virtual, Online, United States
Duration: 19 Nov 202521 Nov 2025

Publication series

NameSoCC 2025 - Proceedings of the 2025 ACM Symposium on Cloud Computing

Conference

Conference2025 ACM Symposium on Cloud Computing, SoCC 2025
Country/TerritoryUnited States
CityVirtual, Online
Period19/11/2521/11/25

Keywords

  • Confidential Computing
  • Nitro enclave
  • PHE
  • SEV-SNP
  • SGX
  • TDX

Fingerprint

Dive into the research topics of 'Confidential Analytics with Scylla'. Together they form a unique fingerprint.

Cite this