Secure Privacy Control inside Clouds with AMD SEV and Nested Virtualization
Naoya Ando, Kazuki Takiguchi, Kenichi Kourai · 2025
The leakage of personal data from public clouds has been a major issue in recent years. As cloud services become increasingly complex, e.g., using microservices and multicloud, personal data can be distributed to various services. However, the details of data flow inside clouds are not disclosed to users. Therefore, users cannot know how their personal data is processed and stored. To regain control of personal data, users need a privacy control mechanism for clouds, but the mechanism provided by clouds cannot be trusted. This paper proposes SEV-tracker for enabling secure privacy control inside clouds using a processor-based trusted execution environment (TEE). SEV-tracker injects a user hypervisor into a cloud virtual machine (VM). Using nested virtualization, the user hypervisor runs a cloud service in a user VM created on top of it and tracks and controls the data flow of the service. To mutually protect the user hypervisor and the cloud from each other, SEV-tracker applies AMD SEV to both VMs. We have implemented SEV-tracker using BitVisor as a lightweight user hypervisor and unikernels as cloud services to mitigate the overhead of nested virtualization. We conducted several experiments and examined the effectiveness of SEV-tracker.