English

Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High Availability

Cryptography and Security 2023-10-19 v1 Distributed, Parallel, and Cluster Computing

Abstract

Confidentiality, integrity protection, and high availability, abbreviated to CIA, are essential properties for trustworthy data systems. The rise of cloud computing and the growing demand for multiparty applications however means that building modern CIA systems is more challenging than ever. In response, we present the Confidential Consortium Framework (CCF), a general-purpose foundation for developing secure stateful CIA applications. CCF combines centralized compute with decentralized trust, supporting deployment on untrusted cloud infrastructure and transparent governance by mutually untrusted parties. CCF leverages hardware-based trusted execution environments for remotely verifiable confidentiality and code integrity. This is coupled with state machine replication backed by an auditable immutable ledger for data integrity and high availability. CCF enables each service to bring its own application logic, custom multiparty governance model, and deployment scenario, decoupling the operators of nodes from the consortium that governs them. CCF is open-source and available now at https://github.com/microsoft/CCF.

Keywords

Cite

@article{arxiv.2310.11559,
  title  = {Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High Availability},
  author = {Heidi Howard and Fritz Alder and Edward Ashton and Amaury Chamayou and Sylvan Clebsch and Manuel Costa and Antoine Delignat-Lavaud and Cedric Fournet and Andrew Jeffery and Matthew Kerner and Fotios Kounelis and Markus A. Kuppe and Julien Maffre and Mark Russinovich and Christoph M. Wintersteiger},
  journal= {arXiv preprint arXiv:2310.11559},
  year   = {2023}
}

Comments

16 pages, 9 figures. To appear in the Proceedings of the VLDB Endowment, Volume 17

R2 v1 2026-06-28T12:53:48.497Z