Skip to content

Proposal: Verifiable Confidential Execution for MemPrivacy #4

Description

@Jasonmils

Problem

MemPrivacy currently protects sensitive data primarily through local detection and pseudonymization. However:

  1. Privacy detection is probabilistic and may miss sensitive spans.
  2. Users still need to trust the remote service not to inspect or retain plaintext that passes through.
  3. Open-source code alone cannot prove that the same code is running in production.

Proposal

Add an optional Confidential Execution Mode based on TEE + Remote Attestation.

Client
  │
  ├─ Verify remote attestation
  ├─ Verify expected workload measurement
  │
  └─ Encrypt request with attested public key
              ↓
       ┌─────────────┐
       │     TEE     │
       │ MemPrivacy  │
       │ Processing  │
       └─────────────┘
              ↓
       Encrypted result

The client should only release sensitive data or encryption keys after verifying that:

  • the workload is running inside a supported TEE;
  • its code measurement matches an approved build;
  • debug mode is disabled.

Why

This changes MemPrivacy's security model from:

"Sensitive information is unlikely to leave the client if correctly detected."

to:

"Even if sensitive information reaches the server, the infrastructure operator cannot directly access it."

A minimal first implementation could target one backend such as AWS Nitro Enclaves, keeping the existing local redaction pipeline unchanged.

This would make privacy defense-in-depth rather than dependent solely on detection accuracy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions