One could try to address this by having a key for every conference, but this creates key distribution problems. Moreover, this approach (whether by global key or per-conference key) requires and relies on preventing the cloud provider from submitting a paper to the conference (since authors are entitled to the secret key). Another problem is that the cloud server cannot send mail to authors and reviewers, since their identities and the contents of the mail are all held in encrypted form. This might be solved by having a mail agent that knows the secret key and is able to receive encrypted mailing instructions and process them. However, the mail agent and the cloud server could conspire to decrypt everything.