A
computer program product for enabling
processing within a
data processing environment, wherein the
computer program product comprises: comprising at least one computer-readable storage medium that is readable by at least one
processing circuit and stores instructions for carrying out a procedure: Binding at least one secure object of a security module (150) of the
data processing environment to a secure guest (180) of the
data processing environment, wherein the secure guest is configured to use the security module (150), and wherein the binding has: Determine (300) through a trusted component (160) of the data
processing environment whether
metadata of the secure guest (180) contains a confidential binding attribute for the security module (150), wherein the confidential binding attribute is to be used to bind the one or more secure objects generated by the security module (150) to the secure guest (180), wherein the security module (150) is separate from the trusted component and is assigned to the secure guest (180) via a
hypervisor (170); Configure (304) by the trusted component (160) based on the finding that the
metadata contains the confidential binding attribute, the security module (150) for the secure guest (180) in a selected mode, wherein the selected mode prevents certain operations from being intercepted by a
hypervisor (170); Interception (306) of a security module
data transmission by the trusted component (160); Performing a cryptographic operation on one or more secure objects of the security module
data transmission using the confidential binding attribute to provide a cryptographic result; and Providing a result of the security module
data transmission to a
receiver, wherein the result contains the cryptographic result.