Cloud Security
We’re working on building the most secure cloud infrastructure platforms. Our research focuses on ensuring the integrity of everything in the stack, reducing the attack surface of cloud systems, and advancing the use of confidential computing and hardware security modules.
Our work
Simplifying cloud security policies with AI
Technical noteJulian Stephen and Shriti Priya- Cloud Security
- Data and AI Security
- Security
How do you measure innovation?
NewsDarío Gil- AI
- Cloud Security
- Quantum
- Science
- Semiconductors
The ultimate tool for data privacy: Fully homomorphic encryption
Technical noteOmri Soceanu and Ronen Levy- Cloud Security
- Fully Homomorphic Encryption
- Security
Extending server integrity across space and time with Durable Attestation
Technical noteDaniele Buono, James Bottomley, Marcio Augusto de Lima e Silva, Maurizio Drocco, and Gheorghe Almasi- Cloud Security
Strengthening cloud security with confidential computing
Technical noteRick Boivie- Cloud Security
- Confidential Computing
- Security
What is confidential computing?
ExplainerDaniele Buono, James Bottomley, Hubertus Franke, and Robert Senger- Cloud Security
- Confidential Computing
- Cryptography
- Hybrid Cloud
- See more of our work on Cloud Security
Projects
SysFlow
A cloud-native system telemetry framework that enables the creation of security analytics on a scalable, pluggable open-source platform.
Publications
- Michael Le
- Md Salman Ahmed
- et al.
- 2023
- ASIA CCS 2023
- 2023
- CLOUD 2023
- Mengmei Ye
- Angelo Ruocco
- et al.
- 2023
- CLOUD 2023
- Somin Song
- Sahil Suneja
- et al.
- 2023
- CLOUD 2023
- Peter Jan Gootzen
- Jonas Pfefferle
- et al.
- 2023
- SYSTOR 2023
- Jinghao Jia
- Raj Sahu
- et al.
- 2023
- HotOS 2023
Tools + code
Virtual TPM
Libtpms-based Trusted Platform Module (TPM) emulator with socket, character device, and Linux CUSE interface.
View project →IMA: Integrity Management Architecture
A kernel integrity subsystem that detects if files have been accidentally or maliciously altered, both remotely and locally, appraises a file's measurement against a "good" value stored as an extended attribute, and enforces local file integrity.
View project →