The goal of the Secure Systems research group is to create new technologies and design and analysis methods for the development of secure computing and communication systems. The new technologies should be, at the same time, secure, easy to use, and inexpensive to deploy. As is typical for security research, our results also include the discovery of novel attacks and previously unknown classes of vulnerabilities in existing systems. Security against malicious attacks is a basic requirement for all network-connected services and products, and scientific research can provide both fundamental understanding of the security issues and practical solutions that enable product development.

We focus particularly on platform security; how hardware, operating systems, and other parts of the system can support the security of the application.  This is a great security multiplier, since we can design and build a mechanism once to secure many different systems.

Much of our work centres on confidential computing and remote attestation, using trusted hardware to isolate sensitive workloads and produce verifiable evidence of what is actually running and on what data. We look at how to make this work across the many hardware platforms in use, how to apply it to real-world workloads (e.g. machine learning training and inference), and how to take advantage of this technology in real distributed systems. We build and test these ideas on real hardware, in the real-world confidential computing ecosystem.

The “Research highlights and State of the Union” presentations from our annual Demo Day events give an overview of our research: