Attested Key Provisioning for Kubernetes
2026report
Securely provisioning PostgreSQL credentials on AKS through AMD SEV-SNP remote attestation, inverting the classical Kubernetes Secret model so the cluster never holds the password.
Essays, notes and research.
report
Securely provisioning PostgreSQL credentials on AKS through AMD SEV-SNP remote attestation, inverting the classical Kubernetes Secret model so the cluster never holds the password.
summary
The Cramer–Shoup Public-Key Encryption Scheme (CS1) – Explains the Cramer–Shoup encryption scheme and shows how it achieves IND-CCA2 security against adaptive chosen-ciphertext attacks under the DDH assumption and target collision-resistant hashing.
summary
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition – Demonstrates that architectural changes in modern TEEs enable a ciphertext-based side-channel attack that can extract attestation keys and break the trust model of confidential computing systems.