Papers

Essays, notes and research.

Attested Key Provisioning for Kubernetes

2026

report

Securely provisioning PostgreSQL credentials on AKS through AMD SEV-SNP remote attestation, inverting the classical Kubernetes Secret model so the cluster never holds the password.

Cramer-Shoup

2026

summary

The Cramer–Shoup Public-Key Encryption Scheme (CS1) – Explains the Cramer–Shoup encryption scheme and shows how it achieves IND-CCA2 security against adaptive chosen-ciphertext attacks under the DDH assumption and target collision-resistant hashing.

TEE.fail

2026

summary

TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition – Demonstrates that architectural changes in modern TEEs enable a ciphertext-based side-channel attack that can extract attestation keys and break the trust model of confidential computing systems.