ConfidentialComputing

ConfidentialComputing

Geek Repo

Github PK Tool:Github PK Tool

ConfidentialComputing's repositories

Stargazers:4Issues:0Issues:0

islet-linux

ISLET is a project to enable on-device confidential computing for end users by leveraging ARMv9 CCA that is the newly emerging confidential computing hardware on ARM devices. Using the hardware support, ISLET enables a Trusted Execution Environment (TEE) on user’s devices within which users can securely process, store, communicate and manage their private data. The protection provided by ISLET applies not only to data-at-rest but also to data-in-use even in the presence of malicious privileged software on devices. We develop components enabling Realm Virtual Machines (VMs), which are secure VM-level TEE provided by ARMv9 CCA. To manage Realm VMs, Realm Management Monitor (RMM) is needed to be running at EL2 in the Realm world. Although the Monitor firmware is available as an open source, there is no functional Realm Management Monitor (RMM) code available yet. ISLET provides the implementation of RMM that is written in Rust.

Language:CLicense:NOASSERTIONStargazers:2Issues:0Issues:0

islet

ISLET is a project to enable on-device confidential computing for end users by leveraging ARMv9 CCA that is the newly emerging confidential computing hardware on ARM devices. Using the hardware support, ISLET enables a Trusted Execution Environment (TEE) on user’s devices within which users can securely process, store, communicate and manage their private data. The protection provided by ISLET applies not only to data-at-rest but also to data-in-use even in the presence of malicious privileged software on devices. We develop components enabling Realm Virtual Machines (VMs), which are secure VM-level TEE provided by ARMv9 CCA. To manage Realm VMs, Realm Management Monitor (RMM) is needed to be running at EL2 in the Realm world. Although the Monitor firmware is available as an open source, there is no functional Realm Management Monitor (RMM) code available yet. ISLET provides the implementation of RMM that is written in Rust.

Language:RustLicense:Apache-2.0Stargazers:1Issues:0Issues:0

multizone-sdk

MultiZone® Security TEE is the quick and safe way to add security and separation to any RISC-V processors. The RISC-V standard ISA doesn't define TrustZone-like primitives to provide hardware separation. To shield critical functionality from untrusted third-party components, MultiZone provides hardware-enforced, software-defined separation of multiple equally secure worlds. Unlike antiquated hypervisor-like solutions, MultiZone is self-contained, presents an extremely small attack surface, and it is policy driven, meaning that no coding is required – and in fact even allowed. MultiZone works with any 32-bit or 64-bit RISC-V processors with standard Physical Memory Protection unit (PMP) and “U” mode.

Language:CLicense:NOASSERTIONStargazers:0Issues:0Issues:0

rust-sgx

The Fortanix Rust Enclave Development Platform

Language:RustLicense:MPL-2.0Stargazers:0Issues:0Issues:0

arm-trusted-firmware

Read-only mirror of Trusted Firmware-A

License:NOASSERTIONStargazers:0Issues:0Issues:0
License:Apache-2.0Stargazers:0Issues:0Issues:0

aws-nitro-enclaves-workshop

AWS Nitro Enclaves Workshop

License:NOASSERTIONStargazers:0Issues:0Issues:0

bcc

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

License:Apache-2.0Stargazers:0Issues:0Issues:0

BigDL

Accelerate LLM with low-bit (INT3 / INT4 / NF4 / INT5 / INT8) optimizations using bigdl-llm

License:Apache-2.0Stargazers:0Issues:0Issues:0

certifier-framework-for-confidential-computing

The Confidential Computing Certifier Framework consists of a client API called the Certifier-API and server-based policy evaluation called the Certifier Service. It simplifies and unifies programming and operations support for multi-vendor Confidential Computing platforms by providing support for scalable, policy-driven trust management including

Language:C++License:Apache-2.0Stargazers:0Issues:0Issues:0

confidential-cloud-native-primitives

Landing Confidential Computing into Cloud Native Computing

Language:GoLicense:Apache-2.0Stargazers:0Issues:0Issues:0
License:Apache-2.0Stargazers:0Issues:0Issues:0

ima-evm-utils

Primary ima-evm-utils repo

License:GPL-2.0Stargazers:0Issues:0Issues:0

incubator-teaclave

Apache Teaclave (incubating) is an open source universal secure computing platform, making computation on privacy-sensitive data safe and simple.

License:Apache-2.0Stargazers:0Issues:0Issues:0

islet-asset

ISLET is a project to enable on-device confidential computing for end users by leveraging ARMv9 CCA that is the newly emerging confidential computing hardware on ARM devices. Using the hardware support, ISLET enables a Trusted Execution Environment (TEE) on user’s devices within which users can securely process, store, communicate and manage their private data. The protection provided by ISLET applies not only to data-at-rest but also to data-in-use even in the presence of malicious privileged software on devices. We develop components enabling Realm Virtual Machines (VMs), which are secure VM-level TEE provided by ARMv9 CCA. To manage Realm VMs, Realm Management Monitor (RMM) is needed to be running at EL2 in the Realm world. Although the Monitor firmware is available as an open source, there is no functional Realm Management Monitor (RMM) code available yet. ISLET provides the implementation of RMM that is written in Rust.

Stargazers:0Issues:0Issues:0

linux-image-5.19

linux-image-5.19 for guest and host

Stargazers:0Issues:0Issues:0

linux-svsm

Linux SVSM (Secure VM Service Module) for secure x86 virtualization in Rust

License:MITStargazers:0Issues:0Issues:0

nvtrust

Ancillary open source software to support confidential computing on NVIDIA GPUs

License:Apache-2.0Stargazers:0Issues:0Issues:0

oak

Meaningful control of data in distributed systems.

License:Apache-2.0Stargazers:0Issues:0Issues:0

open-gpu-kernel-modules

NVIDIA Linux open GPU kernel module source

License:NOASSERTIONStargazers:0Issues:0Issues:0

snpguest

A CLI tool for interacting with SEV-SNP guest environment

Language:RustLicense:Apache-2.0Stargazers:0Issues:0Issues:0

stet

Split-Trust Encryption Tool for ubiquitous data encryption.

License:Apache-2.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

tdx-tools

Cloud Stack and Solutions for Intel TDX (Trust Domain Extension)

License:Apache-2.0Stargazers:0Issues:0Issues:0

trillian

A transparent, highly scalable and cryptographically verifiable data store.

License:Apache-2.0Stargazers:0Issues:0Issues:0
License:NOASSERTIONStargazers:0Issues:0Issues:0
License:CC-BY-4.0Stargazers:0Issues:0Issues:0

volatility

An advanced memory forensics framework

License:GPL-2.0Stargazers:0Issues:0Issues:0