Joined January 2022
21 Photos and videos
NVIDIA GPU Attestation matters for confidential AI πŸ” GPU trust cannot stop at the VM boundary. For platforms like Cocos AI, attestation helps extend trust to accelerated infrastructure. πŸ‘‰ docs.nvidia.com/attestation/… πŸ‘‰ cocos.ai/ #ConfidentialComputing #NVIDIA #GPU
4
6
73
Cocos aTLS now binds attestation to the TLS session πŸ” That means: β€’ stronger relay-attack protection β€’ more robust attested connections πŸ‘‰ ultraviolet.rs/blog/atls-bin… #ConfidentialComputing #TEE #TLS
5
6
80
Why does vTPM matter inside a Confidential VM? πŸ” In Cocos AI, vTPM is part of the trust chain inside the CVM, enabled through Coconut-SVSM. That helps extend trust into the guest environment. πŸ‘‰ cocos.ai/docs/trusted-execut… #ConfidentialComputing #TEE
2
4
65
Confidential workloads on Google Cloud β€” with more than just infra πŸ” Cocos AI adds: β€’ an agent inside the CVM β€’ Docker, Wasm, Python, and ELF runtimes β€’ provisioning, hardening, and integrity monitoring πŸ‘‰ cocos.ai/ #ConfidentialComputing #GoogleCloud #TEE
3
5
105
KBS controls decryption πŸ” In Cocos AI: β€’ KBS stores decryption keys β€’ attestation gates key release β€’ separate KBS paths for algos and data That makes OCI delivery policy-driven, not just encrypted. πŸ‘‰ cocos.ai/docs/remote-resourc… #ConfidentialComputing #OCI #TEE
3
6
103
Less exposure inside the CVM πŸ” In Cocos AI: β€’ SSH is disabled β€’ Docker uses Ramdisk That means less persistent state inside the guest. πŸ‘‰ cocos.ai/docs/architecture-c… #ConfidentialComputing #TEE
3
6
73
Wasm inside Confidential VMs πŸ” Cocos AI supports AMD and Intel TEEs. With Wasm in the CVM: β€’ lightweight runtime β€’ more flexibility β€’ more portable execution πŸ‘‰ cocos.ai/ #ConfidentialComputing #WebAssembly
3
6
61
What makes a Confidential VM trustworthy beyond the TEE? πŸ” In Cocos AI, trust also includes: β€’ vTPM inside the CVM β€’ measured boot β€’ Linux IMA That means guest state can be measured and verified end to end. πŸ‘‰ cocos.ai/docs/trusted-execut… #ConfidentialComputing #TEE
3
7
81
Confidential workloads need runtime flexibility In the Confidential VM, Cocos AI runs: β€’ Docker containers β€’ Wasm modules β€’ Python scripts β€’ ELF binaries Runtime flexibility makes confidential compute practical. πŸ‘‰ cocos.ai/ #ConfidentialComputing #TEE
3
5
64
Confidential workloads across private cloud, Google Cloud, and Azure πŸ” Cocos AI supports: β€’ private and public cloud β€’ more flexibility β€’ an easier path to confidential workloads πŸ‘‰ cocos.ai/ #ConfidentialComputing #TEE #CloudComputing
1
3
5
56
Encrypted algorithms and datasets as OCI images πŸ” In Cocos AI, resources use: β€’ OCI registries β€’ attestation-gated keys β€’ decryption only in the TEE That makes OCI artifacts usable for confidential workloads. πŸ‘‰ cocos.ai/docs/remote-resourc… #ConfidentialComputing #OCI #TEE
1
6
7
116
Why build EOS with Buildroot? πŸ” In Cocos AI, a smaller guest OS means: β€’ less attack surface β€’ lower footprint β€’ faster CVM boot For confidential VMs, minimalism is part of security. πŸ‘‰ cocos.ai/ #ConfidentialComputing #TEE
1
4
6
118
Attestation gives evidence. Compare it to what? πŸ€” CoRIM defines reference: β€’ known-good values β€’ expected state β€’ trust across TDX/SEV-SNP Cocos AI makes it policy-driven. πŸ‘‰ cocos.ai πŸ‘‰ CoRIM draft: datatracker.ietf.org/doc/dra… #ConfidentialComputing #TEE
1
2
4
98
Trust shouldn't depend on vendor TEE attestation πŸ” Entity Attestation Token (EAT) standardizes attestation evidence. With Cocos AI: β†’ across TDX & SEV-SNP β†’ verifiable runtime claims β†’ portable trust layer πŸ‘‰ ultraviolet.rs #ConfidentialComputing #TEE
2
4
91
How do you collaborate on sensitive data πŸ€” Without exposure? πŸ” Multi-party AI enables: β€’ Data is encrypted & processed in enclaves β€’ Attested execution β€’ Only insights are shared AI collaboration without exposure πŸ‘‰ prism.ultraviolet.rs/ #ConfidentialComputing #AI
1
3
22
Who verifies the machine? πŸ€” πŸ” Remote Attestation: β€’ Proof of execution in secure enclaves β€’ Integrity check before processing β€’ No trust in infra No attestation = no proof πŸ‘‰ ultraviolet.rs/ #ConfidentialComputing #CyberSecurity
2
2
26
Why is data vulnerable during processing? πŸ€” Encryption usually stops there. πŸ” Confidential Computing: β€’ Encrypted in use β€’ Secure enclaves (TDX, SEV-SNP) β€’ Verifiable execution Trust β†’ cryptographic proof πŸ‘‰ ultraviolet.rs/ #ConfidentialComputing #CyberSecurity
3
5
57
How do you run secure computations across cloudsβ€”without exposing data? πŸ”’ Prism AI: βœ… Attested TLS (remote attestation) βœ… Intel TDX & AMD SEV-SNP βœ… SHA3-256 verification πŸŽ₯ youtube.com/watch?v=1yGJ787_… #ConfidentialComputing #PrismAI #CyberSecurity
4
6
91
Cocos AI first to implement next-gen aTLS πŸ” Level 2 binding: β€’ Session-bound attestation β€’ TLS 1.3 exporters β€’ Stronger vs relay From identity-based β†’ session-bound crypto trust πŸ“– ultraviolet.rs/blog/atls-bin… #ConfidentialComputing #TEE #CyberSecurity
7
7
127
Collaborate on sensitive data β€” without exposing it πŸ” Prism AI enables secure, multi-party AI across organizations β€” without data sharing. Combine datasets, preserve privacy, and keep full control over your data. πŸ“Ί youtube.com/watch?v=1yGJ787_… #ConfidentialComputing #PrismAI
2
2
48