THE LINUX FOUNDATION PROJECTS
Blog

$91,000 in Grants: How New University Research is Pushing the Boundaries of Confidential Computing

By July 29, 2026July 30th, 2026No Comments3 min read

When it comes to processing sensitive data in the cloud, Confidential Computing has become the gold standard. By keeping data encrypted even while it’s actively being processed inside hardware-based Trusted Execution Environments (TEEs), it allows organizations to run sensitive workloads in untrusted cloud environments without losing control.

However, as workloads evolve, especially with the explosive rise of AI and complex data-sharing ecosystems, new security and privacy challenges naturally emerge.

To help solve these emerging hurdles, the Confidential Computing Consortium (CCC) is excited to announce $91,000 in research grants awarded through our Academic Research Grant program! Chosen from a competitive pool of 35 proposals across 32 organizations, two standout university projects are receiving $45,500 each in unrestricted funding.

Here’s a look at the two cutting-edge projects and how they plan to make confidential computing even safer and more robust.

The Winning Research Projects

1. Securing AI at Scale: Leakage-Aware Security in Confidential GPU LLM Serving

  • Researchers: David Oswald and Qifan Wang (Durham University)
  • The Challenge: As Large Language Models (LLMs) move into TEEs, particularly via confidential GPUs, we need to ensure side-channel attacks can’t compromise privacy.
  • The Project: This research dives into Key-Value (KV) cache management in confidential GPU LLM serving under a standard threat model (e.g., a malicious cloud host). The team is analyzing whether side-channel observations, such as operation timing or power measurements, could accidentally leak prompt details, prompt lengths, or request boundaries. Identifying these potential leakages is a critical step toward fully securing AI workloads in the cloud.

2. Beyond Data Isolation: Verifiable Privacy Policy Enforcement with Deko

  • Researcher: Chenghong Wang (Indiana University)
  • The Challenge: While TEEs are fantastic at protecting data in use, hardware isolation alone doesn’t automatically prove that a dataset was processed according to specific, agreed-upon privacy governance policies.
  • The Project: Enter Deko, a hardware-software co-design built for Confidential Virtual Machines (CVMs). Deko enables end-to-end verifiable data provenance. With Deko, data owners and downstream users can verify the exact methodology and lineage behind a dataset, what inputs were used, which policies were enforced, and how final outputs were generated.

Why This Research Matters

“The projects selected this year reflect the breadth and depth of innovation happening across the confidential computing ecosystem. As confidential computing scales to new workloads like GPU-accelerated AI and privacy-preserving data sharing, rigorous security analysis and verifiable guarantees become more important than ever.” — Mingshen Sun, Program Committee Chair & CCC Governing Board Member

The CCC Academic Research Grant program focuses on three core pillars:

  1. Scaling: Tackling emerging operational challenges in modern environments.
  2. Novel Applications: Expanding privacy-preserving use cases like data sovereignty and transparent data sharing.
  3. Hardening & Verification: Rigorously auditing, analyzing, and verifying TEE security components.

What’s Next?

Once these research projects wrap up, we will publish summary reports detailing their findings and contributions to the open source community. We will also release a new Request for Proposals (RFP) for our next round of grant funding.

Interested in learning more about our research initiatives or submitting a proposal in the future? Head over to the CCC Research Fund Page to explore past work and upcoming opportunities!