EDBT 2026 Demo / reviewers in the wild / expert
Rahul Priolkar
dblp:401/8100
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
0009-0006-2116-4954ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Hardware security and side channels · 87% Systems and software security · 13% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › trusted execution environments
confidential virtual machines |
0.9 | 1 | 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines · EuroSys 2025 |
Hardware security and side channels
trusted execution environments |
0.9 | 1 | 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines · EuroSys 2025 |
Cloud and datacenter computing › cloud security
confidential computing |
0.9 | 1 | 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines · EuroSys 2025 |
Cloud and datacenter computing
virtualization |
0.9 | 1 | 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines · EuroSys 2025 |
Systems and software security
memory protection |
0.3 | 1 | 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines · EuroSys 2025 |
Methods — techniques the papers use, named apart from their topics
sandboxing · 1.7intra-kernel privilege isolation · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual MachinesabstractConfidential virtual machines (CVMs) are designed to protect data in cloud machines, but they fail in this task in common Software-as-a-Service (SaaS) cloud environments. In such settings, the software stack within a CVM, including service programs and the operating system, that receives and processes data may intentionally disclose it to attackers. We present Erebor, a sandboxing architecture for CVMs that processes client data in secure containers, where restrictions apply to both (a) access by all untrusted outside components and (b) the sandbox's ability to communicate data through memory and software-controlled direct or covert exits. Erebor enables such restrictions through a security monitor design based on intra-kernel privilege isolation for CVM, fully compatible with emerging cloud deployments without requiring host modifications. Under realistic scenarios, such as large language model inference and private information retrieval, Erebor only adds a performance overhead of 4.5%-13.2%, demonstrating its practicality in terms of enabling strong data sandboxing in modern cloud machines. Chuqi Zhang, Rahul Priolkar, Yuancheng Jiang, Yuan Xiao 0001, Mona Vij, Zhenkai Liang, Adil Ahmad |
EuroSys | 2 |