<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-23T12:56:57Z</responseDate><request verb="GetRecord" identifier="oai:www.repository.cam.ac.uk:1810/386974" metadataPrefix="uketd_dc">https://api.repository.cam.ac.uk/server/oai/request</request><GetRecord><record><header><identifier>oai:www.repository.cam.ac.uk:1810/386974</identifier><datestamp>2025-07-16T00:43:12Z</datestamp><setSpec>com_1810_219481</setSpec><setSpec>com_1810_256065</setSpec><setSpec>col_1810_219482</setSpec></header><metadata><uketd_dc:uketddc xmlns:uketd_dc="http://naca.central.cranfield.ac.uk/ethos-oai/2.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:uketdterms="http://naca.central.cranfield.ac.uk/ethos-oai/terms/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://naca.central.cranfield.ac.uk/ethos-oai/2.0/ http://naca.central.cranfield.ac.uk/ethos-oai/2.0/uketd_dc.xsd">
   <dc:title>Establishing trust in confidential computation and communication systems</dc:title>
   <dc:identifier xsi:type="dcterms:DOI">https://doi.org/10.17863/CAM.119932</dc:identifier>
   <dc:creator>Kocaoğullar, Ceren</dc:creator>
   <uketdterms:advisor>Beresford, Alastair</uketdterms:advisor>
   <dcterms:abstract>Modern confidential computation and communication systems aim to safeguard data in-use and protect metadata, extending privacy beyond the limits of conventional approaches. Trust is foundational to their security and adoption, yet difficult to establish due to strict privacy requirements, technical complexity, and conflicting stakeholder incentives.

Anonymity networks provide metadata-private communication, protecting information such as who is talking to whom. Current anonymity systems require users to manually exchange key material and network information, a cumbersome operation which hinders adoption. This dissertation presents Pudding, a user discovery protocol that automates trust establishment through email addresses, hides usernames from unauthorised parties, and provides fault-tolerance.

Confidential Computing uses Trusted Execution Environments (TEEs) built for secure and isolated computation to protect data privacy and integrity during processing. As TEEs combine specialised hardware and software from multiple vendors, users must trust a complex and often opaque ecosystem. This dissertation introduces the Confidential Computing Transparency framework as a structured, progressive model to help users make informed decisions by increasing transparency and accountability. A user study, involving over 800 participants, is conducted, demonstrating higher transparency improves trust, and that detailed explanations further increase willingness to share sensitive data.

TEEs can also be used to support dynamic peer-to-peer networks, such as vehicle-to-vehicle communication systems for semi- or fully-autonomous driving, where machine-to-machine trust is essential for collaboration. This dissertation presents Careful Whisper, a gossip-based protocol for establishing trust in such environments. The protocol can reduce attestation cost from quadratic to linear, allows cross-protocol interoperability, and performs reliably in unreliable networks.

These contributions demonstrate practical, scalable ways to build more trustworthy confidential computing and communication. In doing so, they provide some of the foundations required for future secure and private computer systems.</dcterms:abstract>
   <uketdterms:institution>University of Cambridge</uketdterms:institution>
   <dcterms:issued>2025-05-07</dcterms:issued>
   <dc:type>Thesis</dc:type>
   <uketdterms:qualificationlevel>Doctoral</uketdterms:qualificationlevel>
   <uketdterms:qualificationname>Doctor of Philosophy (PhD)</uketdterms:qualificationname>
   <uketdterms:sponsor>Cambridge Trust
King's College, Cambridge
Google</uketdterms:sponsor>
   <dcterms:isReferencedBy xsi:type="dcterms:URI">https://www.repository.cam.ac.uk/handle/1810/386974</dcterms:isReferencedBy>
   <dc:identifier xsi:type="dcterms:URI">https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/5e8a120b-d957-43a9-b6ac-1c615f8530d7/download</dc:identifier>
   <uketdterms:checksum xsi:type="uketdterms:MD5">6bfb5ec92387b71448737a15ab673dab</uketdterms:checksum>
   <dcterms:license>https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/a74444af-17cd-4c45-a00c-bb5dd0156173/download</dcterms:license>
   <uketdterms:checksum xsi:type="uketdterms:MD5">87eda9de84448d1f82354d60eee3eb5f</uketdterms:checksum>
   <dc:rights>http://purl.org/NET/rdflicense/allrightsreserved</dc:rights>
   <dc:subject>computer security</dc:subject>
   <dc:subject>anonymity networks</dc:subject>
   <dc:subject>Confidential Computing</dc:subject>
   <dc:subject>privacy</dc:subject>
</uketd_dc:uketddc>
</metadata></record></GetRecord></OAI-PMH>