A review of the Working Groups

As the new year begins, here’s what we’re looking forward to:

  • Oyster CVMs

    • Sui mainnet integration with oyster-cvm using nautilus framework and provides a reproducible enclave verification using oyster-cvms natively on Sui.

    • Implement attestation verification in the Oyster SDK for the new EC2 instance attestations for use by consumers of the SDK

    • Update the Scallop protocol to use the new SDKs so connections can be established between enclaves with the new EC2 instance attestation support

    • Develop a new base image with the new EC2 instance attestations support that application enclaves can use as an underlying template

    • Deploy a new KMS for enclaves with the new EC2 instance attestations so they can manage persistent secrets sealed to their measurements

    • Build a Pulumi based project to setup VPCs, subnets, route tables, etc for running the new EC2 instance attestations based enclaves with proper rate limiting and security posture

    • Enable running enclaves with GPU support based on the new EC2 instance attestation infrastructure with GPU-enabled instances as the host

    • Add support in the oyster-cvm CLI tool for deploying enclaves with Nitro attestation support including interfacing with the correct contracts and KMS implementations

  • Oyster Serverless

    • Migrate Oyster serverless executors to enclaves with the new EC2 instance attestations for better performance and compatibility with the broader platform

    • Build Nitro attestation based gateways for more sophisticated state management of jobs directly in the gateways and reduce unnecessary contract interactions

    • Develop x402 enabled endpoints for the Oyster serverless web2 gateways to properly rate limit and charge for the resources used by them to serve compute requests

  • Applications

    • Build an image template for providing a verifiable read-only storage disk to enclaves that store large amounts of data that does not fit in memory

    • Add support for enclaves with writable persistent storage where they can persist their running state and restart themselves without losing important data needed to continue computing where they left off previously

    • Develop generic x402 proxies for payment protection of endpoints in application enclaves that can be dropped in as-is in front of existing applications to give them the ability to charge for the usage and be self sustaining application enclaves

  • Monitoring and Visualization

    • Build a dashboard for starting, stopping, restarting, terminating and performing general management of provisioned enclaves with Nitro attestations.

    • Provide a monitoring implementation for enclaves that helps developers monitor resource usage of the enclaves

    • Enable auto-scaling for enclaves based on resource monitoring data provided by the monitoring subsystem to enable applications to automatically scale up and down to incoming traffic patterns

  • Research

    • Research Kubernetes support for TEEs that automatically provisions enclaves with the correct secrets and transparently enforces Rules Based Access Control policies with respect to the network traffic and data in persistent storage

    • Explore the EIP 8004 specification and how it can be leveraged by applications running on the Oyster platform

    • Participate in the EIP 8004 specification and standardization process to make it compatible with application running on the Oyster platform

    • Prototype general SDKs, tools and integration libraries designed to help applications seamlessly integrate with other EIP 8004 infrastructure

  • Commons

    • Reproducible enclaves using Sui Nautilus powered by Marlin Oyster
1 Like