Every day, people upload some of their most sensitive information to the cloud.

Medical records. Financial transactions. Business documents. Family photos. And increasingly, the conversations we are having with artificial intelligence, or AI, systems.

Most users assume that data is protected. But there is an uncomfortable reality behind nearly every cloud service. The companies operating those systems still have technical access to the information they store and process.

Users are asked to trust that providers will follow policies, honor privacy agreements and protect data from misuse.

Adil Ahmad thinks we can do better.

Ahmad, an assistant professor of computer science and engineering in the School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at Arizona State University, has received a U.S. National Science Foundation Faculty Early Career Development Program (CAREER) Award to develop the foundations of a new generation of cloud computing systems that can process sensitive information without exposing it to the cloud providers running the infrastructure.

His long-term, ambitious vision is a cloud where privacy no longer depends on trust.

The confidential cloud

Ahmad is leading efforts to create technical safeguards that will ensure that cloud providers cannot access sensitive information even while their servers are performing computations on it.

“The core question of my research has been: How do we give control over data to the users who generate it or who it belongs to?” Ahmad says.

His work builds on a rapidly growing field known as confidential computing. Think of it as a locked room inside a cloud server. Data can enter the room, be analyzed and produce results, but the company operating the server cannot look inside while the work is taking place.

A useful comparison is online banking and digital payments. Early internet users had to trust websites with their credit card information. Over time, technologies such as HTTPS, tokenized payment systems and services like Apple Pay helped transform encryption from a specialized security feature into a basic expectation.

Ahmad hopes to create a similar shift for cloud computing itself.

The challenge is that the technology already exists in theory, but not always in practice. Systems designed to keep cloud data private often run more slowly and require more computing resources, making them difficult for companies to adopt at large scale. Ahmad’s research focuses on removing those barriers.

“We can’t provide security while taking away all of the things that make cloud computing useful,” Ahmad says. “That’s why it’s extremely important to consider both security and performance.”

The cost of keeping secrets

Ahmad’s research asks a key question: What would it take to make privacy-preserving cloud computing practical enough to become the default?

To provide an answer, his team will tackle four major challenges. They will create tools that make secure cloud applications easier to build and ensure that privacy-preserving systems can run the same software organizations use today. The researchers will also develop new methods to support AI workloads, ensuring sensitive data remains protected even when powerful computing hardware is used to analyze it.

Finally, the team will address efficiency. One of the biggest obstacles facing confidential computing is that stronger privacy often requires additional computing resources, increasing costs and reducing performance. Ahmad’s research aims to remove those barriers, making it possible for organizations to adopt stronger privacy protections without sacrificing the speed, scalability and convenience that have made cloud computing indispensable.

Taken together, these advances could make privacy-preserving cloud computing practical for everyday services, ranging from AI applications to financial systems.

Read the full story on Engineering News.