Jeffery Lim wants to open up cloud research
Millions of people rely on the cloud every day, yet researchers working to secure and improve the cloud are often locked out of the technology it runs on. Jeffery Lim is trying to change that.
One such technology, single-root input/output virtualization (SR-IOV), lets major cloud providers like Amazon Web Services boost the performance of their systems. Cloud providers combine SR-IOV with custom hardware and software to deliver faster cloud services than traditional setups allow.
Lim is a computer engineer at MIT Lincoln Laboratory. While pursuing his master's degree, he noticed that academic research proposing smarter or safer cloud infrastructure did not account for SR-IOV. Very few open-source hardware platforms existed that would let researchers work directly with SR-IOV as they developed new software or models to improve the cloud.
So, Lim filled that gap with his master's thesis, building a hardware platform compatible with SR-IOV that captures key features of the infrastructure used by cloud providers. The result is a research and development platform that allows researchers to build, test, and evaluate realistic cloud designs.
"As a society, everyone uses the cloud now," Lim says. "I hope that people will use this platform to build systems more akin to how cloud providers operate, and, more broadly, that researchers everywhere can take advantage of SR-IOV for the performance benefits it offers."
Lim presented a paper at the IEEE High-Performance Extreme Computing Conference in September, and he plans to release this work open source. In recognition of the hardware's potential impact, the Boston University College of Engineering awarded Lim its 2026 Master's Societal Impact Award.
Winding path to cybersecurity
Growing up, Lim was fascinated with building computers. That fascination set him on a winding path to the Secure Resilient Systems and Technology Group at Lincoln Laboratory.
After studying electrical and computer engineering at the University of Colorado Boulder, he spent several years in industry working on field-programmable gate arrays (FPGAs) — integrated circuits that can be repeatedly reprogrammed for different functions. This background led to his hire at the Laboratory in 2018, where he developed FPGAs for small radars that detect the breathing of humans trapped in rubble and for large radars that track satellites and orbital debris from atop Millstone Hill. He next turned to investigating radiation-induced faults in integrated circuits aboard space platforms and ways to protect the chips.
This focus on safeguarding hardware turned his attention to cybersecurity, an area he had long found interest in but never fully explored. So, Lim transferred to his current group in 2022 to pursue this interest.
"I don't think there's another place in the world where I could say, 'Hey, I want to try something new,' and actually have that opportunity," Lim says. "Lincoln Laboratory does that really well, giving people the chance to transition into a different field of engineering or area of expertise."
To deepen his expertise, he applied and was accepted in 2024 to the Lincoln Scholars Program, which allows Laboratory technical staff to pursue full-time graduate studies at the master's or doctoral level. Scholars remain employed and apply their academic work to national security needs.
As he pursued his master's degree at Boston University, Lim worked closely with his mentor Benjamin Nahill at Lincoln Laboratory. Nahill helped Lim keep his research tied to the Laboratory's mission and provided a sounding board for ideas. "I'd call him my rubber ducky," Lim says, a nod to the classic software engineering practice of "rubber duck debugging" — reasoning things out through speaking aloud to a rubber duck.
"We talked about his thesis concept for quite a while, but the implementation suddenly became real toward the end," says Nahill. "He transformed what began as an idea for a research tool to an incredibly performant implementation. Having worked with Jeffery on projects in our group, I shouldn't have been surprised, but it was most impressive."
Missing piece for cloud research
When most people say "the cloud," they mean cloud services provided by companies such as Amazon, Microsoft, and Google. Virtualization is the invisible process that makes those services possible. Users uploading photos or streaming movies are interacting with virtual machines, running on servers in data centers.
In the past decade, SR-IOV has changed the way traditional virtualization works. Traditionally, a software component known as the hypervisor acts as a middleman between the virtual machines and the server’s physical hardware. Its main role is to distribute computing resources as needed, and provide functions (such as networking) to the virtual machines.
In contrast, SR-IOV enables virtual machines to access a dedicated slice of the hardware device, reducing the hypervisor overhead. This capability is often found on specialized devices called Smart Network Interface Cards (SmartNICs). Major cloud platforms, such as Amazon Web Services’s Nitro System and Microsoft’s Azure Accelerated Networking, use SmartNICs with SR-IOV to provide high-speed networking to many virtual machines.
"This was the missing research capability that I set out to build: an open-source SmartNIC platform compatible with SR-IOV," Lim says. Because SmartNICs can be built on FPGAs, Lim had a familiar starting point. In fact, he found a couple of platforms that supported SR-IOV; however, they lacked features that would make them practical tools for researchers to utilize. He spent a couple of months building those required components.
The first component is a switching fabric. Often, cloud customers' applications or programs may be split across multiple virtual machines, which may be distributed across multiple servers. Therefore, the cloud system needs a way to determine whether a piece of data needs to stay local or leave the server. Lim's switching fabric handles that traffic-directing job.
The second component is a network function engine. This small, specialized processor is built to run security rules, like firewalls, that keep one customer's data safely separated from another's. To build it, Lim used Extended Berkeley Packet Filter (eBPF), a system that allows custom code to inspect network traffic, approving or blocking data as needed. Rather than starting from scratch, he adapted the design from doctoral research conducted by Dr. Zaid Tahir, who studied under their shared advisor, Prof. Martin Herbordt of Boston University.
Herbordt described Lim's efforts as "combining vision with heroic system-building, single-handedly putting together the hardware and software necessary to prove the concept."
"I'm very much a hands-on hardware guy, so, yes, I ended up building two servers at home to test my designs," Lim says. He also used the Mass Open Cloud’s Open Cloud Testbed, a testbed meant for testing cloud platforms, to gather metrics and validate his system.
Impact beyond the platform
Throughout the project, Lim maintained focus on applicability and transparency. "My biggest worry was, is this going to be relevant? Is this something that can actually be utilized?" Lim reflects.
Earning the Societal Impact Award points to yes. The award recognizes projects that address pressing global challenges through innovative applications of technology. Lim's platform opens the door to evaluating a cloud trust model that remains largely opaque, even as many sectors of society, from healthcare to banking, increasingly rely on it.
"Right now, we have limited visibility into how major cloud providers implement and evolve their infrastructure," Lim says. "If researchers can catch up to how the modern cloud operates, they might develop new approaches that improve security or performance."
As part of his role as a Lincoln Scholar, Lim is also exploring how his work connects to the Laboratory's national security mission. He sees several potential avenues.
One program in his group is evaluating cyber-hardening techniques for hypervisors as the cloud takes on an expanding role in defense systems. "Introducing Lim's SR-IOV-compatible platform to this work would help bring our research closer to how cloud environments operate, demonstrating the impact of our techniques in realistic environments," says Nathan Burow, the program's principal investigator. Another program is examining what it takes to stand up high-performance data centers, work that could draw directly on Lim's research into the technologies SR-IOV requires.
Or his path may lead to something new. The Laboratory allocates internal technical investment funding — supported by the Office of the Under Secretary of War for Research and Development — for staff-proposed projects addressing emerging needs. Lim is considering a proposal to bring SR-IOV to the embedded-systems level, say, to drones or satellites.
"We saw how cloud providers moved from traditional virtualization to SR-IOV to maximize performance while maintaining isolation," he says. "I wonder if we can do the same at the embedded level, where power and compute constraints are even tighter. I'd love to complete that transition. I learned a lot from the cloud. Now, can we apply those lessons somewhere else?"