SAN FRANCISCO – Google and Intel recently collaborated on a research project to identify security vulnerabilities in the chip vendor’s latest confidential computing technology — Intel Trust Domain Extensions (Intel TDX). The move aims to strengthen customer confidence in confidential computing.
Intel TDX introduced new architectural elements to deploy hardware-isolated virtual machines (VMs) called trust domains. The technology is designed to isolate VMs from the VM manager/hypervisor and other non-TD software on the platform to protect TDs from a broad range of software, according to Intel.
The goal of the Google and Intel collaborative research is to provide assurances that the Intel TDX is secure and can be confidently used by both cloud providers and customers. During the review, security experts at Google Cloud and Google Project Zero looked at about 81 potential attack vectors and found 10 security issues, five of which were defensive advisories and the most serious implementation issue discovered was a bug in the authenticated code module responsible for initiating the TDX feature.
The Intel team addressed these issues and gave the code back to Google to make sure the fix, Anil Rao, VP of systems architecture and engineering told SDxCentral.
“No customer asked us to do this. It was the initiative of Google and Intel to commit ourselves to win customer respect and build customer confidence,” he said. “The last thing you want to see is some major vulnerabilities in software technology, which is for security.”
The review also offers a better understanding of the expected threat model for Intel TDX and identifies limitations in the design and implementation, which would better inform Google's deployment decisions.
“If we give customers the assurances that we are protecting their data and workload, we need to ensure that we are building the story on a very solid ground,” Google Cloud Group Product Manager Nelly Porter said.
She also noted Google Cloud security team earlier also collaborated with AMD to conduct a similar review of the chipmaker’s technology and firmware that powers AMD’s confidential computing technology.
Why confidential computing is gaining tractionCloud providers and chipmakers such as Google, Microsoft, Amazon Web Services (AWS), Intel and AMD recently all introduced new developments in the technology, riding the wave of confidential computing. Its market size is projected to reach around $8.16 billion by 2027 with a compound annual growth rate of 24.46%, according to a recent report.
Confidential computing provides an additional level of protection and in-use encryption, which help prevent future attacks and security threats, Porter noted. “The ability for us to protect our data and workload is so clearly appealing to everybody, so it's no surprise to all of us that this message is reaching the right audience.”
Rao echoed that as more organizations embrace the cloud, confidential computing offers data in-use protection that helps them with many security risks and challenges that exist outside the trust boundary.
The technology also can protect organizations' artificial intelligence (AI) by securing AI training and inferencing models within a zone, he added. Another use case for confidential computing is for maintaining data privacy and compliance and complying with government regulations.
“A combination of technology availability, a combination of the criticality of data, cloud-scale economics are why I think confidential computing is taking off,” Rao said.
Comments