Arm Holdings today shared the first technical specifications for its Confidential Compute Architecture (CCA), which it announced alongside the ARMv9 microarchitecture earlier this year.

The CCA is Arm’s take on confidential computing capabilities already available from Intel and AMD, and it involves isolating data from privileged entities by processing encrypted data in use.

New ways of harnessing data, like proprietary machine learning and artificial intelligence (AI) models, drive the need for these kinds of capabilities, said Mark Knight, director of architecture products at Arm.

“We believe that secure computing needs to be accessible to all developers, and we really want to extend the kind of high-trust environments that have previously been only accessible to silicon vendors or OEMs using TrustZone,” he said. “This is intended to be an architecture for all markets spanning cloud to mobile and automotive to IoT.”

Democratizing Confidential Compute

Confidential computing is "about protecting data in use,” Knight explained. "Even from privileged software running on a platform, which can include elements like the hypervisor or operating system kernel.”

Arm’s CCA is a hardware-level secure environment that shields portions of code and data from access while in use. The CCA enables memory encryption and works by dynamically allocating what Arm calls “realms” to applications. This effectively segregates secure workloads from non-secure workloads.

Realms are a construct that is flexible, Knight notes. A realm can be large enough to run an entire VM or as small as a micro-service.

The principles behind CCA are nothing new for Arm, either. TrustZone, the foundation on which CCA is built, dates back to 2003, Knight said. Subsequent releases added greater degrees of isolation.

This architecture is not intended to compete against established chipmakers as it aims to standardize and democratize confidential computing across everything from smartphones to data centers, Knight added. And it differs from Intel's implementation in that it doesn’t require a large, secure enclave for processing protected data on-die. Instead, Arm’s implementation ties into system memory.

Knight sees several opportunities for confidential compute outside the data center as well. One application would be to run things like corporate email or messaging within a realm on an employee’s personal cellphone. This would eliminate the need for intrusive device management services, which sometimes limit what apps can be installed, and also allow an employer to wipe an employee’s phone remotely without compromising on security.

The final component of Arm’s CCA strategy enables attestation, or proof that the data is secure. For example, an employer could pull an attestation report for a user's cell to ensure that an application or service is running in a secure environment.

Availability

Confidential computing has grown in popularity in recent years as enterprises grapple with security concerns associated with moving workloads to the cloud. In response, public cloud providers like Amazon Web Services, Microsoft Azure, and Google Cloud Platform have worked with chipmakers to launch confidential computing virtual machines that encrypted both data in use and at rest.

But while the technical specifications for Arm’s CCA are available today, Knight said it will take another two or three years before the technology finds its way into products. “This marks the start of the software enablement process with the open source community,” he added.