Facebook, AMD, Nvidia, and Accenture are among the latest companies to join the Linux Foundation’s Confidential Computing Consortium.
The group, which formed nine months ago, has grown 60% since then and added 10 new members in the last five months. Its other new members include Anjuna, Anqlave, Cosmian, iExec, IoTeX, and R3. They join founding members Alibaba, Arm, Google Cloud, Baidu, ByteDance, decentriq, Fortanix, Huawei, Intel, Kindite, Microsoft, Oasis Labs, Oracle, Red Hat, Swisscom, Tencent, and VMware.
The Confidential Computing Consortium aims to solve a pressing security and data privacy challenge: how to encrypt data in use. Data is typically encrypted at rest (in storage) and in transit (as it moves across the network). But encrypting data in use, thus allowing it to be processed in memory without exposing it to the rest of the system, is more difficult. It is also especially important for organizations that handle sensitive data such as personally identifiable information (PII), financial data, or health information, and thus need to mitigate threats that target the confidentiality and integrity of the applications and data in system memory.
How to Encrypt Data in UseConfidential computing protects data in use by performing computation in a hardware-based trusted execution environments (TEEs). These secure and isolated environments prevent unauthorized access or modification of applications and data while in use. But they are typically proprietary or hardware specific — like Intel Software Guard Extensions (SGX). Arm-based chips, meanwhile, use Arm TrustZone technology to provide secure enclaves on the chip.
The Confidential Computing Consortium aims to make it easier for developers to build applications in secure enclaves by developing technical and regulatory standards and building open source tools. For example, Intel contributed its (SGX) software development kit (SDK) to the open source group, and Microsoft contributed Open Enclave SDK, which is an open source framework that allows developers to build TEE applications using a single enclaving abstraction. Additionally, Red Hat contributed Enarx, which provides a platform abstraction for TEEs enabling companies to create and run “private, fungible, serverless” applications.
Confidential Computing Use CasesAs Fortanix CEO Ambuj Kumar said in an earlier interview, there’s a very real cost of not encrypting data. “If you are a Fortune 500 CEO, for example, there are maybe three things that will cause you to lose your job,” Kumar said. “Security and privacy breach is one of those three.”
In addition to better protecting applications and data from breaches, confidential computing technology can provide a secure platform for multiple parties to combine and analyze sensitive data while preserving privacy and without exposing the data or machine learning algorithms to the other party. This enables new use cases such as multi-party computing or federated learning, which can benefit health care and financial organizations.
“In a health care situation, genomics, or DNA processing where you are doing analytics on a DNA sample, the data is obviously so sensitive that protection of data in use, in memory, has a significant advantage,” said Nataraj Nagaratnam, CTO and director of cloud security for IBM’s Cloud and Cognitive Software business unit, in an earlier interview.
Additionally, financial services companies use confidential computing to analyze data without exposing the underlying data to another party. By analyzing transactions, banks can also better detect money laundering or fraud. This is a specific use case that Microsoft is working on with several of its financial services customers, said Scott Woodgate, senior director of Azure Security during an interview at RSA Conference in February.
Comments