Google Cloud announced an addition to its confidential computing portfolio — Confidential Space —during its Next event. It provides an isolated and secure space for organizations to perform collaborative tasks such as joint data analysis and machine learning (ML) model training while ensuring private data stays private.
Two years ago, Google Cloud introduced Confidential Virtual Machines (VMs) using the Secure Encrypted Virtualization (SEV) feature of second-generation AMD EPYC CPUs — the first product in its confidential computing portfolio to offer customers a service that encrypts data in use while it’s being processed, thus further isolating and securing workloads in the cloud. Earlier this year, the company launched its Confidential Google Kubernetes Engine (GKE) Nodes.
Building on that confidential computing technology, the new Confidential Space can enable organizations to collaborate while providing a trust guarantee that their own data can stay protected from their partners, including the cloud service providers. Google claims this can ease the tensions between data sharing and data privacy regulatory requirements.
The tech giant created this ‘cryptographic isolation’ world for multi-party computation to allow multiple organizations that have no trust in each other to encrypt data and bring it to this Confidential Space, Google Cloud Group Product Manager Nelly Porter told SDxCentral.
The Confidential Space runs workloads in a trusted execution environment (TEE) and builds on the hardened version of Container-Optimized OS (COS). It allows participants to encrypt their data with special keys that are only available to them and have control over how their data is used and which workloads are authorized to act on it.
Porter explained that the service offers the ability for any party to run code if all parties agree, but works as a vault that guarantees that party won’t be able to get access to data that doesn’t belong to them. “This Confidential Space is so hardened that even if you own and pay for these services, you have no way to change anything.”
Additionally, it makes sure that the workload operator and cloud provider are not able to influence the workload.
Google Cloud’s Confidential Space Use CasesWith Confidential Space, organizations can collaborate to aggregate and analyze sensitive data including protected health information, personally identifiable information, intellectual property, and cryptographic secrets that come from different sources while retaining data control, Google claims.
Google Cloud VP and GM Sunil Potti used financial institutions as an example during a press pre-briefing for the Next event. The institutions need to collaborate to identify fraud or analyze money laundering activities across their joint customer data set, including customer identities that have to be private. Confidential Space can make this data sharing happen while helping those companies comply with strict regulatory requirements and retain their competitive advantages.
The service also can be used for health care and medical technology development, such as clinical trials, without compromising sensitive patient data, according to Porter and Potti.
Another use case is that Web3 institutions can use it in areas such as blockchain and cryptocurrency to securely and instantly transact digital assets, Google claims.
“How do you facilitate that secure sharing of data without any leakages of privacy is where we expect confidential computing to take us to the next level,” Potti said.
Comments