At its Innovation 2023 event today, Intel announced the general availability of its attestation service as the first offering of the new Intel Trust Authority umbrella. The new offering aims to enhance the company’s confidential computing portfolio by providing an independent, scalable and unified assessment of trusted execution environments (TEEs) across multiple deployment models.
“Previously known by its codename Project Amber, the attestation service under Intel Trust Authority aims to offer a unified, independent assessment of secure enclave integrity and policy enforcement anywhere confidential computing is deployed including multiple clouds, hybrid, on premises and edge,” Anil Rao, VP of systems architecture and engineering at Intel, wrote in a blog post.
The tech giant introduced the security-as-a-service product Project Amber in May last year. It is designed to provide remote verification of the trustworthiness of a compute asset in multiple environments to enhance confidential computing.
Protecting data and applications in useConfidential computing is designed to enable data to remain encrypted while in use by performing the computation in hardware-based TEE, which can prevent unauthorized modification or access of data and applications in use.
Intel’s confidential computing portfolio includes Trust Domain Extensions (TDX) based on VM isolation technology, Software Guard Extensions (SGX) for application isolation, and now an attestation service under Trust Authority.
Attestation is one of the core principles behind confidential computing, which refers to testing the security of workloads. Intel's attestation service aims to create a multicloud, multi-TEE service for third-party attestation.
Nikhil Deshpande, senior director of product management at Intel, wrote in a blog post to explain the advancement of the attestation service under the Intel Trust Authority:
- Third-party verification: Moves beyond the traditional model of self-attestation by infrastructure providers in the cloud service architectures, aligning with modern “separation of duties” principles.
- Uniform security checks: Provides a consistent and scalable attestation coverage, to accommodate the growing hybrid cloud deployments across different vendors and environments.
- Easy implementation: Delivered as a SaaS solution, making the attestation service simple to deploy and grow, while also decoupling attestation from the infrastructure provider.
Currently, Intel already has collaborations with partners like Thales, Zscaler and Nvidia for attestation services. Nvidia announced plans to collaborate with Intel to offer attestation services for Nvidia H100 GPUs via Intel TDX and the Intel Trust Authority attestation service, according to Deshpande.
Additionally, Microsoft Azure has ensured interoperability between its attestation and the attestation service under Intel Trust Authority so customers can transition between the two platforms effortlessly.
Intel's Trust Authority suiteThe Intel Trust Authority is a suite of trust and security services to enhance confidential computing security, according to Deshpande. “In its first release, Intel Trust Authority attests to the validity of Intel confidential computing environments, also known as TEEs.”
The Trust Authority is designed to enable new use cases including multiparty collaboration for data compute, such as artificial intelligence (AI) environments; ensuring the integrity of both edge and cloud environments; and mutual attestation for cloud services, Deshpande said.
“The implementation of this Trust Authority that we're doing will help provide that independent attestation service that, most importantly, is scalable across multiple cloud environments,” Rao told reporters ahead of the event.
He added the initial release of Intel Trust Authority focuses on TEEs enabled by the vendor’s SGX and TDX, but plans to expand its capabilities to support third-party technologies.
The service has also undergone ISO 27001 certification to show its quality and reliability, Rao said.
Incorporating Intel Trust Authority into zero trustUsing Intel Trust Authority, businesses can more efficiently align with the National Institute of Standards and Technology (NIST) recommendations for a zero-trust architecture across on-premises, hybrid, multicloud and edge deployments, Rao said.
He added that the Trust Authority can help elevate the overall asset security by continuously verifying trust, mitigating compromised asset risks and ensuring security policy compliance while centralizing the attestation process for various deployment types.
One example is the Zscaler partnership. The security vendor is isolating its Zero Trust Exchange and App Connectors in the silicon-based Intel TDX confidential computing environments and using Intel Trust Authority to verify their authenticity and integrity across multicloud environments. The move is to enhance security and scale zero trust across multiple clouds.
Comments