Intel unveiled its confidential computing service for virtual machines (VMs), dubbed Trust Domain Extensions (TDX), as part of its 4th Gen Xeon family launch this week.
The vendor’s confidential computing portfolio now includes TDX based on VM isolation technology, Software Guard Extensions (SGX) for application isolation, and trust verification services with Project Amber.
The new Intel TDX draws a trust boundary around VMs, which is a perimeter drawn around confidential data, explained Amy Santoni, Intel fellow and chief Xeon security architect.
“Today, the boundaries with just virtual machines is a function of the cloud management staff service level agreement. And it's enforced by contract, not unnecessarily by cryptography or hardware,” she said. “VM isolation effectively removes the cloud service provider or other cloud tenants from the trust boundary with cryptography and hardware. It adds technological strength to compliance and sovereignty programs with little impact to the existing applications that run within the virtual machine.”
That’s why Intel claims this technology is ideal for porting existing applications to run in a confidential computing cloud environment. Microsoft Azure, Google Cloud, Alibaba Cloud, and IBM Cloud were the first group of cloud providers to offer confidential computing services based on the Intel 4th Gen Xeon processors and TDX services.
This launch is expected to help Intel better its position and compete with AMD in confidential computing. “Intel’s announcement marks a significant moment in confidential computing history. After establishing itself as a leading player with SGX, Intel now enters the confidential VM market, currently led by AMD,” said Jay Harel, VP of Product at Opaque Systems.
Microsoft announced last October the general availability of its confidential virtual machine nodes in Azure Kubernetes Service (AKS) based on 3rd generation AMD EPYC processors with SEV-SNP. Last May, AMD introduced its confidential VMs on the existing N2D and C2D VMs on Google Cloud, powered by AMD EPYC processors.
Intel Project Amber to Launch in Mid-2023On top of Intel TDX, the company also plans to launch Project Amber in mid-2023. Intel first introduced the project last year, which is designed to create a new multi-cloud, multi-TEE service for third-party attestation, aligning with zero-trust principles.
Project Amber is “a cloud-delivered trust service, helping organizations verify trust in a number of areas from edge to cloud, but will start as an independent attestation service for Intel confidential computing technologies,” according to Anil Rao, VP of systems architecture and engineering.
Based on zero-trust principles and practices, “there should be a division of responsibilities between the infrastructure provider and the attestation provider,” he added. “Project Amber will be an independent, cloud-based trust verification service that can provide a consistent attestation for SGX and TDX across multiple clouds, whether it is on-prem, or public cloud, or edge deployments.”
Intel CTO Greg Lavender also noted in an earlier statement that Project Amber takes confidential computing to the next level amid the company’s commitment to a zero-trust approach.
Comments