The Linux Foundation’s latest project tackles confidential computing with a group of companies that reads like a who’s who of cloud providers, chipmakers, telecom operators, and other tech giants.

Today at the Open Source Summit the Linux Foundation said it will form a new group called the Confidential Computing Consortium. Alibaba, Arm, Baidu, Google Cloud, IBM, Intel, Microsoft, Red Hat, Swisscom, and Tencent all committed to work on the project, which aims to accelerate the adoption of confidential computing.

This idea of confidential computing becomes more important as data moves between an enterprise's IT environments — and encryption becomes a necessity, not just a nice thing to have. In order to secure workloads as they move between on-premises data centers, public clouds, and the edge, data needs to be encrypted at rest, in transit, and in use. Of these three lifecycle stages, encrypting data in use is the most challenging.

What Is Confidential Computing?

Confidential computing addresses this and enables encrypted data to be processed in memory without exposing it to the rest of the system. This reduces exposure for sensitive data and provides greater control and transparency for users.

In addition to accelerating the confidential computing market, the new Linux Foundation group also plans to work on technical and regulatory standards and build open source tools that make it easier for developers to build applications in secure enclaves called trusted execution environments (TEEs).

To that end, participating companies say they will contribute open source code initiatives to the Confidential Computing Consortium. For example, Intel today said it contributed its Software Guard Extensions (SGX) software development kit. Intel SGX is hardware-based technology that isolates specific application code and data to run in private regions of memory — or enclaves — thus protecting select code and data from disclosure or modification. And the software development kit (SDK) helps application developers write code inside these protected enclaves.

Microsoft contributed Open Enclave SDK, which is an open source framework that allows developers to build TEE applications using a single enclaving abstraction.

Red Hat Enarx

And Red Hat contributed Enarx, which provides a platform abstraction for TEEs enabling companies to create and run “private, fungible, serverless” applications.

“Enarx allows developers to deploy applications to whichever trusted execution environments they choose,” said Mike Bursell, chief security architect at Red Hat, adding that it allows developers to write code using the programming language of their choice. “So whether you’re writing in C++ or Java or Rust, this makes it as easy as possible for you to do the right thing without having to make any changes to the applications,” Bursell said.

Currently Enarx works with Intel SGX and AMD Secure Encrypted Virtualization (SEV) based systems. “But this is something that is of interest to most chip vendors,” Bursell added. “We’re talking to all the obvious hardware vendors and trying to provide an abstraction across all these different hardware CPU architectures.”

Red Hat’s work on this open source project made the Confidential Computing Consortium an obvious choice for the software vendor. In addition, Bursell said, “we are very aware that our customers really want to be able to have the highest levels of security possible, specifically confidentiality when they are dealing with sensitive data — and really, what data isn’t sensitive these days?”

Plus, customers want to be able to run workloads on premises or in clouds and move easily between different environments, he added. “This move to confidential computing is something that fits very much with our vision,” Bursell said. “It’s allowing customers to decide where they want to run things, where’s the best place for their workloads. And developers want to write code that won’t get compromised. They all care about it.”