SAN FRANCISCO — When it comes to confidential computing, Microsoft, Intel, and Fortanix weren’t speaking in whispers at RSA Conference. The three companies are all founding members of the Confidential Computing Consortium. And in addition to hosting a panel about the topic at the annual security conference, company executives stressed the importance of confidential computing in their own security events, during interviews, and on the show floor at RSA.

“Confidential computing is one of the most important and relevant new paradigms that you folks will hear in the near future … in terms of data processing in the cloud in different deployments and solutions," said Anil Rao, VP of architecture for Intel’s Data Center Group, during the chipmaker’s Intel Security Day event.

The basic idea behind confidential computing is to improve security for data in use. To this end, confidential computing enables encrypted data to be processed in memory without exposing it to the rest of the system. This reduces exposure for sensitive data and provides greater control and transparency for users.

Confidential computing becomes increasingly important as companies’ data and code is processed in public clouds or edge clouds as opposed to on-premises data centers. “So enabling confidentiality in the cloud is a very, very important use case of this particular technology,” Rao said. But it’s about more than just taking a use case and adding security to it, he added. “Providing confidential computing actually enhances the use cases and it opens up the door to a multitude of options that customers can use in order to do their own computing in very many different ways.”

Microsoft Azure Confidential Computing

Microsoft Azure is the first public cloud to encrypt data while in use, according to Scott Woodgate, senior director of Azure Security. It teamed up with Intel to help design the Software Guard Extension (SGX) technology used in Intel’s Xeon chips, Woodgate said. Intel SGX is hardware-based technology that isolates specific application code and data to run in private regions of memory — or enclaves — thus protecting select code and data from disclosure or modification. And then a little over two years ago Azure, in partnership with Intel, announced Azure confidential computing. It’s now available in public preview in three regions — the United States, United Kingdom, and Europe — and Woodgate expects it to be publicly available later this year.

There’s two reasons why Microsoft is pushing confidential computing, Woodgate said during an interview at RSA.

“We’re a company that believes your data is your data, and the privacy of your data is paramount in our cloud — our primary business model is not on your data,” he said, in a not-to-subtle dig at other public cloud providers. “We want to offer the strongest possible privacy controls we can. And then the second piece is it frankly enables new innovations that weren’t possible before.”

Multi-Party Machine Learning

Multi-party or federated machine learning is one of these, and Microsoft is working with several banks on this use case, Woodgate said. “If you’re a bank, fraud is a big deal — money laundering, in particular,” he said. “And, as a result, you’re probably running machine learning on large data sets within the data you control to understand patterns that could be fraudulent.”

Instead of using just one bank’s data to better train the machine learning model to detect fraud, it would be even more helpful to use multiple banks’ data, especially since organized crime actors don’t just target one facility, they spread attacks across many banks.

“It would be really handy if you could have all the banks sharing this data, while not actually sharing the data, aka the data stay private to each bank, but some shared compute in the middle enabling you to find fraudulent patterns,” Woodgate said. “The combination of the cloud, which is required for the great scale, is something that Azure brings along, and then the confidential computing capabilities. So you can now do this.”

It works like this: each banks’ data remains isolated in a secure enclave. This means other banks, cloud machine administrators, and even Azure have no access to the data — but Microsoft can do multi-party machine learning on the encrypted data and find patterns that indicate fraud. “That absolutely helps the bottom line of each of these banks,” Woodgate said.

Fortanix Runtime Encryption

Fortanix, also a founding Confidential Computing Consortium member, pioneered enclave encryption. Its cloud-delivered runtime encryption technology runs on Intel’s Software Guard Extensions (SGX) hardware and allows general-purpose computation on encrypted data. It also ensures untrusted operating systems, root users, and cloud providers don’t have access to the encrypted data.

“We started the company in July 2016, and up until 2018 we were the only company talking about enclave runtime encryption, confidential compute, etc.,” said Fortanix CEO Ambuj Kumar in an interview at RSA. “Then Microsoft started to talk publicly [about confidential computing]. And now almost everybody wants to join the club — just recently, both Facebook and AMD joined,” he said, referring to the Confidential Computing Consortium.

“So early on people thought that it doesn’t make sense or it cannot be real or possible,” Kumar continued. “But now they’re at a point where the idea that you can actually give your data to somebody, on their own infrastructure, and they will not be able to misuse your data is very intriguing. So [confidential computing] is really capturing people’s imagination.”

There are a few reasons for this, he says. One is that customers have seen Fortanix’s technology deployed at scale. With its Equinix partnership, for example, in which the colocation giant uses Fortanix’s security software running on Intel SGX, “we have world’s largest encryption service by order of magnitude compared to the next person,” Kumar said.

Fortanix also partners with IBM, and that company recently made generally available its IBM Cloud Data Guard service based on Fortanix’s platform.

Plus there’s the very real cost of not encrypting data. “If you are a Fortune 500 CEO, for example, there are maybe three things that will cause you to lose your job,” Kumar said. “Security and privacy breach is one of those three.”

Confidential Computing and the Magic Pill

Fortanix sees two primary use cases for confidential computing: encrypted searches and privacy-preserving analytics, Kumar said. Encrypted searches allows a user to send a query and determine which data entries match that query without decrypting the entire database. “With confidential computing you can take the complete database, run it inside an enclave, we can take the query and do the processing and the data remains encrypted,” Kumar said.

Additionally, this allows users to encrypt the query itself. Financial analysts, for example, investigating small, publicly traded companies while keeping the company names hidden like this use case.

The second use case — privacy-preserving analytics — sounds more like something out of a futuristic movie. But Kumar says companies are working on it now, and he’s confident it will come to fruition in our lifetime. “Privacy preserving analytics is: I have my medical history. I want some pharma company to use that medical history to create a precision medicine that is targeted only for me, one magical pill that I have to take every day, and it will cure all the diseases for me. Of course, this sounds like science fiction today, but there are thousands of people working on these things.”

This use case raises all kinds of privacy red flags, like big pharma selling consumers’ data to insurance companies or revealing it to employers without consent.

“But with Fortanix, we hope to solve that because we can take the data, we can encrypt it, and the encryption key will only be revealed for the right application,” Kumar said. “So when they run their machine learning model, that will find the data available and it will run. But if they try to do anything else [with the data], it will not work.”