Editor's note: This article represents the opinions and views of the author. We occasionally publish articles from industry leaders because we believe readers may find them valuable, but please note the writer's affiliations.
Confidential computing has roots dating back to 2004. Yet market adoption has been slow until recently. So why now? What change is drawing the increased interest?
There’s been much discussion on the needed tools for cybersecurity. That continues to be a growing need and does account for some of the market growth. But consider the new opportunities and business abilities that are newly created around the latest technology based on confidential computing.
According to a recent report by Everest Group, the confidential computing market could grow to $54 billion by 2026 – signifying its increasing importance in the enterprise security space. This article will delve into the potential for unlocking new opportunities through the latest technological advancements in confidential computing. It will explore how ensuring security can, in turn, unlock innovation in critical industries.
The triad
The world at times feels besieged by nefarious actors and players attacking critical computer systems. It’s here where sensitive and highly valuable information may be stolen. Cybersecurity frequently tops today’s news with efforts to prevent and thwart these cyberattacks. One of the primary threats to cybersecurity is data breaches.
The foundational principles, or triad, in cybersecurity are the following:
- Confidentiality - which aims to prevent sensitive information from unauthorized access attempts
- Integrity - to maintain the consistency, accuracy, and trustworthiness of data over its entire lifecycle
- Availability - for information to be consistently and readily accessible for authorized parties
Together, these are considered the three most important concepts within information security. They define the fundamental principles that organizations can use to focus questions and frame the development of security policies for organizations.
Confidential computing vs. traditional computing
A rising key component of this triad is confidential computing.
In traditional computing, data is typically processed and stored in systems that are vulnerable to attacks from insiders or external attackers. So it can be difficult to ensure the confidentiality and integrity of sensitive data.
Confidential computing enables organizations to protect their most valuable assets through different technologies and techniques. These include intellectual property, trade secrets, financial data, and personal information. It allows sensitive data to be processed securely in a trusted computing environment, such as a public cloud, without revealing the data to anyone who is not authorized to access it. Confidential computing shields unauthorized access, ensuring that the data remains confidential, even if the computing infrastructure is compromised.
And though confidential computing is most recognized for protecting data, looking after the process algorithms can be as highly significant. Securing the code and data is a guard against cyber threats such as malware and insider attacks. Hence, confidential computing is a key component of the triad. Confidential computing works well by leveraging a combination of hardware and software-based mechanisms.
Made for today
The root of confidential computing originated with trusted computing several years ago. Since 2004, most major manufacturers have shipped the necessary hardware components. The Linux kernel has included trusted computing support since version 2.6.13. With such a long history, it raises the question of why adoption has been slow.
Confidential computing is highly topical today because of these reasons:
The rapid adoption of public cloud and the rise of remote edge environment
Both are generally considered less secure, requiring the protections that confidential computing can supply. Public cloud has a supporting operations layer, which means all your data is “technically” under the provider's purview. Edge environments are generally less secure because you can’t fortify them in the same way that you would an on-premises data center. With on-premises data centers, we don’t hear as much about confidential computing because the customer owns the data center. The data is in their control, and they have strong security tools. That is different for cloud providers and edge environments.
Growing ease of use
For today’s software developer, the complexities are abstracted and simplified, making confidential computing much more accessible to the average developer. Also, advances in the layers surrounding confidential computing are more robust in support.
Platforms are proven to enable confidential computing to run perfectly in public and private clouds and at the Edge. Today, it is much easier to securely put workloads into confidential computing environments. The leading platforms secure execution environments, ensuring that code launched by firmware is trusted. It does this by isolating the interferences of multiple Virtual Machines, building, storing, and deploying secure images, providing runtime attestation and remote attestation, and securing container images creation, storage, and deployment.
Solving riddles
And while in today’s world we think first of this as a tool for protection, why not use it as a tool to expand the world of collaboration?
I recently worked on an unusual jigsaw puzzle. Some of the individual jigsaw pieces held clues to solve a riddle. While putting the puzzle together, I enjoyed seeing the beautiful picture unfold, yet it wasn’t until the puzzle was completed that I could see the whole picture enough to solve the riddle.
We have reached a point where medical records, research labs, geo-physical data, and more – while collected amongst the many institutions, for-profit companies, research centers, and others – are like a dispersed set of jigsaw puzzle pieces. Each entity gathers some pieces – enough to garner great insight into many of the world's wonders and business opportunities. Yet if we could put the whole puzzle together, without compromise, imagine the riddles that could be solved, and for business, the money that could be made.
In many industries, collaboration has been hampered and siloed by high regulation to protect the privacy of individuals, corporations, and nations. Confidential computing gives us the opportunity to uphold those protections while extracting the goodness that collaboration can bring.
How confidential computing is used today
As this technology can be used to protect a wide range of sensitive information, it has been deployed in a variety of industries. These include health care, financial services, and the insurance industry. There are so many use cases for protecting intellectual property as well as data privacy.
Confidential computing can secure code and the inner workings of entire applications. While data security is always a top priority, proprietary program methods can be just as valuable. This is especially true when a process is critical to increasing an organization’s efficiency or providing a service that no one else can provide. Key differentiators in business need to be protected. Companies can use confidential computing in the cloud without fear of a competitor stealing a key component of their offering.
Confidential computing at the edge
Many tend to think of confidential computing solely as a security measure for confidentiality in public computing environments. But confidential computing is quickly growing in use with Edge computing.
Edge computing is evolving from the simple sensors gathering data at the edge of the computing network to more sophisticated and interactive devices. These devices can gather data and interact in real time with customers, business partners, and sophisticated data gathering. The security protections offered in early edge computing devices tended to be simplistic and offered no protection beyond password or networking security. This left many of these environments at risk from cyber hackers. All aspects of the security triad are needed.
Today, more companies are not only deploying more devices at the edge, but they're asking them to do more computing. Many analysts are predicting that most of a business’s incoming data will be gathered at the edge. Predictions foresee the edge surpassing the current data flow at the data center. As data handling continues to grow at the edge, compute power is key. Not only for filtering and cleansing the data that's gathered, but also in the ability to intelligently interact with customers and active response, such as running a machine learning (ML) algorithm on incoming sensor data to make autonomous decisions.
Business-to-business interactions are also becoming vital to the success of these edge devices. The need to securely share sensitive data with partners is being demonstrated. For example, there is often the need to give the manufacturer of the edge devices access to specific data to help them update and maintain a hardware device. But need to do so without potentially exposing proprietary or sensitive data.
Recent technological advances demonstrate that today's hardware isn’t just capable of speed but that it can additionally support confidential computing constructs. Equally advanced is the software platform intentionally tuned for the edge environment, offering aligned execution, isolation, delivery, storage, and more.
In today's business environments that utilize edge computing, confidential computing demonstrates clear value in these insecure and unstable environments. It can be used to protect in-use data, which helps mitigate risk and ensure compliance with strict privacy and regulatory requirements.
Envision leveraging the cybersecurity triad with confidential computing to break today’s cyber-siege, unlocking many more opportunities for securely processing data at your core data centers, the cloud, and at the edge.
Confidential computing is robust enough to meet your secure computing needs.
Comments