Azure Confidential Computing and Zero Trust
by Razi Rais, Jeff Birnbaum, Graham Bury, Vikas Bhatia
Chapter 1. Understanding Confidential Computing and Trust
The phrase “data is the new oil” makes perfect sense in today’s digital world. In recent years, we have seen widespread adoption of cloud computing, and with artificial intelligence (AI) making considerable advances, particularly in areas such as generative AI, data has become one of the most valuable assets. For many businesses, data is the key differentiator because it gives them a competitive edge and, in many instances, enables incumbents such as startups to challenge existing hegemonies.
However, as data becomes more important to businesses, it presents a challenge: How can we ensure that data is protected while computation is performed on it? Additionally, how can we be certain that the code that is conducting the computation has not been tampered with? Confidential computing addresses these challenges by providing assurances with hardware-based, attested trusted execution environments (TEEs), which provide data integrity and confidentiality as well as code integrity. In this way, they ensure that a high level of trust can be achieved even when data and code are running within a multi-tenant cloud environment.
TEEs isolate data in memory. The TEEs used by Azure encrypt data in memory using keys managed by the underlying CPU firmware. The firmware also prevents data in memory from being altered by any software running outside the TEE that owns the memory. TEEs can help prevent unauthorized access to data in memory ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access