Azure Confidential Computing and Zero Trust
by Razi Rais, Jeff Birnbaum, Graham Bury, Vikas Bhatia
Chapter 3. Azure Confidential Computing Portfolio
Azure confidential computing (ACC) consists of a portfolio of products and supporting services that enable customers to protect sensitive data while in use in accordance with the definitions and principles outlined in Chapter 1. This portfolio includes VMs, container-based platform as a service (PaaS), and other PaaS and software as a service (SaaS). The portfolio as of November 2023 is summarized in Figure 3-1.
This chapter is organized by grouping the ACC portfolio as follows:
-
VMs, with both VM-level and code-level isolation
-
Container-based PaaS, with VM-level, code-level, and container group-level isolation
-
Supporting services and features such as attestation, trusted launch, and OS disk encryption with customer-managed keys
-
Other ACC-enabled SaaS and PaaS
Figure 3-1. Azure confidential computing portfolio
ACC VMs
ACC VMs are building blocks for customers who want to migrate their existing VM workloads to Azure. They include confidential VMs, VMs with application enclaves, and confidential VMs with confidential GPUs.
Confidential VMs
Confidential VMs offer strong security and confidentiality, as well as hardware-enforced boundaries, to meet the most stringent security requirements. Confidential VMs are particularly useful in scenarios where customers are migrating existing workloads and seeking to lift and shift ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access