Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

8/5/2020
10:00 AM
Vinton G. Cerf
Vinton G. Cerf
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
100%
0%

Why Confidential Computing Is a Game Changer

Confidential Computing is a transformational technology that should be part of every enterprise cloud deployment. It's time to start unlocking the possibilities together.

When the Internet was first built, engineers were focused on getting it up and running, and functionality took precedence over protection. But when nefarious actors started to emerge, many pioneers across the industry came together to add more layers of defense. Encryption was used more widely, and the Internet became more secure. 

We've come a long way since those early days of the Internet when email showed up as an ARPANET project. It opened up new possibilities; mailing lists such as Sci-Fi Lovers and Yum Yum for restaurant reviews were created. Spam followed not very long after when someone from Digital Equipment Corporation sent out a job posting. Email is now ubiquitous, and organizations are now embracing technologies such as the Internet of Things and artificial intelligence. Cloud computing has entered the mainstream as organizations modernize their technology infrastructure, using the cloud to make fast changes, optimize costs, and get ready for the future. However, as cloud usage explodes, security can't be an afterthought. Security must be woven into the cloud computing fabric.

The Next Frontier of Data Protection
I believe that cloud computing will increasingly shift to private, encrypted services where users can be confident that their software and data are not being exposed to cloud providers or unauthorized actors inside their own organizations. This approach will foster innovation, allowing organizations to adopt the latest cloud technologies and alleviate concerns when it comes to data privacy and compliance.

When organizations, especially those in regulated industries, are ready to move workloads to the cloud, one of the biggest challenges is how to process sensitive data while still keeping it private. However, when data is being processed, there hasn't been an easy solution to keep it encrypted. Now there is. Confidential Computing is a breakthrough technology that encrypts data in use, while it is being processed.

Under the hood, Confidential Computing environments keep data encrypted in memory, and elsewhere outside the CPU. Data is decrypted within the CPU boundary by memory controllers using embedded hardware keys that a cloud provider does not have access to. It is a way for organizations to process data in the cloud while preserving confidentiality. A few weeks back, Google Cloud introduced our first Confidential Computing product called Confidential VMs. We are excited to offer this level of security and isolation while giving customers a simple, easy-to-use option that doesn't compromise on performance.

A United Approach
My role as a technologist is to try to be helpful, to provide clear explanations for how emerging technologies work, to responsibly inform policy developers and ensure their policies are implementable. I have learned that it's imperative that we work together to accelerate the adoption and acceptance of technology that moves us forward as a society.

Cloud providers, hardware manufacturers, and software vendors all need to work together to define standards to advance Confidential Computing. This is why Google was among the founding members of the Confidential Computing Consortium, operating under the umbrella of the Linux Foundation to facilitate adoption of Confidential Computing. We've joined forces with Intel, Microsoft, Red Hat, VMware, and others to shape technical and regulatory standards and support the development and adoption of open source tools. This is an encouraging start. It is only through sustained industry collaboration that the true potential of Confidential Computing will be realized.

Imagine being able to collaborate on genomic research in the cloud across geographies, across competitors, all while preserving privacy of confidential health records. Imagine being able to more quickly design or discover vaccines and to cure diseases as a result of secure collaboration. The possibilities are endless. Transformational technologies will truly solve problems that will make our lives better. I believe Confidential Computing is one of them. It will and should be a part of every enterprise cloud deployment. This is an ambitious goal that requires collaborative efforts to advance the technology. Now, it's time to start unlocking the possibilities together.

Related Content:

Vinton G. Cerf is vice president and chief Internet evangelist for Google. Cerf has held positions at MCI, the Corporation for National Research Initiatives, Stanford University, UCLA and IBM. Vint Cerf served as chairman of the board of the Internet Corporation for Assigned ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ayalyogev
50%
50%
ayalyogev,
User Rank: Author
8/11/2020 | 5:58:21 PM
Great article
Confidential Computing and Secure Enclaves will change security and enable new technologies in the same way PKI changed security and enabled e-commerce. Secure Enclaves allow the ability to bake security into the infrastructure and make sure all the data is protected automatically all the time, not just in memory.
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Hunny, I looked every where for the dorritos. 
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8567
PUBLISHED: 2021-01-21
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
CVE-2020-8568
PUBLISHED: 2021-01-21
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that conta...
CVE-2020-8569
PUBLISHED: 2021-01-21
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, ...
CVE-2020-8570
PUBLISHED: 2021-01-21
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executi...
CVE-2020-8554
PUBLISHED: 2021-01-21
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typicall...