| | 19February 2023Network InfrastructureThe emerging hardware-based technology called Confidential Computing is set to underpin multiple new ways of securing your networks and data.At the core of Confidential Computing is a system's ability to keep the code and data it is working on hidden, even from the device's owner or administrator (and even if the device is hacked!). Such a system is also able to prove to a remote party, through a process called attestation, what code has executed, in which configuration, on what data, and what was the result. Said another way, whatever the system says has happened, really did happen, and whoever had the system in their possession, was not told what that was and couldn't do anything about it ­ short of powering it off.If you own a mobile phone or a gaming console, you have already been touched by this technology, most likely without even being aware of this. On a mobile phone, Confidential Computing protects your payments and biometric data. Gaming consoles use it to prevent piracy, thwart attempts at cheating, and reject knock-off peripherals.These days, Confidential Computing is marching into the datacenter and beyond. With a slew of offerings from nearly every major hardware manufacturer and cloud service provider, across virtually all device categories ­ CPUs, GPUs, and peripherals ­ Confidential Computing delivers previously unimaginable capabilities.The first and most obvious application is to Zero Trust. With application of Confidential Computing techniques, device management ceases to be a best-effort affair, because the designated portions of each device can now be assessed and fully trusted. Since each device is guaranteed to tell the truth about its state and patch level, misconfigurations can be detected and remediated with perfect accuracy. Beyond just code and configuration, you can be guaranteed that each device you manage is provisioned with exactly the secrets and policies you designate, no matter where in the world that device is located, and regardless of whose possession it is in. And best of all, any device can be attested ­ whether you own or manage it, or someone else does.Looking another way, Confidential Computing ensures that access to data is granted only to specified code, never to any other actor - human or otherwise. When used in the cloud, this capability enables mutually distrustful institutions to collaborate on highly sensitive datasets without revealing the portions of the overall data they own to each other, or even to the Cloud Service Provider. The parties, such as a bank and a hospital, agree on the code that should see the data (such as machine learning models), and only that code will ever be able to access the complete dataset, not the individual data administrators on either side. Without Confidential Computing, such scenarios used to require CONFIDENTIAL COMPUTING: THE EMERGING SECURITY MULTI-TOOLBy Mark Novak, Director, Applied Security Architecture, JPMorgan ChaseMark NovakCXO INSIGHTS
< Page 9 | Page 11 >