O'Reilly Media report: Azure Confidential Computing and Zero Trust
We are excited to announce the publication of our first O'Reilly Media report: Azure Confidential Computing and Zero Trust. We felt a need to make it clear to our customers, and the industry as a whole, what confidential computing is, how it relates to the foundational principles of zero trust, what use cases it enables, and the depth and breadth of confidential computing in Azure.
Confidential computing is the processing of data in a hardware based and attested trusted execution environment (TEE). This helps enforce zero-trust principles down to the hardware level in several ways. For example, it supports the principle of enforce least privileged access by ensuring only the software that writes to a memory location may read it or write over it. It also supports the principle of always verify access through the confidential computing requirement of attestation of the TEE. This allows the good state of the TEE hardware and software to be verified before sensitive data is unlocked and available for processing. And finally, it supports the principle of assume breach by removing the cloud provider's host OS and hypervisor from software that must be trusted.
Our report contains several links to industry standards, our ACC case studies, and other reference material. Please take a look and share with your colleagues!
Published on:
Learn moreRelated posts
Adams Bridge: An Accelerator for Post-Quantum Resilient
The name Adams Bridge is inspired by the mythological structure which was said to span a vast gulf between two landmasses. In the realm of cry...
Azure AI Confidential Inferencing: Technical Deep-Dive
Generative AI powered by Large Language Models (LLMs) has revolutionized the way we interact with technology. Through chatbots, co-pilots, and...
General Availability: Azure confidential VMs with NVIDIA H100 Tensor Core GPUs
Today, we are announcing the general availability of Azure confidential virtual machines (VMs) with NVIDIA H100 Tensor core GPUs. These VMs co...
Verify the integrity of Azure Confidential Ledger transactions with receipts and application claims
In today's digital landscape, the integrity and confidentiality of transactional data are paramount. Microsoft’s Azure Confidential Ledger off...
Memory Protection for AI ML Model Inferencing
This article was originally posted on Confidential Container Project's blog by Suraj Deshmukh & Pradipta Banerjee. Read the original artic...
General Availability: Azure Managed HSM Backup/Restore when Storage is Behind a Private Endpoint
We are excited to announce the General Availability of support for Azure Key Vault Managed HSM backup/restore when the sto...
Public Preview: Azure Managed HSM Backup/Restore when Storage Account is Behind a Private Endpoint
We are excited to announce the Public Preview of support for Azure Key Vault Managed HSM backup/restore when the storage accoun...
General Availability: Managed HSM Networking Settings in Azure Portal
We are excited to announce the General Availability of networking settings for Azure Key Vault Managed HSM on the Azure po...
Confidential Temp Disk Encryption for Confidential VMs in Public Preview
We are announcing the public preview of confidential temp disk encryption for confidential VMs. Until recently, confidential encryption has o...
Try new Azure confidential ledger features, including an Azure Blob Storage Marketplace application
To support customers in regulated industries and compliance scenarios who asked about higher integrity protection of storage blobs, the Azure ...