Loading...

Azure announces next generation Intel SGX confidential computing VMs

Azure announces next generation Intel SGX confidential computing VMs

Microsoft Azure was the first major cloud provider to announce support for confidential computing. Over the past 3 years, we have helped customers leverage the benefits of Azure confidential computing to scale and protect their most privacy and security sensitive workloads in the public cloud. Earlier this year we became the cloud provider with the broadest support for confidential computing cloud services.

 

Today, we are announcing game changing upgrades to the DC-series family with the public preview of DCsv3 and DCdsv3-series Azure Virtual Machines.

 

DC-series VMs are unique as they offer support for Intel® Software Guard Extensions (Intel SGX). These VMs allow customers to create enclaves that protect data while processing in the CPU by keeping it encrypted and isolated in memory, thus protecting data from the operating system, hypervisors with escalated privileges, and Azure operators.

 

Now with the 3rd Gen Intel® Xeon Scalable processors, the capabilities of DC-series have improved substantially. The size of the Enclave Page Cache (EPC) for Intel SGX has increased 1500x to support much larger workloads, regular memory has been increased 12x and up to 48 CPU cores enable more performance for memory intensive workloads while maintaining data confidentiality.

 

DC-series features Intel SGX which offers application-level isolation for granular security control. Many customers desire protections and encryption at the VM-level to “lift and shift” existing VMs into a more protected infrastructure. With this generation, we’re enabling customers to encrypt their VM with separate and unique keys using Intel® Total Memory Encryption – Multi Key, which enables always-on encryption and provides protection against tenants on the same node. Leveraging both, customers using Intel SGX get confidential computing in application enclaves and additional protection for all software in their VMs.

 

Microsoft Azure Attestation and Azure Kubernetes Service (AKS) support

 

Attestation is the process of verifying that software binaries are executing on a trusted hardware platform. Intel® Xeon Scalable processors supports ECDSA-based attestation solutions to remotely verify identities of the SGX enclaves. Microsoft Azure Attestation supports ECDSA, is free and reinforces the verifiable security promises made through a unified framework for attesting multiple trusted execution environments.

 

We are extending Azure Kubernetes Service (AKS) support to the confidential computing SGX add-on for AKS. This added support significantly improves the performance of memory intensive workloads that utilize Confidential containers, such examples include data analytics, ML training and inferencing and multi-party data computation. 

 

How customers are succeeding with Azure confidential computing

 

Confidential computing has proven useful for AI/ML and Blockchain scenarios. We are partnering with Mithril Security and iExec, to enable them to utilize the benefits of Intel SGX in protecting sensitive machine learning code and data.

 

“Azure confidential computing has enabled us with the latest generation of Intel SGX. By using the 3rd Generation Intel Scalable Processors, Mithril Security have built a Confidential AI solution with data-in-use protection and code attestation that addresses customers desires for privacy, scalability, and ease of use. In the past, SGX memory constraints made it impossible to have reasonable throughput for AI workloads, this has been overcome with latest generation of DC-series.”  Daniel Huynh, CEO of Mithril Security

 

“Azure confidential computing efficiently addresses security concerns by protecting data-in-use. iExec Blockchain platform leverages Intel SGX to enable high-value data to be widely shared and used while preserving its privacy and ownership. The coming together of these unique capabilities on iExec Blockchain platform empowers AI developers to protect their intellectual property, whilst creating new economic opportunities for AI developers.”  Lei ZHANG, Director of Information Security, iExec Blockchain Tech

 

Learn more about the preview

mmcrey_0-1645600135798.png

 

The preview starts in East US 2, Central US, North Europe and West Europe. Over the coming months, we will expand to more datacenters for disaster recovery and high availability capabilities, as we approach general availability.

 

If you’d like to learn more, please see the VM specificsfurther documentation, onboarding guide and frequently asked questions.


Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries.

Published on:

Learn more
Azure Confidential Computing Blog articles
Azure Confidential Computing Blog articles

Azure Confidential Computing Blog articles

Share post:

Related posts

Azure VMware Solution - Using Log Analytics With NSX-T Firewall Logs

Azure VMware Solution How To Series: Monitoring Azure VMware Solution   Overview Requirements Lab Environment Tagging & Groups Kusto ...

3 hours ago

Troubleshoot your apps faster with App Service using Microsoft Copilot for Azure | Azure Friday

This video provides you with a comprehensive overview of how to troubleshoot your apps faster with App Service utilizing Microsoft Copilot for...

3 days ago

Looking to optimize and manage your cloud resources? Join our Azure optimization skills challenge!

If you're looking for an effective way to optimize and manage your cloud resources, then join the Azure Optimization Cloud Skills Challenge or...

3 days ago

Have a safe coffee chat with your documentation using Azure AI Services | JavaScript Day 2024

  In the Azure Developers JavaScript Day 2024, Maya Shavin a Senior Software Engineer at Microsoft, presented a session c...

3 days ago

Azure Cosmos DB Keyboard Shortcuts for Faster Workflows | Data Explorer

Azure Cosmos DB Data Explorer just got a whole lot easier to work with thanks to its new keyboard shortcuts. This update was designed to make ...

3 days ago

How to Use Azure Virtual Network Manager's UDR Management Feature

What will you learn in this blog? What is Azure Virtual Network Manager’s UDR management feature? How UDR management simplifies route setting...

3 days ago

Secure & Reliable Canonical Workloads on Azure | GA Availability

With Azure's partnership with Canonical, the industry standard for patching Linux distributions on the cloud is elevated. The collaboration hi...

4 days ago

Azure VMware Solution now available in Italy North, Switzerland North and UAE North

Azure VMware Solution continues to expand its reach, as it is now accessible in Italy North, Switzerland North, and UAE North. With this expan...

4 days ago

Connecting Azure to Mainframes with Low Latency

Many organizations are running their mission critical workloads on the mainframe and would greatly benefit by incorporating the mainframe in t...

4 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy