Breaking News

Kioxia Broadens 8th Generation BiCS FLASH SSD Portfolio ASUS Announces Pro WS Platinum Series Power Supplies Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition Transcend Introduces 8TB Industrial SSD with Power Loss Protection

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Azure Confidential Computing Adds Cloud Security to Keep Out Hackers

Microsoft Azure Confidential Computing Adds Cloud Security to Keep Out Hackers

Enterprise & IT Sep 14,2017 0

Microsoft and Intel are offering a new cloud-computing service with more powerful encryption to secure data from hackers and government snoops.

Azure confidential computing offers a protection that to date has been missing from public clouds, encryption of data while in use. The Azure team, along with Microsoft Research, Intel, Windows, and Microsoft's Developer Tools group, have been working on confidential computing software and hardware technologies for over four years.

The service, now available to Microsoft's customers via an Early Access program, protects Microsoft Azure clients from malicious insiders with administrative privilege or direct access to hardware on which it is being processed. It also protects data against hackers and malware that exploit bugs in the operating system, application, or hypervisor, and of course any third parties accessing it without their consent.

Confidential computing ensures that when data is "in the clear," which is required for efficient processing, the data is protected inside a Trusted Execution Environment (TEE - also known as an enclave), an example of which is shown in the figure below.

A virtual enclave is essentially a black box that keeps anyone outside the customer -- including Microsoft itself -- from accessing the data. TEEs ensure there is no way to view data or the operations inside from the outside, even with a debugger. They even ensure that only authorized code is permitted to access data. If the code is altered or tampered, the operations are denied and the environment disabled. The TEE enforces these protections throughout the execution of code within it.

Azure confidential computing will offer two ways to create these secure enclaves. One is based on Microsoft's own server software, while the other uses Intel chips with that company's built-in security features, according to Azure Chief Technology Officer Mark Russinovich.

Initially Microsoft supports two TEEs, Virtual Secure Mode and Intel SGX. Virtual Secure Mode (VSM) is a software-based TEE that's implemented by Hyper-V in Windows 10 and Windows Server 2016. Hyper-V prevents administrator code running on the computer or server, as well as local administrators and cloud service administrators from viewing the contents of the VSM enclave or modifying its execution. Microsoft is also offering hardware-based Intel SGX TEE with the first SGX-capable servers in the public cloud.

Microsoft already uses enclaves to protect everything from blockchain financial operations, to data stored in SQL Server, and its own infrastructure within Azure. While the company has previously spoken about its confidential computing blockchain efforts, known as the Coco Framework, Microsoft today announced
the use of the same technology to implement encryption-in-use for Azure SQL Database and SQL Server. This is an enhancement of Microsoft's Always Encrypted capability, which ensures that sensitive data within a SQL database can be encrypted at all times without compromising the functionality of SQL queries. Always Encrypted achieves that this by delegating computations on sensitive data to an enclave, where the data is safely decrypted and processed.

Microsoft's customers can try out Azure confidential computing through an Early Access program, which includes access to Azure VSM and SGX-enabled virtual machines, as well as tools, SDKs, and Windows and Linux support to enable any application in the cloud to protect its data while in use.

The new service means that Microsoft won't have the capability to turn over data in response to government warrants and subpoenas, an issue at the heart of a current Microsoft lawsuit against the U.S. government fighting the requirement to turn over client data, sometimes without the customer's knowledge.

Google has been working on its own chips, called Titan, that offer a different type of security against hackers in cloud networks. That effort makes sure that when machines boot up, every piece of Google software is valid and hasn't been tampered with.

Tags: Microsoft azurecloud computing
Previous Post
Facebook Limits Ad Targeting Features Based on Religion, Education
Next Post
Netflix Coming two More Countries Through Global Distribution Deal With France's Orange

Related Posts

  • ChatGPT is now available in Azure OpenAI Service

  • How Easy is Cloud Migration for Enterprises?

  • FedEx and Microsoft Announce New FedEx Surround Platform For End-to-end Commerce

  • The Coca-Cola Company Partners With Microsoft

  • Alibaba Announces $28 billion Cloud Investment

  • NBA Announces Multiyear Partnership With Microsoft

  • Baidu 'Cloud Phone' Lets You Run Android Apps on the Cloud

  • NYS Department Of Labor Partners With Google, Deloitte, and Verizon To Make It Easier for New Yorkers To File For Unemployment Insurance Applications

Latest News

Kioxia Broadens 8th Generation BiCS FLASH  SSD Portfolio
Enterprise & IT

Kioxia Broadens 8th Generation BiCS FLASH SSD Portfolio

ASUS Announces Pro WS Platinum Series Power Supplies
PC components

ASUS Announces Pro WS Platinum Series Power Supplies

Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device
Consumer Electronics

Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device

ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition
GPUs

ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition

Transcend Introduces 8TB Industrial SSD with Power Loss Protection
Enterprise & IT

Transcend Introduces 8TB Industrial SSD with Power Loss Protection

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Noctua NH-D15 G2

Noctua NH-D15 G2

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed