Breaking News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards Sony Unveils 1000X THE COLLEXION Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Azure Confidential Computing Adds Cloud Security to Keep Out Hackers

Microsoft Azure Confidential Computing Adds Cloud Security to Keep Out Hackers

Enterprise & IT Sep 14,2017 0

Microsoft and Intel are offering a new cloud-computing service with more powerful encryption to secure data from hackers and government snoops.

Azure confidential computing offers a protection that to date has been missing from public clouds, encryption of data while in use. The Azure team, along with Microsoft Research, Intel, Windows, and Microsoft's Developer Tools group, have been working on confidential computing software and hardware technologies for over four years.

The service, now available to Microsoft's customers via an Early Access program, protects Microsoft Azure clients from malicious insiders with administrative privilege or direct access to hardware on which it is being processed. It also protects data against hackers and malware that exploit bugs in the operating system, application, or hypervisor, and of course any third parties accessing it without their consent.

Confidential computing ensures that when data is "in the clear," which is required for efficient processing, the data is protected inside a Trusted Execution Environment (TEE - also known as an enclave), an example of which is shown in the figure below.

A virtual enclave is essentially a black box that keeps anyone outside the customer -- including Microsoft itself -- from accessing the data. TEEs ensure there is no way to view data or the operations inside from the outside, even with a debugger. They even ensure that only authorized code is permitted to access data. If the code is altered or tampered, the operations are denied and the environment disabled. The TEE enforces these protections throughout the execution of code within it.

Azure confidential computing will offer two ways to create these secure enclaves. One is based on Microsoft's own server software, while the other uses Intel chips with that company's built-in security features, according to Azure Chief Technology Officer Mark Russinovich.

Initially Microsoft supports two TEEs, Virtual Secure Mode and Intel SGX. Virtual Secure Mode (VSM) is a software-based TEE that's implemented by Hyper-V in Windows 10 and Windows Server 2016. Hyper-V prevents administrator code running on the computer or server, as well as local administrators and cloud service administrators from viewing the contents of the VSM enclave or modifying its execution. Microsoft is also offering hardware-based Intel SGX TEE with the first SGX-capable servers in the public cloud.

Microsoft already uses enclaves to protect everything from blockchain financial operations, to data stored in SQL Server, and its own infrastructure within Azure. While the company has previously spoken about its confidential computing blockchain efforts, known as the Coco Framework, Microsoft today announced
the use of the same technology to implement encryption-in-use for Azure SQL Database and SQL Server. This is an enhancement of Microsoft's Always Encrypted capability, which ensures that sensitive data within a SQL database can be encrypted at all times without compromising the functionality of SQL queries. Always Encrypted achieves that this by delegating computations on sensitive data to an enclave, where the data is safely decrypted and processed.

Microsoft's customers can try out Azure confidential computing through an Early Access program, which includes access to Azure VSM and SGX-enabled virtual machines, as well as tools, SDKs, and Windows and Linux support to enable any application in the cloud to protect its data while in use.

The new service means that Microsoft won't have the capability to turn over data in response to government warrants and subpoenas, an issue at the heart of a current Microsoft lawsuit against the U.S. government fighting the requirement to turn over client data, sometimes without the customer's knowledge.

Google has been working on its own chips, called Titan, that offer a different type of security against hackers in cloud networks. That effort makes sure that when machines boot up, every piece of Google software is valid and hasn't been tampered with.

Tags: Microsoft azurecloud computing
Previous Post
Facebook Limits Ad Targeting Features Based on Religion, Education
Next Post
Netflix Coming two More Countries Through Global Distribution Deal With France's Orange

Related Posts

  • ChatGPT is now available in Azure OpenAI Service

  • How Easy is Cloud Migration for Enterprises?

  • FedEx and Microsoft Announce New FedEx Surround Platform For End-to-end Commerce

  • The Coca-Cola Company Partners With Microsoft

  • Alibaba Announces $28 billion Cloud Investment

  • NBA Announces Multiyear Partnership With Microsoft

  • Baidu 'Cloud Phone' Lets You Run Android Apps on the Cloud

  • NYS Department Of Labor Partners With Google, Deloitte, and Verizon To Make It Easier for New Yorkers To File For Unemployment Insurance Applications

Latest News

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards
GPUs

ASUS Announces T1 GeForce RTX 5070 and RTX 5060 Ti Graphics Cards

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards
PC components

COLORFUL Launches iGame B850M ULTRA Series Micro-ATX Motherboards

Sony Unveils 1000X THE COLLEXION
Consumer Electronics

Sony Unveils 1000X THE COLLEXION

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors
Enterprise & IT

Samsung Launches Next-Gen Odyssey, ViewFinity and The Movingstyle Essential Monitors

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor
Consumer Electronics

LG Electronics Introduces World’s First Native 1000Hz Full HD Gaming Monitor

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed