Creating New Levels of Security with Containers and Confidential Computing

Jul 23, 2024 | Blog

Data breaches are becoming increasingly common. It’s more important than ever to find robust solutions that protect sensitive information. Recent high-profile data breaches underscore the necessity for fresh approaches to data protection. Breaches like these are unsettling and highlight the critical need for innovation in data security.
This particular data breach appears to have originated from stolen credentials for a workspace hosted by a third-party AI data platform. A report from Google’s Mandiant suggests several approaches to mitigate these types of attacks including “credential monitoring, the universal enforcement of MFA and secure authentication, limiting traffic to trusted locations for crown jewels, and alerting on abnormal access attempts.” While these are necessary steps to deter credential theft, is there more that can be done to protect an organization’s most sensitive data behind the firewall?

At Sylabs, we envision a future where sensitive data sets such as this remain encrypted in armored containers throughout their entire lifecycle, accessible only to trusted applications that are running in trusted execution environments using confidential computing technologies.

Understanding Confidential Computing and Containers

Confidential computing is an emerging set of technologies focused on trust and privacy in data processing. It involves creating secure enclaves within a processor, called a Trusted Execution Environment (TEE), whose purpose is to shield the data being processed from the surrounding environment, including the CPU and administrators. This “black box” approach ensures that sensitive workflows are protected from unauthorized access.

We believe that combined with confidential computing, containers will play a critical role in creating a more secure future that opens up a world of possibilities to accomplish more with data while protecting customers and intellectual property. By leveraging containers alongside confidential computing, we can significantly reduce the friction associated with adopting confidential computing technologies. Containers offer a seamless and efficient way to encapsulate and deploy units of code within secure enclaves, ensuring that data remains protected throughout its lifecycle, even during processing. This approach minimizes the risk of breaches like the one AT&T experienced. By isolating sensitive workloads and encrypting data within these secure environments, organizations can mitigate threats from both external attackers and internal vulnerabilities.

The Ecosystem of Confidential Computing

Without a doubt, we are still in the early days with an emerging ecosystem that includes key players such as hardware vendors, cloud service providers (CSPs), and software companies working to create the infrastructure needed to make this level of data security a reality. Virtually every major chipmaker is investing heavily in the development and implementation of TEEs, which includes developing the processor code with the goal of making these secure environments as small as possible so as to eliminate vulnerabilities. Each of these vendors has established different approaches, and they’re not always compatible.

Collaborative efforts, such as the Confidential Containers Project (CoCo) within the Cloud Native Computing Foundation (CNCF), have been established with the goal of standardizing and promoting these technologies. As with any nascent technology, compatibility, and standardization are important factors for success if we are to reach a point where a unified framework is established and widespread adoption is a reality.

Addressing Data Breaches with Confidential Computing

The rise in data breaches is apparent on a weekly basis. According to the IRTC 2023 Annual Data Breach Report, there was a 72% increase in these types of breaches from 2020 to 2023. It’s clear that organizations need to find new ways to protect their sensitive data – data which is seemingly only going to increase in value as the AI era advances. By limiting sensitive data exposure using confidential computing, organizations can significantly reduce their threat exposure, ensuring that their data is protected even in a perimeter breach.

For instance, in the event of a cloud provider compromise, data processed within an enclave remains protected. Even insider threats are mitigated, as administrators can manage the system without accessing the data. This approach narrows the scope of potential vulnerabilities providing a higher level of security assurance.

Multiparty Compute and Confidential Computing with Containers

Besides being comprised of sensitive customer information and personally identifiable information (PII), organizational data often constitutes critical intellectual property that when given the proper guardrails, can be leveraged for such things as federated learning and multi-party computing for creating machine learning models that might not otherwise have been possible. Multiparty computing is a powerful concept that allows multiple parties to combine their datasets for enhanced insights without exposing their data to each other. In this way, an organization can productize its data for licensing to other organizations without the concern of losing the exclusivity or exposure of that data.

Remote attestation plays a key role in this paradigm. It is about building trust in both hardware and software configurations by authenticating and verifying that the environments are secure and have not been tampered with. In a multi-party use case, remote attestation allows organizations to understand and trust the hardware and software their most sensitive data will be exposed to. This trust is essential for securely sharing and collaborating on data-driven projects, ensuring that proprietary information is safeguarded.

By utilizing remote attestation alongside advanced encryption techniques and secure enclaves, organizations can ensure that data remains protected throughout its lifecycle. When applied to containerized workflows, data owners gain transparency into the software supply chain of the containers that their data is exposed to, allowing risk-based decisions to be made in real-time. In multi-party scenarios, this transparency provides the necessary information to ensure the confidentiality and integrity of sensitive data is protected, and also facilitates compliance with regulatory requirements, making it an essential component in the secure handling of organizational data.

Confidential Computing, Containers, and AI

The future of confidential computing and containers is promising, with significant potential across various industries. In the next 5-10 years, confidential computing technologies are expected to become standard for cloud computing, with industries such as healthcare, energy, transportation, and defense benefitting immensely from them. The combination of IT and operational technology (OT) requires robust security measures and confidential computing offers a solution to protect critical infrastructure from emerging threats.

We see containers as an important enabling technology that will make the adoption of confidential computing easier and more seamless. Containers provide a practical and efficient way to deploy and manage applications within secure enclaves, reducing friction and simplifying the process of leveraging confidential computing. By integrating containers with confidential computing, organizations can enhance their security posture and unlock new possibilities for data collection and collaboration.

While the technology is still in its infancy, it is not too early to develop practices that begin to implement these technologies and benefit from the protection that containerization can provide. For CIOs, CTOs, and CSOs, integrating confidential computing solutions into their organization’s security operations should be a strategic priority. Start by identifying the most sensitive data within your organization and consider how these technologies can protect it. Implementing confidential computing for the most critical workloads first allows you to gain experience and develop a phased approach for broader adoption.

Sylabs has already started assisting our customers in this journey by providing solutions built to seamlessly integrate containerization into their operational environments and help them leverage confidential computing. Our goal is to make adoption easy, enabling organizations to protect their data without needing deep expertise in these technologies.

If you’re interested in learning how Sylabs can help you on your journey to a more secure environment for your data, contact us at support@sylabs.io to arrange a discussion. We look forward to getting you established for success.

For additional insights, I discussed this topic on a recent Cyber Insiders Podcast episode focused on confidential computing’s role in enhancing cybersecurity:

Related Posts