Confidential Computing in the GenAI Era with Nelly Porter
Nelly Porter, Google’s confidential computing lead, shares best practices for implementing confidential computing, the future of confidential computing in the generative AI era, and Google Cloud’s unique approach and advantages in this field.
Transcript
This is Techstrong tv. Hi everyone. Welcome back here to Techstrong tv.
Our next guest is the first time she's been on here with us. I think it's gonna be a good, a good session. I want to introduce you to Nelly Porter.
Nelly is the Director of Product management for GCP Confidential computing and encryption, of course, GCP, Google Cloud. Nelly, welcome to Text Trunk tv. It's great to have you on here.
Thank you so much, Alan, for having me. I really looking forward to this conversation and the topic is very important, confidential computing. Yes.
It's, let's make it confidential. Yes. It's, yeah.
And it's more important every day. Nelly, before we jump into that though, look, this, let's hear a little bit about you. I, I always like to let our audience know who they're talking or who they're listening to, so, right.
If you don't mind, give us a little bit of the Nelly Porter story. Nelly Porter story. Uh, thank you so much for asking.
I am working for Google for eight years already, so I'm long time Googler. I started working on very interesting areas. As usual Google, you will find plenty of interesting areas in security, in particular in what they called infrastructure security.
And the first one project that I had chance to work on was what we called Titan. And Titan is very, very small asic very small, uh, things we call the truth of trust as that we put in every single host in GCP to ensure that we can identify them, know where it's coming from, and ensures that all levels software is not tempered, it's not changed. So we first publish the blog on explaining what is art because it's complicated story.
And the first next conference is that our, again, um, uh, leadership known title, we force them to wear it in the ear. And mm-hmm. Again, moving on from that, done quite a bit of work on securing and accounting, our help advisor, because again, in GCP, most of our workloads, customers, workloads and everything, they're running, running in virtual environments and ability for us to again, harden, uh, this middle layer that we call hypervisor.
Incredibly critical. So all of these years it's mostly security, infrastructure, security. And from day one, I started to work on confidential computing and encryption.
It's my area for expertise. So it took us long time until again, our customers had the first introduction to confide Google 2020. And we, again, producing a lot of interesting generation in the space.
I'm sure there will be talking to them. Absolutely. So, and as I mentioned, you're the director of product management for gcps confidential computing and encryption product line.
We should start with basics though. What you, you know, because look, a lot part of our audience are security folks, but we have developers, digital transformation, you know, run the gamut. Tech people.
When we say confidential computing and encryption, how would you define confidential computing? I don't think I would start with confidential computing in this definition. I would start with what customers or what our, uh, DevOps quite familiar with and encryption and everything that you do when you bring your data to GCP mm-hmm.
So we have ability to protect your data and you bring it to GCP and we have some products that help you in GCP to do this work. We have products that protect your data, whatever you brought up at track. And it's set of cloud key as cloud data sounds and other products that also part of my portfolio that be helping customers to do this job.
So that was the third step, was missing how to protect data, whether the data is actually in use when you run your application and using this data to perform whatever you need to do. Talking about SPA or talking about Hadoop web produce, what happened with your data in the moment when it's actually performing some useful function. And here we're missing ability to protect it, create those cryptographic around those workloads with attach sensitive data.
And that's what confidential computing is all about. It's ability for us to completely cycle this festa and add a third lab to this tool to protect data and its processing and its in use. Excellent.
Very good. Um, now look, I've been in security 25 more. I'm ashamed to tell you long time.
Um, and nothing is bulletproof. Nothing is a hundred perseverated. Stuff happens, breaches happen.
But so much of what we see in everyday headlines around security incidents really could be avoided because most breaches still today, you know, I take place, well, it's human error, but it it's also lax lax security compliance, right? Not, not compliance complying with a specific GDPR or something, you know, or, or regulation, which is basic security process of policy. I do Often, I do, that's a great word, right?
Just pure bad hygiene, bad cyber hygiene. That's, that's what gets us. And for as long as I've been in security and I I Nelly I've been involved in, in education and training, I've been involved.
I, I started a security company in Colorado 23 years ago. Network security primarily. Um, but we've always talked about implementing best practices, you know, improving the, the person behind the keyboard, if you will.
The weak link, if you would mind, right. From your perspective where you sit and you have a great perspective in your seat. Right.
Talk to us a little bit about best practices to implement confidential computing to get the organization on board here with this. And, and again, I don't wanna blame it just on people. There is an element of platform and so forth, but generally it's, it's people a lot.
Um, especially, you know, look, everyone is an AI expert today. We're using AI and it's sucking our data and spit it back out in different ways. Um, talk about what do you think of best practices and what Google Cloud's doing that binny's a little different, that's a little bit more effective.
Before I will touch AI topic, I want to kind of slightly change how I see provide seed, why implementing security guide, it's so complicated. And I think complexity that we introduce with those security requirements or compliance requirements is driving normal human being away from implementing them. And any chance to avoid implementing this multilayer complexity is actually the, the pass of flu resistance as the ization in humans are taking.
So I think from GCP and from our side, security was paramount, but what else do we understood that without usability, performance and scale security is not going to succeed. And I'm talking about the big security, but I can give you completely random, unrelated to our topic. Example of two factor authentication.
It's like how many years we need to convince people, administrators, and normal human beings, is it second factor authentication is actually a beneficial, and still we can have so many passwords in the wild and doesn't have that can act and because it's complicated. So removing complexity from security, make it, it enablement by different, but again, ability for you to verify that those security controls are in place because you need to provide to your regulators, auditors or to yourself is absolutely critical to us. And that's why one of the biggest and most important thing in confidential computing coming back was for us, those three principles, it has to be secure in the way how, again, hardware insecurity is implemented.
And we spend a lot of time ensure that those provinces, those claims is true. But the second it has to be incredibly usable. And again, to enable confidential environment, you literally need to check it.
It's exactly quack like a normal environment and beyond. It does exactly the same thing. But these one chat bots or one flag in your, again, uh, terraform, so CLI, this environment magically becoming confidential and the sir it's necessity, something with confidential and other things started to bring in place.
They called it cryptographic attestation. Its ability for you to verify that claims that I am offering you is actually in place. That your environment really running encrypted.
It's the environment that's sitting beneath you is not, is not changed. So all of that you can verify by yourself in utilizing Google at distinction services, but a combination of usability, incredible scale, you can run again, your huge applications and why it's important because again, is the role of ai, but there is no small needle time apps you can run in human traps. Your ability to serve again the model, it means the model needs to run in C-P-U-G-P-U in all of those environment.
It's a huge workload. So scale and performance, it was critically important for us when we're talking about security. The security alone and security guidance alone is always need to be vetted and make appropriate all other dimensions that our customer's looking at.
And it's never only security, it's always everything. And security and compliance. Absolutely.
And this is, again, as I said, isn't security a mistake that we made way back, which is thinking of security in its old silo. That's not Part of it. It was not part of, you know, it was, it was, it was the redheaded stepchild.
It was always you always being special. Always special. Yeah, it's special.
Um, that's a good word. Special. But, you know, but I, so here's the good news though, is I really feel like in my heart, I feel this, that we've made a lot of progress over the last five, six years and it's still special, but it's, it's more integrated.
It's more part of, and a lot of that is, is frankly with Google Cloud and some of the other cloud providers who, you know, with the shared responsibility model have what to say about security and are bringing some needed, uh, not grownups, but a bringing, bringing some more, more firepower, more resources and more Pragmatic approach. Yes. More pragmatic approach to all of those security guidelines and requirements and helping customers to implement them in such way that still not be barriers for adapting those requirements and security requirements.
You are absolutely, and without that, we couldn't, couldn't help our customers with all. Yeah. But so, but there's, and there, so there's reason to be optimistic, there's reason to be hopeful.
We are in spite of what you may hear on the headlines and every social security numbers breached and all of these other things were, you know, very recently. Um, on the other hand though, the last two years have been the dawn of this AI era, right? Everybody's talking generat of ai.
Everybody, you know, everybody that comes here to my office shows me stuff they're working on. Let me see what, let me show you what I whipped up on Gemini or, or whatever, right? Their AI choice.
Yes. And well, no, now I see people, they bring front ends, they'll plug in all of them on the back end and you get to pick, oh, I'm going to use, you know, claw for this, but I'll use GPT-4 oh for that Gemini for that llama for that some good right? And, and amazing stuff.
I mean, every time I see more and more I'm like just blown away. What is this going to do though for confidential computing? Is this, is this our best friend or our worst enemy or somewhere in between?
I do believe that it's the best friend and the best friend because it will expedite to the understanding of the value that confidential computing is opening. And the reason why I am so hopeful and looking forward with that in confidential computing society community, by the way, we formed Google Intel one, well, tangent point and Google, Intel and Microsoft long time ago formed contr computing consortium because we understood that any, any company alone would not be able to move its huge effort forward. And the funniest story, it's happened, a discussion about that on Google offices because we have really find nice food.
So all representative of companies come together to discuss the conditions and to discuss how we will form these consortium to include the whole entire. So it was a lot of fun, uh, to, to to, to do that. But again, coming back to ai, I think confidential computing, trying to ensure that people understand the value by protecting and using data important into, in their applications.
Now, there is no separation. When we are talking about ai, the data is driving those models. It's actually you training on data.
You fine tuning on data and you actually speaking out data as a result of users' pros. And again, when those models are used for inference for certain. So data is everywhere and the amount of data really in humanly generated data is becoming a problematic and it's not so easy to find.
And it's includes so much very important information about people, about organizations, about what they do, the, the interesting things about what else they called for the app. And this means whatever you feed into this model and that there is two, two interesting aspects. If you film the garbage, you will get the garbage in, garbage out.
So you need to run and use the high quality dataset to be able to make something useful out of this model. And as a result of that, you have to protect this. So I do believe as an introduction and the whole attention to Jenny and I and uh, alliance, and again, AL AI in general is bringing and giving really huge to all those capabilities that we are all working on to ensure that we can protect our data, our customer's data in all of those stages and all of those CIS pipeline.
Because one additional thing that happened is LL it's also something as we, we've been in security very long, we were trying to separate as the layers. We had the tools to protect workloads, your applications, and we ensure that the whole ci CD pipeline, uh, again helping, we used encryption to protect data and we had treat it separately. The data protection technology elements, uh, push it all upside down.
There's no separation between application, the model configuration and data. It's all together. So you have to protect all of them.
You have to present model when it's loaded and operating. You need to protect, especially when this model is fine tuned by corporate data, by organizational data and has significant IP in that you need to protect data, you need to protect. And having confidential computing is incredibly strong tool to do.
Agreed mely, unfortunately we're outta time to 15 minutes. I would probably post to 20 minutes or Oh. But I want thank you for coming on and, and raising the awareness of this, right?
Making sure it's on people's radar scopes and on their mindset because it's in, it's, you know, no all getting inside and everything else. This is incredibly important stuff. And, and, and as we continue moving forward with gen ai, gen ai and as we continue hybrid cloud and, and you know, exploring all of the great technology that we have available plus today, if we don't get this right, it, it's for nor in many ways.
Right. We'll continue kind of one step forward, two steps back. Thank you so much Nelly.
You so much happy you back on. Okay. Absolutely.
Thank you so much for inviting. It was pleasure. Okay.
Nelly Porter, director of product management for GCP confidential computing and encrypt encryption over at Google Cloud here on text R tv. We're gonna take a break. We'll be right back.