Confidential Computing – Rishabh Poddar, Opaque Systems
Opaque Systems CEO Rishabh Poddar explains how confidential computing will improve data security.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're talking with rishab Potter. Who is CEO for opaque systems and we're talking about confidential Computing in a lot of people will go. Well.
What the heck is that? So let's just jump right into it and I don't know we shot. Do you want to give an explanation of confidential Computing?
I mean my simple explanation is we get encrypted at rest and we can encrypt it in motion. But now we're getting grip data in memory while it's processing and that's known as confidential Computing, but I'm sure there's a more technical explanation. Uh, you've got it absolutely spot on Mike.
But yeah, thanks so much for having me. It's a confidential Computing is like you described a new and emerging technology that was pioneered in the last decade, but it's now available on all major Cloud providers and essentially like you said what allows you to do is keep data protected even during runtime, which is where the Revolution and the change in Paradigm comes from because if we take a step back and look at the state of data protection that exists in the world today, right? As an industry we know how to protect data at rest.
So when it's stored on disk or it's in the cloud it can be encrypted using standard encryption mechanisms that are list approved and it's sort of a it's become a default protection that we adopt today. We also know how to encrypt data in motion. So when data is being sent over the network from a source to sync over the Internet we can once again use standard encryption mechanisms to keep the data protected as well.
But what is not widely adopted or deployed today which makes data vulnerable to breaches and exposure is a lack of protection for data in use. Right now when data needs to be processed by software on the clouds or on-prem or anywhere at all. It needs to be unencrypted for the software to be able to actually process the data but with confidential Computing the data remains protected even when it's being processed by the by the machine, even when you're running software on top of it, so when it is in main memory or during computation, it remains encrypted and protected as well.
I can give you a very briefly how this technology works is that you can think of the CPU as sort of a black box now when data protected data or data that needs to be protected is loaded inside this black box only there is a decrypted deep down in the CPU die by the hardware itself and the hardware ensures that no software on the machine in some cases not even the operating system or privileged software that exists. And can penetrate this black box inside of get access to unencrypted data. The they can look at memory but memory is always encrypted and the only way to actually get access to unintered data is to physically attack the CPU die and Chip which you'll end up destroying it in the process and it's it's designed to be tamper-resistant.
So it's very very strong security guarantees that you get as a result of This Confidential Computing technology that is rooted in specialized Hardware that is now free easily available on the clouds. So the barrier to adopt confidential Computing has sort of gone away and there is a rich emerging ecosystem around confidential Computing that is using this core capability and very exciting ways. And yeah our Focus that's opaque is to enable analytics and AI at scale on confidential data and to enable data collaboration, but that is just one of the many things that we can do with it.
And I think as an industry the aim is to make confidential Computing the default no matter what the workload is no matter what the data is things should always be process in a confidential way similar to what we have with protection for data at rest and for data in motion today. when the bad guys targeting Data while it's processing because it's not encrypted or they after that or is this a more of an issue that we know we're going to be concerned about the future, but the bad guys haven't quite figured out how to do that particular hack yet. Um, I would say that the best guys currently don't often need to Target data and use even because in many cases of data exposure, even the data is often not encrypted at rest and there are other forms of violating data confidentiality through phishing attacks and so forth but as these Processes become stronger a data in use will become more important and the more thought of the Target that is one example of how confidential Computing can help de-risk cloud deployments and cloud-based migration on digital transformation.
But also more crucially I think is this opens up the world of collaborating and confidential data. And what do I mean by that I mean by in many cases because this data is so confidential but it can contain sensitive personally identifiable information to Pi information or sensitive health information and because of this confidentiality this data is often locked down on-prem in silos. It's going to be shared in many cases across teams within the same organization because of very cumbersome governance processes.
Let alone sharing this data outside the organization boundaries moving into the cloud or sharing it within your business ecosystem for deriving some mutual benefit. This is not possible right now without having to trust a third party if you want to share and collaborate on confidential data yourself, for example Banks can now collaborate towards fighting Financial crime more effectively human traffickers money launderest criminals hide that traces across multiple banks in the absence of a technology like this the best that each Bank can do is look at its individual transaction data identify patterns and Flagship suspicious transactions, but criminals hide that traces across multiple Banks. So to be able to detect Financial criminals more effectively Banks need to be able to collaborate with each other and Data, they can't do this right now because one the competing with each other there are laws in regulations and players and the data is super confidential but with this technology, they can each encrypt their data individually pull it together in the cloud in a secure environment and then jointly train models or jointly run analytics on the collective data that benefits everyone.
Healthcare is another very good example as well hospitals and health institutions can collaborate towards better patient profiling towards better disease prediction, which they can't do right now because it's very sensitive patients data covid is actually a very topical example around this but there's one thing we store during covid is that contact tracing could have helped solve the problem to a large extent perhaps or mitigated but the moment we try to deploy contact facing Solutions, we found that we needed to be able to combine patient data from various Health repositories and the moment we try to do that all these data confidentiality concerns came to the Forefront to watching those efforts to a large extent such problems can be effectively mitigated and solved using confidential Computing Technologies as well because you don't have the trust anyone with the data. I don't have to trust you. You don't have the trust me neither of us has to trust software of the cloud but what but we can all we can each other.
Individually, pull it together and then run analytics and machine learning on top of it. And that to me is the most exciting value prop here. Is naming long term that we can get rid of a lot of these compliance motions because today for example companies are doing cartwheels for stock compliance and all this other stuff and it's really just about trying to verify whether or not somebody yes could access data or not.
But if no one actually ever sees the date in the first place that I don't really care who's running the machines on the other end, right? Um, that's the next I would say that this would make compliance easier. I wouldn't say that.
This is a silver bullet because there are lots of controls around processes and best practices and other auxiliary security issues. So in which case confidential Computing can help comply with these laws and emerging regulations, which are getting stricter globally is you know, and it but you would still need a other Solutions around it to comply with all aspects of so for example gdpr requires that data needs to be deleted securely. You would still need to implement controls like that within the software.
So in which case it's not a silver bullet, but it makes it much much easier to comply with requirements that around anonymizing pseudonymizing Data before sharing with the third party processor because now the leader remains encrypted so you get much stronger security guarantees as a result. As we go along here as I understand that we need a special class of processors whether they're from Intel or somebody else to go and take advantage of this capability. So is it expensive in the cloud or we reach a point soon where the cost of that drops to the point where it's a small difference in people are just gonna use it by default.
I mean, where are we on that curve? That is certainly where we want to be the everything is confidential by default. It's not cost prohibited the for example the price of a confidential Computing VM of the end that runs on Hardware that is on servers that has this capability is within a few tens of percentage more expensive than a regular virtual machine.
So I would between yeah, that's an up to two ways is what I believe it to be right now, so it's not It's not very expensive in terms of money or cost of just renting those machines on the cloud. There is another aspect of cost that is around cost of performance. So if you are running workloads or big data workloads or cluster work clustered cluster Computing workers on these machines.
Do you pay a price in terms of performance overhead? Is it slower? And that would that depends on the workload itself and the specific Hardware that you are using but even there based on our benchmarking we see performance overheads ranging from a few percentage points to a few tens of percent and this is even this is constantly improving and being Innovative one and a lot of the software ecosystem that is now emerging around the space specifically takes into account the architecture of these machines and build software that that can remain as performant as a regular cpu-based computation.
So I don't think it's super expensive to adopt. Do you think we still suffer from some Notions about encryption and performance that people don't encrypt because they have it in their heads that this is a performance issue, but maybe you know, we're getting better at this in the hardware is Advanced and maybe we should take a second or even a third. Look at this.
I completely agree with you. I mean and honestly to some part of that is it's almost seems like black magic right? Like how can you compute with data if it's encrypted because encryption turns data sets into gibberish and that's what it's meant to do.
So, how can you even compute on those data sets? So that education is of course that we need to do more around and drive more awareness in the club providers are also doing a lot of good work in this space. And then there is this other angle here where a cryptographers have this problem has been studied for decades of how do you compute on encrypted data?
And a decade ago cryptographers invented fully homeopathic encrypt encryption schemes that allow data to be computed upon while keeping it encrypted at all times beautiful cryptography. These are specialized techniques with very beautiful mathematics underneath it. these Technologies however still suffer from High resource consumption and slow down and performance.
They're not as scalable yet as regular vanilla computation. And so people are some many people many organizations are now looking to adopt these Technologies as well. But when we talk about big data analytics or machine learning workloads, we still need to make more progress on the cryptography front where we get to a point where you can use these specialized cryptographic approaches for processing such workloads.
A confidential Computing takes a different view to it because it's based on Hardware which used to be the barriers adoption. So there is no specialized cryptographic technique that's being that's involved here the encryption and decryption are being done by the hardware itself. The reason it's fast is because when the data is being processed, it is processed within This Confidential Computing Hardware environment.
So it is decrypted within it and then the software is analytics or machine learning workers, whatever you're running takes place on the decrypted data, but when data is in memory as it moves in and out of this environment, it remains encrypted so you act ones get the very strong benefits keeping data encrypted or protected when it's being computed one, but you get the strong performance properties of a CPU or of a machine as well. So it provides the best of both worlds in my view to some sense. Who's gonna drive adoption of confidential Computing?
Is it going to be the developers who are building the applications? Because they have to do things that invoke those apis or is it the security team was going to stand up and say guys we're sick and tired of these issues and thou shalt use confidential computing. That's an excellent question.
And the answer to that I believe would be what do you want to use confidential Computing for? If you want to de-risk your existing applications and software by adopting confidential Computing, then that would be driven by the security teams. But when we look at use cases around data collaboration and data sharing and analytics and machine learning that is driven by the by the business teams and the owners of that use case or the product teams, even or the data analytics teams who want access to more data that is currently locked down, which is currently can't get access to and confidential Computing provides a solution to that problem.
So yeah. I think this will depend on what you want to use Contraption Computing for. And there is a lot of innovation that's happening on board along both fronts.
All right, folks. Well, you heard it here and we can now encrypt it and and essentially while it's running while it's at resting. Well, it's moving around.
Guess there's really not much of an excuse anymore not to encrypt everything. Hey, I would say I would completely agree with that sentiment. All right, Misha.
Thanks for being on the show. Thank you for so much for having me. Mike was a pleasure.
All right back to you guys in the studio.