Showing posts with label confidentialcomputing. Show all posts
Showing posts with label confidentialcomputing. Show all posts

Tuesday, 5 May 2026

Protecting RAM

Attacks on RAM are one of the arguments to better protect data in use.

There are various security attacks on RAM. One is malware that can scrape memory e.g. for plaintext credit card numbers (once read into RAM prior to encryption).  Modern systems aim to encrypt data as early as possible in the processing pipeline.

Privileged operators (e.g. cloud admins) can peek into RAM. This is why confidential VMs isolate memory to hide data-in-use from cloud providers. 

DMA devices such as Thunderbolt peripherals can read system memory (and hence potentially sensitive data, from RAM). Modern operating systems restrict "hot-plug" DMA access.

Note: this list of compromise attacks is non-exhaustive. This is a big field of operations.

Microsoft's GitHub

Microsoft's GitHub is worth perusing from time-to-time. Some of the big projects are VS Code and TypeScript but many more additions are made to cover new directions like confidential computing.

Microsoft also have a website (opensource.microsoft.com) detailing their open source initiatives more broadly.  The Microsoft open source blog is also worth reading.

Monday, 8 July 2024

Intel SGX based confidential computing VMs

Intel Software Guard Extensions (SGX) represent instruction codes implemented in some Intel CPUs to provide a "trusted execution environment". 

It does this by protecting private regions of memory called enclaves. 

How it works is SGX encrypts a portion of memory called the enclave. 

Data and code from the enclave are decrypted on the fly inside the CPU, preventing it being read by other code. This can be used for protecting proprietary algorithms and encryption keys. 

In 2021 this became deprecated for Intel Cores but still valid for Intel Xeon for cloud and enterprise use.

Microsoft Azure makes available confidential computing VMs based on SGX technology.