Fortanix CEO Anand Kashyap on Confidential Computing

Transcription

foreign speaks we're talking about cloud data security which is a topic that is only getting more complex as Cloud continues to grow to discuss that I'm joined by a non-kashup chief executive officer for tanx Anon very good to have you with us today good to be here thanks for having me James so cloud data security can be a challenging topic first of all because cloud is no longer just an element of Enterprise ID it's really the foundation for many companies for their Enterprise I.T infrastructure the other part of course is that you know cloud data security is often on the clients I mean the the cloud providers have their responsibility but really it's it's the the clients have a huge responsibility so so what are your thoughts what's really moving the cloud data security here Market here in 2023 yeah that's absolutely right James so that's all the cloud providers all the major public Cloud that talk about the shared responsibility Matrix uh in terms of security there's a real secure the infrastructure will secure everything related to their own blog storage or object storage databases compute infrastructure but then the data security is the responsibility of the End customer and what's becoming more and more important as well is all the regulations uh that are being passed in terms of data privacy and also in terms of data sovereignty so in Europe for example with gdpr and then the later shrimps 2 addition to that it becomes very important for customers in Europe as they're moving to the cloud and everybody wants to move to the cloud what we're seeing is even the very traditional large banks are also now moving to the cloud because of the advantages of the cloud the cost advantages but then as they move into the cloud because of these regulations they need to make sure that the controls for the data Securities in their own hands and they need to make sure that they are keeping the security controls out of the cloud and also in region there are also a lot of data sovereignty regulations not just in Europe but around the world in various countries the regulations which say that the data for the citizens of that country or companies in that country need to be in the same country so now as people move to the cloud you see instances of sovereign Cloud being created and also customers are being forced to mean make sure that the data security is in their own hands and not with the with the cloud interestingly you say that the banks are moving over because I think of them as being the the last sector to really move over because it's there's so many issues that are so sensitive about the data security is is it true that banks are some of the the last laggart when it comes to moving to the cloud I think they're close to being the last leg what we saw in the early days of the cloud is uh smaller companies the startups tech companies move to the cloud then there was a wave of companies which were born in the cloud they never migrated they were always everything was in the cloud over time we have seen more traditional companies Banks fintech companies they've started moving to the cloud I think there are still a lot of companies and ads the digital Revolution is going on we'll see almost everybody move to the cloud and if they don't move entirely they'll still have some components which will move to the cloud because with Cloud you get cost efficiency you get Simplicity you get elasticity which is important for a lot of customers and to take advantage of all of that you have to move to the cloud and I think that's a secular Trend that we are seeing Cloud migration and banks are late Commerce but but they're right in the middle of it right now Banks and I believe healthcare too correct me if I'm wrong about the healthcare is a little load I'm moving there certainly but a little slower than some companies yeah I'll put the healthcare right behind Banks but yeah they're also moving to the cloud we see that Trend as well all right well let's talk about what companies can do because here they are they they realize that there was this enormous responsibility for cloud data security it's kind of a newer thing for them it's not like a for the last 20 years companies have been dealing with this issue it's a newer issue even though it's not brand new what can companies do to to feel safer and more compliant with cloud data security and and multi-cloud cloud data security yeah absolutely so going back to the shared responsibility Matrix uh companies are responsible for the data security for the securing the day in their own data even though it's moving to the cloud and what does that mean that means that as data goes in the cloud you lose a lot of control and visibility you don't know how the cloud provider is managing your data when it's being encrypted how it's being encrypted if it is encrypted then who is managing the encryption keys where the data resides if you're a European customer you want your data to be in Europe but you don't know whether Cloud keeps it there or shards it and puts it everywhere else so it's important for customers to know first of all how the data is being managed but then they need to start taking control so taking control means there could be various things one is there's some customers who take the extreme view they don't want to give anything to the cloud they want to encrypt all their Data before it even touches the the cloud services if you do that then you get a lot of security benefit but then you lose out on a lot of benefits of the cloud because once you data is encrypted it's like dead data you can't put it in a database and run intelligent queries on it right if I can ask you about one question you're calling the encrypted data dead data but of course I would think the responsible party is responsible staffers in the company have the encryption key so why would it be dead for them yeah so again it depends on how that data is being used if you want to put it in the cloud managed database and then want to run queries on that database even though you have the keys you first have to get the data out and then run the query so so that defeats the purpose of using a cloud native database or a cloud native service like bigquery in Google for example so yeah doing client-side encryption that is one extreme view where you encrypt everything before it hits the cloud but then there are other variations of that one is you could move your data to the cloud but hold on to your own keys and Google and recently Amazon have made that possible using interfaces such as ekm or Google to external Key Management Amazon has launched something called xks or external key store and we use something like that then you can hold on to your keys the key material never goes to the cloud but then you can continue to use the cloud native applications but if you think about it even with that approach when the data is being used by the cloud when you run a query at that time the data does get decrypted so data isn't clear so somebody could make an argument that yeah if somebody gets to or hacks into the cloud system they can still get to the data so there is an even more secure way to secure the data in the cloud and that is using this new type of security called confidential Computing and this is something we pioneered as a company and we are one of the founders of the confidential Computing Consortium along with the cloud providers like Microsoft and Google as well as the chit vendors like Intel and AMD and others and using this technology what you can achieve is that the data can be secured not just when it's sitting at rest or when it's being transferred in motion but also when the data is in use and imagine if you could run your application on the cloud could provide an application running inside computational Computing then you could run your queries you could run your analytics you could run even your AI even on the data which is being used and and not be able to look at the data itself good all right so I think it's a really important point to stop and let let's get like a nutshell definition of confidential Computing so what what exactly is confidential Computing and then we can go back and put that in context there yeah it's a very simple definition of computational computing is it's a way to protect data in use using hardware-based trusted execution environment which is also adjusted and that's the dictionary definition and the definition that has been given by the computational Computing Consortium there are other ways to protect data in use using things like fully homomorphic encryption the people that were multiparty computation but computational Computing specifically talks about protecting the data in use using hardware-based you know the the sort of wonderful irony about that is the is there's that famous saying that says Hardware excuse me software is eating the world you know Mark Andreessen said that uh but it turns out that Hardware plays a pretty important role perhaps he he acknowledged that but I so so really confidential Computing relies heavily on hardware-based data security is it is it something that companies are struggling with or is it a new idea is it help them how is it going in the market yeah the software is eating the word but if you think about hardware-based security that has always been prevalent if you look at your smartphones for example uh when you store your face ID or your fingerprint in your Apple iPhone or Android device guess where it gets stored it doesn't go to the cloud it gets stored in a secure Hardware element on your phone what uh Intel and other Ultra printers have done is that take that same technology around secure enclave and then they have made it available in server class CPUs and then Nvidia which is known for gpus they have come out with confidential gpus so again wherever the compute runs whether in CPUs or gpus in the cloud and now a computational Computing technology is becoming more and more available initially uh the it was a challenge for end customers to go build software for confidential Computing and take advantage of this new technology and that's why we exist we make it easy for our customers to build applications deploy them orchestrate them and take full advantage of the security technology because if you don't use the security technology the right way you're still not secure so just by putting your application in the configuration Computing doesn't make it secure you need to still think about how the data is coming where it's coming from how is it encrypted who's managing the keys who have access to that data who has access to the Keys and and we strive to provide the full platform for doing all of that all right let's let's take a moment and drill down into the photonics offering how is 410x you know enabling account Financial Computing what is the 410x advantage given that any number of people could be doing the same technology yeah uh absolutely so as I talked about various ways you should um you can protect your data As you move into the cloud we provide solutions for all of them so first of all it's the client-side encryption if there's some kind of data that is so secure you don't want it to be seen at all we provide apis for doing client-side encryption we can manage your encryption Keys we actually use computational Computing for our own key management system so the keys are secured using conversational computing and then as you move to the cloud we do provide Integrations with the cloud native Key Management Services using the ekm interface for Google or using the xks interface for AWS so you could still be using an Amazon S3 or Google's bigquery but have your keys managed by photonics outside the cloud and then going forward we also provide a full-fledged platform for orchestrating workload that's run in a computational Computing environment in the cloud uh just recently we launched uh an offering with Microsoft we are taking advantage of the configuration Computing infrastructure in the other confidential Computing and we allow data such as Healthcare data or fintech data to be processed inside the computational Computing environment is encrypted end-to-end and the applications that are running and processing that data they're also running inside the secure Enclave so so you can't look at the data you can't look at the code and you get that security that you need so fortunix is essentially enabling confidential Computing using software even the confidential computers is Hardware based but for 10x is offering it uh a software-based solution to enable a hardware-based security am I correct not thinking that yeah exactly so we believe that the hardware will be provided by the CPU and the GPU vendors they'll be made available uh as infrastructure as a service by the different Cloud providers and today all the three major Cloud providers uh AWS Microsoft and Google they do have their own confidential Computing offerings in terms of either VM based offering or a container based offering and we sit on top of all of that so we build solutions that use coordination Computing and then we also provide orchestration for end customers to bring their own applications and run them in a confidential Computing environment think of an example uh like confidential AI which is one of our offerings and this is where you can train or you can do inference using machine learning on some very sensitive data inside a confirmation Computing environment and the use cases in healthcare for example where the healthcare data which is heavily regulated heavily protected it using regulations like HIPAA and others that has to be used by an algorithm developer let's say I was looking for a cure for cancer now they have to train their models on various types of data with different biomarkers but since that data is heavily protected it's very hard to bring that data inside a secure environment and then do your validation or your machine learning algorithm with computational Computing you can do that you can bring that sensitive data you can bring the algorithm together the algorithm provider doesn't know where the data is coming from the data provider doesn't know whether algorithm is coming from and but they can be sure that the data will not be leaked or it will not be exposed and this creates that ecosystem that environment where new algorithms can be developed and validated very quickly on some very sensitive data what would you say is the launch year for confidential Computing when was the first year companies are actually really using it so we started to become 2016 and the first product we have built we call it data security manager um I think that was the first and the most popular use case for confidential Computing it's about it's a competition Computing and protect data in use but if you consider encryption Keys as data then we have already built that so the data security manager that important that we are built it runs entirely inside a compression Computing environment when somebody authenticates authorize they create a key they use a key uh the key usage gets logged all of that happens inside a confidential Computing environment so we've already launched the product uh I would say the next few use cases for competition Computing whether it's a data clean room or whether it's multi-party analytics or whether it's confidential AI I think this year is when some of those new applications locations New use cases will get launched in the first use case is is already pretty popular and I think there'll be succession of new use cases eventually I feel that any service that's running in the cloud which is processing and using sensitive data should use confirational Computing so whether it's the database as a service whether it's AI as a service whether it's chat GPT or any other service they should not be able to look at your data and that's when end customers and users will actually trust the cloud services interesting all right well given given how it's growing I think it's interesting to take a look at the future of confidential computing still relatively new technology uh what do you see in the next few years what will confidential Computing look like uh three to five years from now I believe that confidential Computing has been a little bit slow uh because the availability has has not been there uh earlier the only game in town was Intel with the sgx technology what you have seen recently is that AMD has come up with its own technology Nvidia is coming up with confidential gpus so there's more additional technology has become more widely available but then the cloud providers have also been a little bit slow to adopt and make it available to end customers but again that seems to be changing Satya nadilla talks about confidential Computing these days particle singer talks about commercial Computing so the Mind share has gone up and people recognize that this is the right technology to use in the cloud to protect the data so I think this is we are at an inflection point is what I feel where the availability has reached a point where somebody wants to build a confessional building application they can easily go to a cloud provider and start doing that and it was not the case a couple of years ago you still had to figure out which CPU version to use which instance in the cloud to use but now it's more widely available and then it's just about unlocking the next set of use cases which will make it uh and the software the vendors like botanics or others they need to make the complicated technology which it is compression Computing and make it transparent to the end users the end user should not need to worry or how do I use complexion Computing is it a hardware component is there something special I need to do for them which would just be an API call and if software vendors are able to make that transition if they're able to make that leap in terms of providing the services which are very easy to use which are just a delight to use and just an API call away I think that's when competition Computing will take off hmm interesting well Anan I think you said it I think it's a it's confidential Computing is going to be a really interesting sector to follow in the in the years ahead I know there seems like there's going to be a lot going on uh thanks so much for sharing your Insight today thanks for having me games

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: Apr 3, 2023
Updated: Sep 25, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Anand Kashyap, CEO of Fortanix, about how cloud data security is enhanced by confidential computing, which uses hardware for an extra layer of security.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.