Episode 90 - Confidential Compute on AWS

AWS TechChat - A podcast by Shane Baldacchino

Categories:

In this podcast episode, learn about confidential computing and data privacy in the context of AWS services. The hosts - Shai, Anton, and Arindam, who are AWS Solution Architects, provide insights into AWS's security technologies and operational practices that exceed customer standards for confidential computing and data privacy. The podcast delves into the Nitro system and its protection categories for confidential computing, as well as AWS Nitro Enclaves - a feature that provides isolation for sensitive data and applications. The hosts discuss the many use cases of Nitro enclaves, including cryptographic attestation capabilities, and explore how it can be used in various blockchain use cases, containerization, and Kubernetes. Additionally, the podcast provides resources for listeners to learn more about Nitro enclaves. Throughout the episode, the hosts emphasize the importance of keeping customers' workloads secure and confidential. They provide insights into how confidential computing can be used in blockchain networks and modern advanced enterprise architectures. Overall, the podcast provides a comprehensive understanding of confidential computing and how it can be implemented for enhanced security. It's a valuable resource for those interested in AWS services and data privacy. Key Moments: [00:02:30] Confidential computing explained. [00:05:13] AWS Nitro system. [00:10:36] Cryptographic attestation. [00:13:39] Nitro Enclave's use cases. [00:18:11] Cryptographic attestation capabilities. [00:21:11] Bridging multiple blockchain chains. [00:26:41] Nitro enclaves workshop. Links: Workshop: https://nitro-enclaves.workshop.aws/en/ (also available in Japanese) Workshop (“one module if you only have 30 min”): https://nitro-enclaves.workshop.aws/en/my-first-enclave/cryptographic-attestation.html Docs https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html Blogs: Confidential computing: an AWS perspective: https://aws.amazon.com/blogs/security/confidential-computing-an-aws-perspective/ Announcement Nitro Enclave: https://aws.amazon.com/blogs/aws/aws-nitro-enclaves-isolated-ec2-environments-to-process-confidential-data/ Nitro Enclaves + windows: https://aws.amazon.com/blogs/compute/getting-started-with-aws-nitro-enclaves-on-microsoft-windows/ Nitro Enclaves + Blockchain Part 1: https://aws.amazon.com/blogs/database/part-1-aws-nitro-enclaves-for-secure-blockchain-key-management/ Part 2: https://aws.amazon.com/blogs/database/part-2-aws-nitro-enclaves-for-secure-blockchain-key-management/ Part 3: https://aws.amazon.com/blogs/database/part-3-aws-nitro-enclaves-for-secure-blockchain-key-management/ GitHub Samples: https://github.com/aws/aws-nitro-enclaves-cli https://github.com/aws/aws-nitro-enclaves-sdk-c https://github.com/aws/aws-nitro-enclaves-acm https://github.com/aws-samples/aws-nitro-enclaves-certificate-manager-sample EKS + Nitro Enclaves https://github.com/aws/aws-nitro-enclaves-k8s-device-plugin https://github.com/aws/aws-nitro-enclaves-with-k8s https://docs.aws.amazon.com/enclaves/latest/user/kubernetes.html Video: Confidential computing with AWS compute - https://www.youtube.com/watch?v=pyRBOHYgHc0