https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Cloud


Shutterstock

Google Cloud Adds Confidential VMs to Enable Encryption for Data in Use

  • Written by Jeffrey Schwartz
  • July 14, 2020
Encryption for most sensitive data uses AMD EPYC CPUs with onboard encryption.

Google Cloud is adding advanced encryption capabilities with the launch of Confidential VMs to its portfolio.

The company introduced Confidential VMs at Google Cloud Next ’20: OnAir, a virtual conference that began Tuesday. Confidential VMs are an option for Google Cloud enterprise customers that require enhanced security for highly sensitive data in use.

Now available in beta for Google Compute Engine, Confidential VMs are the first offering though the company’s Confidential Computing portfolio. Confidential Computing is a new set of services for workloads where data privacy is critical. It builds on last year’s addition of Shielded VMs, designed to ensure VMs boot with a verified kernel and bootloader.

While Google Cloud offers encryption for data at rest and in transit, the data must be decrypted before it’s processed. Cloud providers are in a race to also enable encryption while data is in use, affordably and with acceptable performance.

Addressing that limitation promises to reduce a key barrier to running business-critical, sensitive workloads in the cloud.

Google Cloud's Sunil Potti

Google Cloud’s Sunil Potti

“We are able to blend usability, performance and confidentiality in a much more consumable mainstream adoption,” said Google Cloud VP and general manager Sunil Potti.

At the CPU level, AMD and Intel have worked at reducing those limits. Google Cloud has chosen AMD’s second-generation AMD EPYC processors over Intel’s Software Guard eXtensions (SGX).

AMD’s new EPYC platform uses onboard encryption, while Intel’s s SGX is more software driven. Intel offers the benefit of addressing operating system encryption, which AMD does not. Potti said Google addressed that in the cloud stack of its software.

No Software Recompilation Required

Google’s Confidential VMs are based on an open-source project called Asylo that it established in 2018. Through that project, Asylo offers a SDK with a Docker image in a Google Container Registry. According to Google, it includes all of the dependencies needed to run a container.

The benefit of AMD’s EPYC is partners and customers don’t have to recompile their software, when migrating legacy applications.

“The single biggest feedback that we got to ensure mass adoption of confidential VMs was, you don’t want to forklift and redesign and recompile your apps,” Potti said. “With our technology, you literally lift and shift your workloads over as VMs or otherwise.”

Google’s Confidential VMs also use AMD’s Secure Encrypted Virtualization (SEV). Also a feature of AMD’s second generation EPYC processors, SEV encrypts VM in-memory. It uses a dedicated per-VM key generated by an embedded processor, according to AMD.

Michael Kollar, SVP and CTO of Atos, a Google Cloud partner, was among those who favor AMD’s approach.

Atos' Michael Kollar

Atos’ Michael Kollar

“Typically, if it’s encrypted in memory, the only way to get it out is you have to have the key,” Kollar said. “But even then, it’s nearly impossible,” at least until quantum computing comes along, he added.

Still, Confidential VMs aren’t necessary for all workloads, Kollar said, but they are suited for the most sensitive data. And there are other considerations.

“What remains to be seen, as it goes further into production, are performance implications and scalability,” he said.

Kollar has little doubt that it will scale, but when it will reach an acceptable price is unknown.

“I think [initially], most security conscious workloads will go there,” he said. “And that makes sense, because any objection of moving a workload to Google, this negates the potential risk or issue.”

Confidential VMs also are practical for multiparty computation, according to Google. In such scenarios, organizations can collaborate with their respective private datasets, while ensuring protection of confidential data.

Assured Workloads for Government

In other security-related news at Google Cloud Next, the company is looking to make its platform suited to government agencies. Google’s new Assured Workloads for Government, now in private beta, aligns with U.S. government regulations, Potti explained. The service will let partners deliver controlled environments for the U.S. government, suppliers and contractors. It uses automation to ensure compliance with key standards maintained by the Department of Defense, FBI and FedRAMP, among others.

“Assured Workloads for Government essentially helps you secure sensitive workloads and accelerate your path to running compliant workloads,” Potti said. “It allows you to have automatic enforcement so that customers can meet U.S. government compliance requirements by choosing to store data at rest in specific U.S. regions. On the flip side, it brings a level of one-click controls, to put day-zero operations or onboarding to Google Cloud. But also, day-N operations where you can afford to be compliant. From an always-on perspective, the system will recommend changes. It will detect changes to configurations, or misconfigurations and notify you of changes and then auto correct some as well.”

Tags: Cloud Service Providers Artificial Intelligence Cloud Data Centers Open Source Security Technologies Virtualization

Most Recent


  • Enterprise Connect 2023
    Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More
    “It’s as exciting as it gets,” a Microsoft official said of generative AI.
  • SMB
    New Comcast Business SD-WAN Solutions Put Focus on SMBs
    The solutions appeal to smaller businesses that don't necessarily need site-to-site connectivity.
  • Time for Change
    HP's Head of Global Channel Strategy Talks Program Changes, Poly Opportunity
    HP’s channel strategy leader reveals how HP is tweaking its two-year old partner program, and what to expect for the rest of 2023.
  • Cybersecurity research
    ConnectWise MSP Report: Cybercriminals to Heavily Target MSPs in 2023
    MSPs will remain the target of supply chain and critical infrastructure attacks.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Drive revenue
    Proofpoint Protect: Rising Vendor, Partner Revenues Amid COVID-19
  • Growth plan
    N-able Empower Day 1: How to Grow Your Business
  • Cloud Computing diagram for Microsoft gallery
    Avaya Cloud Office by RingCentral Adds Capabilities for Global Businesses
  • Call Center Contact Center
    Avant Analytics: Expect Big CCaaS Adoption, Fueled by AI, Through 2021

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More

March 31, 2023

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

Is the Gap Widening Between Superagents and Mom-and-Pop Shops?

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

The shortage of talent in the tech industry gives women a great opportunity to build a career in tech says… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Check out our images from the expo floor at #EnterpriseConnect: @Microsoft @Zoom @GoTo @Cisco @googlecloud @ujetcx… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X