Keeping data safe while it is being used by processing it in an attested, hardware-based trusted execution environment (TEE), which even the cloud provider cannot see into. It adds to encryption of stored data and data on the move.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Confidential computing in context, with comparison tables and the common traps.
Terms in this definition
- Azure Machine Learning environment
Versioned asset that pairs a Docker image with a pip or conda specification, so every job or deployment using it gets identical dependencies. You point to it by name plus a version number, or by name with @latest.
- Provider
The organisation that shares data in OpenSharing. Recipients also see a provider as a Unity Catalog securable, from which shares can be mounted as catalogs.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
Related terms
- Confidential Corp
For internal-only workloads handling highly confidential data, this Sovereign Landing Zone group, beneath Landing zones, takes the Corp policies and adds confidential computing controls that protect data while in use.
- Confidential Online
A management group in the Sovereign Landing Zone, beneath Landing zones, intended for workloads exposed to the internet that handle highly confidential data. It layers confidential computing controls for encryption in use on top of the Online policies.
- Data in use
Information an application is working on in memory at that moment. Confidential computing is the protection for it.
- DCasv5
General-purpose confidential VM sizes protected by AMD SEV-SNP. Sizes with lookalike names, such as Ddsv5 or D2ads_v5, offer no confidential computing.
- Sovereign Landing Zone
Builds on the Azure platform landing zone's design principles and library, adding sovereignty measures such as keeping data in a region, customer-managed keys and confidential computing. It is not meant to replace an Azure landing zone already in place.