THE LINUX FOUNDATION PROJECTS
Category

Announcement

COCONUT-SVSM Joins the Confidential Computing Consortium: Enhancing Security for SensitiveWorkloads

By Announcement, Blog No Comments

The Confidential Computing Consortium (CCC) welcomes a new project: The COCONUT
Secure VM Service Module (COCONUT-SVSM), which aims to be a game-changer for secure
service provision within confidential virtual machines (CVMs). This is a significant step forward
for the project.


Published by SUSE in March 2023 the project built an active developer community with major
industry players contributing, including AMD, Microsoft, IBM, Intel, Redhat and Google. By
joining the CCC the project gains enhanced visibility and even more collaboration opportunities
within the confidential computing community and is set for further community growth.

Building a Secure Foundation for Confidential VMs

COCONUT-SVSM was started by SUSE and is now hosted by the Linux Foundation (LF),
known for fostering open-source collaboration. This choice reflects the project’s commitment to
open development and community involvement. COCONUT-SVSM aims to become a platform
that delivers essential services to CVMs. These services, which can not be provided by the host
VMM in a secure way, include:

  • Virtual TPM emulation: This functionality provides a secure Trusted Platform Modulewithin the CVM, enabling functionalities like secure key generation and storage, but alsoenable full remote attestation of workloads.
  • UEFI variable store: This secure storage area safeguards critical configuration data forthe CVM and enables secure boot on some platforms.
  • Live migration for CVMs: This feature allows for seamless movement of running CVMsacross different physical hosts without compromising security.

The key advantage of COCONUT-SVSM lies in its secure execution environment. It operates
within the trust boundary of the CVM, but is still isolated from the actual operating system. This
isolation ensures that even if the underlying system gets compromised, the security of services
offered by COCONUT-SVSM remains intact

Benefits for Confidential Computing

This integration will enable users to enhance their confidential VM setups with features like:

  • Secure Remote Attestation: This allows for verifying the integrity and trustworthiness of the execution environment, a crucial requirement for running sensitive workloads and protecting data.
  • End-To-End Data Security: Users can guarantee that their data is always encrypted and never visible to any unauthorized party during storage, transmission, and processing.

Ultimately, these features empower users to fully protect their data even in untrusted
environments like the public cloud. This paves the way for secure cloud deployments and
confidential computing adoption across various industries.

Industry Leaders Support COCONUT-SVSM

COCONUT-SVSM is gaining traction within the tech industry, with key partners recognizing its
potential to advance confidential computing. Here’s what some industry leaders have to say
about COCONUT-SVSM:

AMD
“SUSE and AMD have a long history of collaborating on the development of the Linux
ecosystem and confidential computing technologies for AMD EPYC Processors” said
Frank Gorishek, corporate vice president, Software Development, AMD. “We are thrilled
to see COCONUT-SVSM join the CCC as an open source implementation of the AMD
SVSM specification for SEV-SNP. AMD is committed to open source technologies such
as COCONUT-SVSM as a catalyst for collaborative innovation on transformative
technologies such as confidential compute.”

Microsoft
“A secure environment like COCONUT-SVSM can play a valuable role in confidential
computing.” a spokesperson from Microsoft Hyper-V said. ”It can hold secrets and
provide virtualization services seamlessly to improve the usability of CVMs.”

Open Governance and Continued Growth

The COCONUT-SVSM project fosters open collaboration. SUSE’s Jörg Rödel, as the founding
developer, is the current lead maintainer. In the future, a broader project leadership will be
established by a Technical Steering Committee (TSC) consisting of at least 3 lead people to
ensure diverse perspectives guide the project’s direction.


The project community collaborates via its GitHub organization, a mailing list and in weekly
community meetings. There the project’s future, current challenges, and contributions from a
broad developer base are discussed.


Every developer passionate about confidential computing and secure service provisioning is
invited to start contributing to COCONUT-SVSM and support the continued growth of the
project.

The Meaning Behind the Name

The name COCONUT is a play on the term “CoCo,” a common abbreviation for confidential
computing. The “coconut” metaphor reflects the project’s focus on robust security, symbolizing a
hard-to-crack shell protecting the integrity of sensitive data.


By joining the Confidential Computing Consortium, COCONUT-SVSM is set to make significant
contributions to the field of confidential computing. The community excited to see the project
flourish within the CCC and invite all those interested in secure virtualization technology to join
the thriving COCONUT-SVSM project. Together, we can bring confidential computing and
end-to-end data protection forward for a wide range of industries and applications.

NVIDIA Elevates Membership to Premier Status in Confidential Computing Consortium

By Announcement No Comments

We are thrilled to announce that NVIDIA has recently upgraded from a general member to Premier membership of the Confidential Computing Consortium (CCC), marking a significant step forward in redefining data security standards. In an era where data and AI hold immense potential for businesses, the importance of robust privacy and security measures cannot be overstated.

NVIDIA has been at the forefront of Confidential Computing innovation, with groundbreaking achievement in GPU security, and the delivery of Confidential Computing on NVIDIA Hopper™ GPU architecture. Leveraging the unprecedented acceleration of NVIDIA Tensor Core GPUs. This advancement provides the confidence needed to uncover revolutionary insights while ensuring data and models remain secure, compliant, and uncompromised.

The Confidential Computing Consortium, a community-driven initiative, brings together industry leaders and organizations committed to advancing confidential computing technology. Through collaboration and innovation, the CCC aims to promote the widespread adoption of confidential computing, enhancing security and privacy by protecting data in use. This approach complements existing encryption methods, fostering comprehensive data protection measures.

“NVIDIA integrates privacy and security directly into the hardware and software stack utilizing advanced AI spanning from the silicon level to software, including encryption, attestation, and isolation technologies to protect against unauthorized access, and provides assurance around the confidentiality and integrity of sensitive data and AI models through technologies like Confidential Computing and Secure AI”, said Laura Martinez, who directs security marketing at NVIDIA. “By joining the CCC, NVIDIA aligns with a community of like-minded entities dedicated to shaping a safer, more privacy-centric future.”

As technology evolves, robust data protection measures become increasingly paramount. Through initiatives like confidential computing, NVIDIA is safeguarding users’ information and contributing to the broader effort of establishing a more secure and trustworthy digital ecosystem. NVIDIA’s membership not only holds significance for the company itself but also serves as an inspiration for other technology companies to prioritize data security in an era where digital trust is of utmost importance.

Join us in welcoming NVIDIA to the Confidential Computing Consortium and in celebrating their commitment to advancing secure computing solutions.

Read about other organizations who recently joined CCC:

Fujitsu

TikTok

TikTok Becomes Premier Member of Confidential Computing Consortium

By Announcement, Blog No Comments

In an era dominated by rapid technological advancements, the need for robust data security measures has become more critical than ever. Recognizing this imperative, TikTok has joined the Confidential Computing Consortium (CCC) as a Premier member, a collaborative effort dedicated to advancing the adoption of confidential computing technology.

The Confidential Computing Consortium is a community-driven initiative comprising industry leaders and organizations united in their mission to redefine data security standards. Our mission centers on promoting the widespread adoption of confidential computing, focusing on safeguarding sensitive information and cultivating a more robust computing landscape. Utilizing advanced computational techniques, such as hardware-based Trusted Execution Environments, confidential computing enhances security and privacy by protecting data in use. This approach complements existing encryption methods for data at rest and in transit, fostering comprehensive data protection measures.

As a platform, TikTok is used by billions of users worldwide on a global scale. When building products and features, securing the privacy of users is at the forefront of TikTok’s engineering strategy. TikTok’s Privacy Innovation is an open-source initiative dedicated to advancing data privacy through cutting-edge technological advancements and fostering collaboration and transparency. Their open-source initiatives aim to make technology readily available to researchers and practitioners, aligning with a shared vision to shape a safer, more privacy-centric future. By joining this global consortium, TikTok aligns with a community of like-minded entities dedicated to advancing secure computing solutions.

As technology evolves, robust data protection measures become increasingly paramount. Through initiatives like confidential computing, companies like TikTok are safeguarding their users’ information and contributing to the broader effort of establishing a more secure and trustworthy digital ecosystem. TikTok’s membership not only holds significance for the company itself but also serves as an inspiration for other technology companies to prioritize data security in an era where digital trust is of utmost importance.

Join us in welcoming TikTok to the Confidential Computing Consortium.

Read about other organizations who recently joined CCC:

Fujitsu

NVIDIA

Fujitsu Strengthens Commitment to Secure Computing: Joins Confidential Computing Consortium as General Member

By Announcement No Comments

Fujitsu has strengthened its commitment to secure computing by joining the Confidential Computing Consortium as a General Member. It reflects its dedication to leading-edge technology and recognizes security’s paramount importance as a global information and communication technology (ICT) leader in the digital age.

Through active participation in the consortium, Fujitsu becomes a key player in shaping the future of secure computing, collaborating with industry leaders to contribute expertise and resources to develop open-source technologies enhancing data security and privacy.

This membership marks a crucial step in Fujitsu’s journey to fortify data security, establishing itself as a secure and confidential computing leader alongside other industry leaders. As the consortium drives innovation, we anticipate transformative advancements, leading to a redefined data security landscape.

Confidential Computing Consortium unites industry leaders to advance confidential computing, focusing on secure data-in-use and safeguarding sensitive information during processing. Fujitsu’s alignment with like-minded organizations underscores its commitment to data security through open-source technologies.

Confidential computing introduces a paradigm shift in securing sensitive data, addressing the need to protect data during processing, in addition to traditional measures for data at rest and in transit. This approach ensures encryption and protection of sensitive information during active use.

The consortium provides a collaborative platform for members to share insights, expertise, and resources. Fujitsu’s involvement signifies a shared commitment to fostering innovation and driving advancements in confidential computing. As technology evolves, collaboration becomes crucial in addressing complex challenges and overcoming emerging threats.

Learn more about the Confidential Computer Consortium and how to get involved.

Read about other organizations who recently joined CCC.

NVIDIA

TikTok

Welcoming Sal Kimmich to the Confidential Computing Consortium

By Announcement, Blog, In The News No Comments

The Linux Foundation’s Confidential Computing Consortium (CCC) is proud to announce Sal Kimmich joining as the Technical Community Architect. Sal’s career started by sharing Python scripts with other computational neuroscientists in the wild world of supercomputing. A decade later, they are still paying attention to the algorithmic side of open source tech.  

Before joining CCC, Sal worked as a scalable SecDevOps Machine Learning engineer and brought those contributions to the Cloud Native Computing Foundation (CNCF) and the Open Source Security Foundation (OpenSSF). They have focused on practical automation around security best practices that make the maintainer’s lives easier, like Security Slams.  

At CCC,  we are building the landscape for Trusted Execution Environments (TEEs) at the Linux Foundation as it becomes as Confidential Computing becomes foundational to cross-industry security practicesConfidentiality of data in use is also a cornerstone of digital progress: having hardware level trust in compute is critical to the wave of critical technologies in both edge and cloud. 

Sal’s vision for CCC is clear – to make maintainers’ work enjoyable and rewarding, to create tech demos that dazzle, and to showcase the world-class Open Source Projects enabling secure computation. 2024 marks the start of an incredible year of compute, collaboration and community expansion ahead, as runtime security takes the spotlight in emerging tech. 

The CCC welcomes 5 new General Members and Gramine project during final quarter of 2021

By Announcement No Comments

The Confidential Computing Consortium is thrilled to welcome five new General Members and the Gramine project. The community continues to grow with a total of 36 corporate members, 4 nonprofits, and 6 projects.

New General Members include:

Baidu USA

Canary Bit

HUB Security

Opaque Systems Inc

Technology Innovation Institute

The Gramine project will be hosting a webinar on February 3, 2022 at 9am PST. You can register here.

More on Gramine project:

Following the first production-ready release “v1.0”, The Gramine Project is releasing “v1.1” in upcoming weeks. One highlight of this release is stability improvements for Golang and Rust workloads. Another prominent feature of the release is support for the musl C standard library – now Gramine allows users to choose between glibc and musl, depending on users’ requirements on the binary size (TCB), as musl is more light-weight than glibc. Also, AddressSanitizer was integrated in Gramine, and it runs in the CI on each change, for detecting any security issues ahead of code merge. This version adds several other features as well as multiple bug fixes (thanks to our ever-increasing user base for reporting issues!).

While there are several use cases under development, we would like to highlight the production release of the OpenVino Security Add-on (OVSA) for Model IP protection (consider using it for your protected ML workloads). Please reach out to the Gramine team if you are experimenting with Gramine and would like to be added to the list of “Users of Gramine

 

Confidential Computing Consortium at the RISC-V Summit December 6-8, 2021

By Announcement No Comments

RISC-V Summit brings the community together to show the power open collaboration can have on the processor industry. The audience spans across industries, organizations, workloads, and geographies to learn about the technology advancements in the RISC-V ecosystem and visibility of RISC-V successes.

The Confidential Computing Consortium will be on site staffing a booth. Come say hello!

To learn more, please visit: https://events.linuxfoundation.org/riscv-summit/

Confidential Computing Market Could Reach US$54 Billion in 2026

By Announcement No Comments

Today, the Confidential Computing Consortium released findings from Everest Group’s market study revealing that the Confidential Computing market is projected to grow at a CAGR of 90%-95% to reach US$54 billion in 2026.

Read the press release: https://www.prnewswire.com/news-releases/confidential-computing-market-could-reach-us54-billion-in-2026-301407273.html

Read the report: https://confidentialcomputing.io/white-papers-reports/

CCC media contact: pr@confidentialcomputing.io