Confidential computing using Secure Execution

Procrastination is a bad habit and it got me again. As I did not put myself some dates into the calendar I thought, yes I have time to write the next thing what I learned on LinuxONE. Looking back, ups some time spend and I thought I have time and just need to finish the next thing prior to writing in here.

I try to do better, and I will let you know :-)

Ok something triggered my to get back to the writing desk. I saw a message from Holger Wolf Yesterday talking about Secure Execution been now available in OpenShift as a Tech preview.

I know Secure Execution already from z15 and I'm glad to see the next steps to make it available from the OpenShift platform and it made me curious. I knew Nataraj Nagaratnam just recently talked about Confidential Computing and how he thinks this capability will change the way applications are build.

Application architectures are not alway small and simple. Beside all the benefits of a microservice architecture, it brings as well additional risk and responsibility. Where is the data flowing?, Which code or service has access? All important question to ask.

An IT Architect could, using Confidential Computing technology, design a system where the critical data is only available in clear in one microservice and protect this service (and all if its instances) using a Confidential Computing runtime.

I have to read through what can be done with OpenShift and Secure Execution, but I'm thrilled to see the next steps and details on this path. So definitely more on this in the future.

Back to Secure Execution itself. This technology provides the ability to isolate a guest from the host on the data "in use". In addition to the data in flight and data at rest which we all know and care about already (or should). The image started in Secure Execution is validated through attestation providing trust on what is running inside of it, so it has not been modified or willingly or by accident. The good think here is the size of an image. The way it had been added to the LinuxONE environment you can protect even guest with the need of large memory allocation and still have the full memory protected. This gives an advantage over other current available technologies. And I'm not talking about the benefits someone would get alone by the IO optimised architecture you find on the LinuxONE system.

From my perspective an interesting topic to keep an eye on. And hopefully it will trigger me again if I'm stuck in procrastination again.

Stefan Schmitt

Love to discuss topics around Technology | LinuxONE | Mainframe | Security | Leadership

2 年

In case you want to know more about it. There will be a WebCast at Wednesday, March 29th, 11:00 AM - 12:00 PM ET ·???????Register here:?https://ibm.webex.com/ibm/onstage/g.php?MTID=ebc5f8251de8e8366f5ff71f577a1089a by Holger Wolf Good way to learn and ask more about this topic

回复
Sandeep B.

Lead Solutions Architect & Thought Leader

2 年

Great article Stefan Schmitt . Will catch you to discuss more

Holger Wolf

STSM / Chief Product Owner - OpenShift on IBM Z and LinuxONE

2 年

Glad I reminded you Stefan Schmitt for this nice article to get one step further in addition to my post.

回复
Iqbal Singh

Executive Architect, Multi-Verse Cloud, Payments, IBM Services..

2 年

The real question is; did you miss us ? ??

回复
Iqbal Singh

Executive Architect, Multi-Verse Cloud, Payments, IBM Services..

2 年

You are always missed ??

回复

要查看或添加评论,请登录

Stefan Schmitt的更多文章

  • Dynamic Infrastructure on LinuxONE

    Dynamic Infrastructure on LinuxONE

    Back at the writing desk after busy weeks. It is always amazing to step back and think about what had been new…

  • Platform management options on LinuxONE

    Platform management options on LinuxONE

    In previous posts I talked about the different hypervisors IBM provides on the mainframe especially LinuxONE. To recall…

  • New capabilities around sustainability on LinuxONE 4

    New capabilities around sustainability on LinuxONE 4

    You may or may not know about the history of what IBM is doing around taking care of the environment. Over 32 years IBM…

    6 条评论
  • Getting your team behind you

    Getting your team behind you

    I think I have to start with some background about the banner. The American Football team you see above are the Red…

    4 条评论
  • Can you use Low Code Frameworks on LinuxONE

    Can you use Low Code Frameworks on LinuxONE

    Low Code, what does it mean? I think before I talk about if it can be used on LinuxONE or the Mainframe I need to talk…

    1 条评论
  • Hypervisor on LinuxONE - z/VM

    Hypervisor on LinuxONE - z/VM

    I mentioned earlier already, on LinuxONE there exists multiple Hypervisor. But why? In LinuxOne Virtualisation I gave a…

    1 条评论
  • What is "the Mainframe"?

    What is "the Mainframe"?

    Honestly I do not have a single answer for it. I got triggered by the post by Thomas Schwaerzl below which I saw Today…

    3 条评论
  • Post Quantum Cryptography and IBM LinuxONE

    Post Quantum Cryptography and IBM LinuxONE

    The last month I had the honor to speak about Post Quantum Cryptography (PQC) at an IBM Conference in Montpellier. It…

  • Hypervisors on LinuxONE (part1)

    Hypervisors on LinuxONE (part1)

    In the last post I described high level how flexible IBM LinuxONE is in regards to resource assignment and separation…

    6 条评论
  • virtualisation on LinuxONE or What is an IFL?

    virtualisation on LinuxONE or What is an IFL?

    Ok I have to admit I knew already parts of this post, but I really was impressed by the talk I listed to this week and…

    8 条评论

社区洞察

其他会员也浏览了