Kubernetes Podcast from Google cover image

Kubernetes Podcast from Google

Confidential Computing, with Fabian Kammel

Nov 23, 2023
Guest Fabian Kammel, Security Architect at ControlPlane, discusses confidential computing, trusted execution environments, and the differences between TPMs and HSMs. The chapter also explores the concept of confidential virtual machines and their use in sensitive industries like defense and healthcare.
53:36

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Trusted execution environments (TEEs) and confidential virtual machines (CVMs) provide hardware-protected and isolated environments for computations.
  • TPMs and HSMs offer varying levels of security capabilities for key storage and cryptographic operations.

Deep dives

Trusted execution environments and confidential virtual machines

Trusted execution environments (TEEs) and confidential virtual machines (CVMs) are two key concepts in confidential computing. TEEs provide hardware-protected environments that shield sensitive computations from external observers. They have been used in specialized hardware like TPMs and HSMs. On the other hand, CVMs are virtual machines that offer memory encryption and remote attestation. CVMs are easier to use and provide transparency and isolation within the VM. They are available in cloud environments and can be a secure solution for sensitive workloads.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner