Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

What is Confidential Computing?

CNCF Confidential Containers

Before getting to confidential computing, we must understand data security challenges and solutions.

The Data Security Triad

Modern data security is often described using three pillars:

PillarsDescriptionProtection Mechanism
Data at RestStored on disk, databases, backupsEncryption (e.g., AES, LUKS)
Data in TransitMoving across networksTLS/mTLS, VPNs
Data in UseActively being processed in memoryConfidential Computing

For decades, security focused on the first two pillars. Confidential Computing (CC) fills the missing pillar - protecting data in use.

Data security triad

Current Data Security Challenges

When you run a workload in an infrastructure managed by an external entity, you face several fundamental challenges:

Current Solutions

Current Data Security Challenges and Solutions

Confidential Computing is one of the key PET technologies.

How Confidential Computing Compares to Other PETs

Confidential Computing is not the only technology that protects data during computation. Three cryptographic approaches solve overlapping problems, and it helps to know when each fits:

Confidential ComputingFHEMPCDifferential Privacy
Trust anchorCPU vendor’s hardwareMathematics (cryptography)Mathematics (cryptography)Statistics
Performance overheadLow (single-digit % for most workloads)Very highHigh (network-bound)Negligible
Application changesNone (VM-based TEEs)Rewrite around FHE operationsCustom protocol per use caseQuery/pipeline changes
Protects data in use from infrastructure✔ Yes✔ YesPartially (split among parties)✗ No
General-purpose computation✔ YesLimitedLimitedN/A
Maturity for productionGA on all major cloudsEmergingNicheMature (analytics)

The practical takeaway: Confidential Computing is the only PET that runs existing, unmodified applications at near-native speed, at the cost of trusting the CPU vendor and its hardware implementation. FHE and MPC remove even that trust assumption but are limited to specialized workloads. These technologies also compose: multi-party analytics can run MPC protocols inside TEEs, and a model trained in a TEE can be released with differential privacy guarantees.

Confidential Computing Definition

“Confidential Computing is the protection of data in use by performing the computation in a hardware-based, attested Trusted Execution Environment.” — Confidential Computing Consortium

Three key phrases in this definition:

  1. Protection of data in use — not just at rest or in transit, but while actively being processed.

  2. Hardware-based — the security guarantee comes from the hardware itself, not from software policies that can be bypassed.

  3. Attested Trusted Execution Environment (TEE) — you can verify (remotely) that the environment is genuine and unmodified before trusting it with your secrets.

The CCC further specifies that TEEs provide three distinct security properties that are often overlooked:

PropertyWhat it means
Data confidentialityCode running outside the TEE cannot read data inside it
Data integrityCode running outside the TEE cannot modify data inside it without detection
Code integrityThe code running inside the TEE cannot be replaced or tampered with by outside software

Code integrity in particular is frequently underestimated — it ensures not just that your data is protected, but that the computation itself has not been altered by a privileged adversary.

The Core Problem Confidential Computing Solves

Confidential Computing solves the problem of securing remote computation — executing software on a remote computer owned by an untrusted party, with integrity and confidentiality guarantees.

This shifts the trust requirement: instead of trusting the infrastructure operator’s policies and personnel, you trust the hardware itself. A cloud provider’s software stack — including privileged administrators — cannot access your data in use, and you can verify this cryptographically.

What problem does Confidential Computing solve