Anestis Bechtsoudis

Confidential Computing Across Cloud and Edge

  • Confidential Computing
  • Cryptellum
  • CENSUS

A solution that leverages confidential computing technologies to protect sensitive data and workloads across both cloud and edge environments, ensuring security, privacy, and trusted execution throughout the computing lifecycle.

Shared compute is now the default model across cloud and edge, consolidating tenants and mixed-criticality workloads on common infrastructure. Hardware-backed trust and remote attestation provide the evidence organisations need to verify what is actually running before sensitive data, keys or models are released.

Illustration • Upgrading Trust • V.1.1
Illustration • Upgrading Trust • V.1.1

Shared compute creates an assurance gap

Modern platforms are becoming shared in principle. Clouds multiplex tenants across the same silicon. Vehicles consolidate functions once separated across ECUs. Mission computers combine autonomy, payload processing and communications on one SoC. AI clusters serve multiple customers, models and data owners on common accelerators.

This consolidation delivers economic and operational value, but it also places different security domains on the same physical resources, with their isolation depending on firmware, hypervisors, kernels, orchestrators and management planes. Much of that privileged software is large, frequently updated and operated by parties other than the data owner.

Modern isolation technologies are strong. The remaining gap is assurance. Policy contracts, certifications and audit reports describe what should be true. They do not prove what was running when sensitive data was processed.

From assertion to evidence

Sensitive assets must be available in usable form while being processed: model weights, prompts, retrieval corpora, cryptographic keys and regulated records. Conventional encryption at rest and in transit does not protect this runtime state.

At the same time, DORA, NIS2, the EU AI Act, DESC cloud standards, PCI DSS, IEC 62443, UNECE R155 and ISO/SAE 21434 are increasing the expectation that controls are implemented, governed and demonstrable. Security is becoming an evidence problem.

This matters most where organisations are still deciding whether shared infrastructure is acceptable: a bank assessing an AI pipeline, an OEM consolidating third-party and safety-relevant functions, or a defence integrator processing data on equipment that may be physically recovered.

The challenge is not the value of consolidation. It is proving that consolidation remains compatible with their obligations.

Confidential computing across cloud and edge

Confidential computing protects data in use, reduces what a workload must trust, and produces hardware-rooted evidence of platform and workload state. Data, keys and models can then be released according to proof rather than assumption.

In the cloud, it can place the hypervisor, host operating system and platform operators outside the set of components trusted for workload confidentiality and integrity. The challenge is scale: short-lived workloads, frequent image and firmware changes, automated policy updates and, for confidential AI, a second trust chain across the GPU.

At the edge, hardware-backed isolation and attestation can support security separation between safety-relevant functions and third-party code, while binding device identity, keys and mission data to protected hardware. The challenge is heterogeneity, long service life, physical access, rollback resistance and securing the update path.

The mechanism is consistent: measure what runs, prove it to a verifier, and release secrets only when the evidence satisfies policy. The principles are common, but the architecture cannot be transferred unchanged because cloud and edge systems have different trust anchors, adversaries and operating constraints.

Attestation is the control plane

The core building blocks are hardware roots of trust, verified and measured boot, execution isolation, accelerator protection and remote attestation. Technologies include TPM 2.0 and vTPM, secure elements, AMD SEV-SNP, Intel TDX and SGX, AWS Nitro Enclaves, Arm TrustZone and CCA, pKVM, and NVIDIA Confidential Computing.

For a remote relying party, isolation without attestation remains an assertion.

A complete control loop measures the platform and workload and produces hardware-rooted evidence. A verifier appraises that evidence against policy, and a relying party releases keys, model weights or credentials only when the appraisal passes. Where secrets or sessions are established, the attested workload identity should also be cryptographically bound to the channel or session.

This changes workload identity. Identity becomes a function of measured state and policy approval, not only an IAM role that a privileged actor might obtain.

What this enables

  • Confidential AI: Protected inference and training on regulated or proprietary data, with chained CPU and GPU trust.
  • Multi-party collaboration: Data clean rooms, federated learning and privacy-preserving workflows where participants can verify the code handling their data.
  • Regulated workload migration: PII, PHI and payment workloads on shared infrastructure, supported by cryptographic evidence.
  • Sovereignty and key control: Bring-your-own-key and bring-your-own-root-of-trust models that keep release authority under customer control.
  • Trusted edge platforms: Isolation across mixed-criticality functions, protected device identity and secure update paths.

How we engage

CENSUS applies its Cybersecurity Engineering model across the lifecycle of critical systems:

ASSESS: Assurance gap analysis, threat modelling, security posture reviews, data workflow analysis and technology selection against the business and threat context.

DESIGN: Trust architectures, verifier topology, attestation-conditioned key release, attested channels, workload identity and mixed-criticality compartmentalisation across public cloud, private cloud, on-premises, air-gapped and edge deployments.

BUILD: Implementation of production-ready key release services, verifier deployments, secure boot and OTA components, confidential container platforms and custom Cryptellum integrations, followed by adversarial validation of the implemented controls.

Cryptellum

Cryptellum is the CENSUS confidential computing platform for sensitive and AI workloads.

It turns attestation into an operational control plane through a lightweight SDK, workload integrity checks and application-facing APIs. It is agnostic across confidential computing technologies, deploys across public, private and air-gapped environments, and supports bring-your-own-key and bring-your-own-root-of-trust models.

Cryptellum can also integrate with customer PKI, policy engines, SIEM platforms and SOC workflows.

Why CENSUS

CENSUS has more than fifteen years of experience building and testing secure systems, with over 130 security engineers across Europe, the UAE, the United Kingdom. CENSUS is ISO 27001 certified and CREST accredited.

The practice spans embedded roots of trust, secure boot, TrustZone, pKVM, Gunyah and the Android Virtualization Framework through to SEV-SNP, TDX, SGX, Nitro Enclaves and confidential GPUs.

CENSUS has collaborated with the Google Cloud Confidential Computing team since November 2023 and published Challenging the Boundaries of Confidential Computing for AI.

Where to start

Organisations looking to strengthen critical systems need clear answers on what is exposed, what the platform can prove, and which controls will materially reduce risk. CENSUS assesses the system and threat model, then defines a practical path for stronger isolation, attestation and cryptographic control.

Talk to CENSUS about securing your critical systems.