Encryption at rest and in transit is no longer enough. The final frontier of cloud security is protecting data while it is in use. If you deploy workloads to the public cloud, you are implicitly trusting the host infrastructure. But for highly regulated sectors, financial services, and privacy-first machine learning, perimeter security and disk encryption leave a critical vulnerability: data exposed in plaintext within CPU memory. Confidential Computing in Practice is the definitive, authoritative guide for platform architects, security engineers, and DevOps professionals who need to build hardware-enforced trust boundaries in zero-trust environments. Moving far beyond high-level theory, this book provides the deep technical mechanics of Trusted Execution Environments (TEEs) and equips you with the practical methodologies required to isolate your workloads from malicious cloud operators, compromised hypervisors, and insider threats. Inside, you will learn how to: Architect Hardware Roots of Trust: Master the fundamental architecture of Intel SGX enclaves, AMD SEV-SNP memory encryption, and Intel TDX confidential virtual machines. Implement Remote Attestation Pipelines: Build robust attestation services (DCAP, Azure Attestation) to cryptographically verify platform integrity before releasing decryption keys. Manage Keys and Enclave Identity: Securely seal secrets to enclave measurements, integrate with external Hardware Security Modules (HSMs), and enforce policy-based key release mechanisms. Deploy to the Cloud-Native Edge: Orchestrate Confidential Containers (Kata, Gramine, Enarx) in Kubernetes and run isolated workloads seamlessly on Azure, GCP, and AWS. Secure AI & Machine Learning: Protect proprietary model weights and sensitive training data during active inference, while navigating the performance tradeoffs of GPU-accelerated compute. Mitigate Advanced Side-Channel Attacks: Hardening your enclave code against cache-timing, speculative execution, and page-fault vulnerabilities. Stop relying solely on cloud provider promises. Whether you are building a multi-party secure data-sharing system or migrating sensitive workloads to confidential VMs, this book gives you the exact blueprint to take back cryptographic control of your data's execution state. Close the final gap in your security posture. Secure your copy today and build verifiable, hardware-backed trust into your cloud architecture.
ThriftBooks sells millions of used books at the lowest everyday prices. We personally assess every book's quality and offer rare, out-of-print treasures. We deliver the joy of reading in recyclable packaging with free standard shipping on US orders over $20. ThriftBooks.com. Read more. Spend less.