DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk6 min

The Case for Confidential Computing: Protecting Data in Use

Confidential computing adds a hardware-backed boundary for data in use, helping reduce reliance on cloud hosts while leaving important software and operational risks to address.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confidential computing uses a hardware-based, attested Trusted Execution Environment (TEE) to reduce exposure of sensitive data while it is being processed. It addresses a gap left by encryption at rest and in transit—but it does not make a workload invulnerable or remove the need to secure its software, keys, and operations.

What confidential computing protects

Data has three broad states: it can be stored, moving over a network, or actively being processed. Encryption at rest and in transit protects the first two states. During computation, however, software generally needs access to usable data. A TEE creates a hardware-backed boundary intended to limit exposure in that third state.

As an Amazon Associate I earn from qualifying purchases.

The Confidential Computing Consortium (CCC) defines the field as “the protection of data in use by performing computation in a hardware-based, attested Trusted Execution Environment.” NIST’s glossary describes hardware-enabled features that isolate and process encrypted data in memory, reducing its exposure to concurrent workloads and the underlying system or platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A TEE aims to protect confidentiality, integrity, and code integrity: it seeks to limit who can inspect data during execution, detect unauthorized changes to protected data, and help establish that the expected code is running. These are bounded assurances tied to a particular implementation and configuration, not a promise that every part of an application is safe.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How a TEE changes the trust boundary

In a conventional cloud deployment, customers rely on the cloud infrastructure and privileged software to handle workloads securely. A hardware-backed TEE is designed to reduce how much the customer must trust the host operating system, hypervisor, administrators, or other tenants with plaintext during execution. What is isolated, and from which threats, depends on the technology and its configuration.

Attestation provides evidence about a TEE’s identity, origin, or state, including relevant software measurements. A relying party can check that evidence against its own policy before releasing secrets or accepting a result. Attestation is therefore an input to a trust decision—not a blanket certification that the application is secure or behaves appropriately.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For a practical deployment, the trust decision typically has this shape:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Establish the workload. The software and its configuration must be delivered through a process the organization trusts.
  2. Verify the evidence. A verifier checks the attestation against an explicit policy, including which hardware and software measurements are acceptable.
  3. Release secrets conditionally. Keys or other sensitive inputs should be provisioned only if the evidence passes the policy checks.
  4. Control outputs and operations. The application still needs appropriate authorization, output handling, monitoring, patching, and incident response.

Microsoft describes Azure confidential computing as a way to protect data in use from access by the infrastructure operator. Microsoft says that, when Azure confidential computing is properly configured, it cannot access unencrypted customer data in use. That is Microsoft’s description of its service and configuration—not a universal guarantee for every cloud provider, workload, or TEE.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Where confidential computing can be useful

  • Sensitive cloud workloads: Organizations can use shared infrastructure while reducing the need to trust its host operator with data in memory.
  • Secrets and machine identities: NIST’s hardware-enabled security work identifies protection of keys and machine identities while in use as a motivation.
  • AI workloads: NIST IR 8320E, an initial public draft dated May 29, 2026, describes an approach for protecting datasets used by AI workloads in cloud infrastructure. Its comment period ended July 13, 2026. It is an example of relevance to AI, not evidence that every stage of an AI pipeline can be protected end to end.
  • Collaborative analysis: A TEE can provide a more constrained place for organizations to process sensitive data without exposing it to the infrastructure operator. Application design, governance, access rules, and output controls still determine what is ultimately disclosed.

Confidential computing is not limited to public cloud servers. The CCC’s technical analysis describes potential use on on-premises servers, gateways, IoT devices, edge systems, and user devices, as well as in components such as GPUs and network interface cards.

Enclaves and confidential virtual machines are different approaches

Two common patterns illustrate why “confidential computing” is not a single interchangeable product feature. An application enclave protects selected code and data; a confidential virtual machine (VM) protects a broader VM trust domain. The right boundary depends on the workload, required compatibility, and threat model.

Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Approach What is isolated Workload implications Examples in the cited sources
Application enclave A selected application component and its data. Teams may need to place sensitive operations inside the enclave and adapt code or its surrounding software. Compatibility depends on the implementation. Intel SGX enclaves, described in Intel’s Microsoft payment-processing case study.
Confidential VM A VM or defined VM trust domain, rather than only a selected application component. Can suit workloads intended to run as a VM, but supported operating systems, instances, configuration, and attestation paths vary by provider and hardware. AMD SEV-based VMs, including SEV-SNP; Azure also documents confidential VMs using Intel TDX.

AMD lists cloud providers offering SEV-based confidential VMs, including AWS, Google Cloud, IBM, Microsoft Azure, and Oracle Cloud Infrastructure. Availability and exact product support vary. Azure documentation likewise describes configuration and attestation differences between supported offerings, so confirm the current instance, region, and service requirements before deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Neither pattern is automatically superior. Compare the isolation boundary, code and operating-system changes, supported devices, who verifies attestation, which measurements are checked, how keys are released, and how the design addresses side channels and operational risks. Performance, memory constraints, scale, and cost are workload- and service-specific; the cited material does not establish a neutral, current benchmark or cost comparison.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the payment-processing example shows—and does not show

Intel’s February 2024 solution brief describes Microsoft moving payment processing to Azure confidential computing using Intel SGX enclaves to protect key operations. Intel reports that the deployment handles $25 billion in credit-card transactions per year and that Microsoft saved $2 million in hardware-security costs after moving from on-premises infrastructure. These are vendor-published case-study claims, not independently audited industry statistics or a forecast of what another organization would save.

What confidential computing does not solve

The CCC’s technical analysis cautions that no TEE provides absolute security. Protection depends on the implementation, configuration, and threats it is designed to address.

  • Side channels: Timing, cache activity, power use, and other observable behavior may leak information even when an attacker cannot directly read protected memory. Mitigations may require work from hardware, runtime and library providers, and application developers.
  • Faulty attestation or provisioning: Isolation is not enough if the verifier accepts the wrong measurements, workload delivery is compromised, or a key-release policy is misconfigured.
  • Implementation differences and bugs: Protections against behaviors such as rollback, replay, and integrity attacks vary across technologies and configurations.
  • Out-of-scope threats: The CCC analysis generally places sophisticated invasive physical attacks, upstream hardware supply-chain attacks, and denial of service outside current TEE threat models.
  • Application flaws and misuse: A TEE does not fix authorization bugs, unsafe outputs, insecure application logic, or poor data governance.

Confidential computing belongs within a broader security architecture. Encryption at rest and in transit, sound identity and key-management controls, secure boot, patching, logging, and governance remain important. A TEE narrows one part of the trust boundary; it does not eliminate trust or automatically establish regulatory compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to decide whether it fits

Start with the data and threat you are trying to protect, then test whether the proposed TEE meaningfully reduces that exposure without creating unmanageable operational complexity.

  • Name the adversary and protected state. Specify whether the concern is a host administrator, hypervisor, other tenant, or another threat—and whether the sensitive data is exposed during execution.
  • Choose the boundary deliberately. Decide whether selected code needs an enclave or whether a VM-level boundary better fits the workload.
  • Make attestation policy concrete. Identify who verifies evidence, what measurements and versions are acceptable, and what happens when verification fails.
  • Design key release and recovery. Decide where secrets are held, what conditions permit their release, and how rotation, revocation, and incidents will be handled.
  • Test the whole application. Review side-channel exposure, permissions, inputs and outputs, logging, update procedures, and failure behavior—not just whether the TEE launches.
  • Validate deployment-specific constraints. Confirm supported hardware, region, operating system, devices, provider configuration, and pricing for the exact service being considered.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.