Off-Prem

SaaS

AWS users can finally use Nitro Enclaves on Arm Graviton EC2 instances

Just don't forget Enclave data is held in memory and costs can ramp when processing digital reams


AWS has updated its Nitro Enclaves feature for confidential computing so users can now operate it on Arm-based Graviton EC2 instances.

The move means it is supported on the majority of Intel, AMD, and Arm-based EC2 instances that use the cloudy giant's Nitro technology.

Nitro Enclaves were first introduced a couple of years ago as a way for AWS users to create a secure space in which to process sensitive data such as financial details or intellectual property in the cloud. It is basically an implementation of a Trusted Execution Environment (TEE), like Intel's SGX technology, but overseen by the AWS Nitro System.

For isolation, each enclave runs with an independent kernel and exclusive memory and CPU resources. Enclaves have no external network connection and no persistent storage, and all communication between an enclave and the parent EC2 instance that created it is via a virtual socket (vsock) connection.

According to AWS, customers familiar with the price and performance of Arm-based Graviton instances (which run on AWS's in-house designed processor silicon) can now build and operate secure enclaves on Graviton-based instances.

There are no additional charges for using Nitro Enclaves other than the EC2 instances used, along with any other AWS services that are used with Nitro Enclaves. Each enclave is treated as a separate virtual machine, attached to a parent EC2 instance that runs the customer's application.

AWS made available EC2 instances based on its latest Graviton3 silicon earlier this year. As The Register reported at the time, these cost less for customers to operate than comparable x86 instances, and AWS claims they provide up to 25 percent better compute performance and faster cryptographic workload speeds compared to those based on the earlier Graviton2 chips.

There are downsides to Nitro Enclaves, of course – all the Enclave data is held in memory, which could potentially lead to high memory costs if you need to process large chunks of information in one go.

Nitro Enclaves is supported with the following Graviton-based instance types; C7g, C6g, C6gd, C6gn, M6g, M6gd, R6g, R6gd, and X2gd. AWS said thatmore supported instance types are coming soon. ®

Send us news
Post a comment

Watchdog claims retaliation from military after questioning cushy federal IT contracts

IT-AAC had a hand in scrutinizing JEDI, now faces probe for challenging $300M+ single-source deals

You're so worried about AWS reliability, the cloud giant now lets you simulate major outages

Fake it 'til you break it, for a whole availability zone or WAN FAIL

AWS previews AppFabric for productivity – pitched as AI-powered glue between apps

Park user data in Amazon's servers for ML-generated insights and actions – yea or nay for you?

AWS rakes in half a billion pounds from UK Home Office

Someone has to top up the Bezos rocket fund, like British taxpayers

AWS exec: 'Our understanding of open source has started to change'

Apache Foundation president David Nalley on Amazon Linux 2023, Free software, and more

AWS unveils core-packed Graviton4 and beefier Trainium accelerators for AI

Also hedging its bets with a healthy dose of Nvidia chips too

The AI everything show continues at AWS: Generate SQL from text, vector search, and more

Invisible watermarks on AI-generated images? Sure. But major tools in the stack matter most

AWS accuses Microsoft of clipping customers' cloud freedoms

World's biggest off-prem service slinger submits comments to UK cloud inquiry, mostly has Redmond HQ's rival in its sights

AWS plays with Fire TV Cube, turns it into a thin client for cloudy desktops

$195 a pop, delivered, pre-provisioned ready to stream desktops or apps

Now AWS gets a ChatGPT-style Copilot: Amazon Q to be your cloud chat assistant

Anthropic CEO also rocks up on stage for reasons

Google submits complaints about Microsoft licensing to UK competition regulator

Now Microsoft has regulator breathing down its neck in three regions

Microsoft to intro dedicated mode for Cloud PCs

Latest Insider Build brings new features for Windows 365 Boot