AWS unveils highly secure cloud 'enclaves' for your most confidential data

security
(Image credit: Shutterstock)

AWS is giving customers an even more secure way to protect sensitive data in the cloud with a new EC2 instance type that has no external network connectivity, no persistent storage and no user access.

Customers in industries such as financial services, defense, media and entertainment and life sciences often process highly sensitive data on Amazon's cloud. However, when they do this, they need to protect against internal and external threats while dealing with complex situations involving multiple partners, vendors, customers and employees.

While customers currently use AWS VPC (virtual private cloud) to create isolated environments with controlled and limited connectivity, the company is giving them another option to store their sensitive data with the launch of AWS Nitro Enclaves.

AWS Nitro Enclaves

AWS Nitro Enclaves can be used to carve out an isolated environment on any EC2 instance powered by the Nitro System. 

While the company's Nitro System already isolates multiple EC2 instances running on the same hardware, Nitro Enclaves provide additional isolation through an independent kernel and by partitioning the CPU and memory of a single “parent” EC2 instance. The parent EC2 instance connects to the enclave over a virtual socket and this socket is the only way data can get in or out of a Nitro Enclave.

Chief evangelist for AWS Jeff Barr explained how these new secure enclaves utilize the “Nitro" hypervisor AWS introduced back in 2017 in a blog post, saying:

“The Nitro Hypervisor creates and then signs an attestation document as it creates each Nitro Enclave. The document contains (among other things), a set of Platform Configuration Registers (PCRs) that provide a cryptographically sound measurement of the boot process. These values, when attached to a KMS key policy, are used to verify that the expected image, OS, application, IAM role, and instance ID were used to create the enclave. After KMS has performed this verification step, it will perform the desired API action (decrypt, generate data key, or generate random value) requested by the code running in the enclave.”

Enclaves are now available on any EC2 instance that runs Nitro and while users can create one enclave from an EC2 instance, AWS also plans to support multiple enclaves in the future.

Via The Register

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
An AI face in profile against a digital background.
Smarter, faster, better: how AI is elevating the customer experience industry
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
Latest in News
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025