|
| 1 | +--- |
| 2 | +title: Perform secure multiparty data collaboration on Azure |
| 3 | +description: Learn about Intel SGX hardware to enable your confidential computing workloads. |
| 4 | +author: mathapli |
| 5 | +ms.service: azure-confidential-clean-rooms |
| 6 | +ms.subservice: workloads |
| 7 | +ms.topic: conceptual |
| 8 | +ms.date: 10/28/2024 |
| 9 | +ms.author: mathapli |
| 10 | +--- |
| 11 | + |
| 12 | +# Azure Confidential Clean Rooms |
| 13 | + |
| 14 | +> [!NOTE] |
| 15 | +> Azure Confidential Clean Rooms is currently in Gated Preview. Please fill the form at https://aka.ms/ACCRPreview and we will reach out to you with next steps. |
| 16 | +
|
| 17 | +Azure Confidential Clean Rooms, aka ACCR, offers a secure and compliant environment that helps organizations overcome the challenges of using privacy-sensitive data for AI model development. This solution ensures that the model's intellectual property remains intact while also enabling advanced data analytics. |
| 18 | + |
| 19 | +With advanced privacy-enhancing technologies such as secure governance & audit , secure collaboration (TEE), verifiable trust, differential privacy and controlled access, organizations can safely collaborate and analyze sensitive data without violating compliance standards or risking data breaches. This capability is essential for unlocking the full potential of AI and data analytics while ensuring adherence to evolving data privacy laws. |
| 20 | + |
| 21 | +## Who should use Azure Confidential Clean Rooms? |
| 22 | +Azure, Confidential Clean Rooms could be a great choice for you if you have one or more scenarios such as the ones below: |
| 23 | + |
| 24 | +- Data Analytics and Inferencing: Organizations looking to build insights on second-party data while ensuring data privacy can leverage ACCR. This is particularly useful when data providers are concerned about data exfiltration. ACCR ensures that data is only used for agreed purposes and safeguards against unauthorized access or egress (as it is a sandboxed environment). |
| 25 | +- Data Privacy ISVs: Independent Software Vendors (ISVs) who provide secure multiparty data collaboration services can use ACCR as an extensible platform. It allows them to add enforceable tamperproof contracts with governance and audit capabilities, as well as uses confidential hardware underneath to ensure data is encrypted during processing so that their customers' data remains secure. |
| 26 | +- ML fine tuning: For organizations that require data from various sources to train or fine-tune machine learning models but face data sharing regulations, ACCR provides a solution. It allows any party to audit and confirm that data is being used only for the agreed purpose, such as ML modeling |
| 27 | +- ML inferencing: For organizations that require data from various sources to train or fine-tune machine learning models but face data sharing regulations, ACCR provides a solution. It allows any party to audit and confirm that data is being used only for the agreed purpose, such as ML modeling |
| 28 | + |
| 29 | +### Industries which can successfully leverage ACCR |
| 30 | +1. Healthcare- In the healthcare industry, Azure Confidential Clean Rooms enable secure collaboration on sensitive patient data. For example, healthcare providers can use clean rooms to train and fine-tune AI/ML models for predictive diagnostics, personalized medicine, and clinical decision support. By leveraging confidential computing, healthcare organizations can protect patient privacy while collaborating with other institutions to improve healthcare outcomes. |
| 31 | +Subsequently, ACCR can also be used for ML inferencing where partner hospitals can leverage power of these models for early detection. |
| 32 | +2. Advertising- In the advertising industry, Azure Confidential Clean Rooms facilitate secure data sharing between advertisers and publishers. This enables targeted advertising and campaign effectiveness measurement without exposing sensitive user data. |
| 33 | +3. BFSI- The BFSI sector can leverage Azure Confidential Clean Rooms to securely collaborate on financial data, ensuring compliance with regulatory requirements. This enables financial institutions to perform joint data analysis and develop risk models, fraud detection models, lending scenarios amongst others without exposing sensitive customer information. |
| 34 | +4. Retail- In the retail industry, Azure Confidential Clean Rooms enable secure collaboration on customer data to enhance personalized marketing and inventory management. Retailers can use clean rooms to analyze customer behavior and preferences to create personalized marketing campaigns without compromising data privacy. |
| 35 | + |
| 36 | +## Benefits |
| 37 | + |
| 38 | +:::image type="content" source="./media/confidential-clean-rooms/accr-benefits.png" alt-text="Graphic of Azure Confidential Clean Rooms benefits, showing zero trust, no data duplicationm container workloads, and managed governance."::: |
| 39 | + |
| 40 | +Azure Confidential Clean Rooms (ACCR) provide a secure and compliant environment for multi-party data collaboration. Built on confidential hardware, ACCR ensures that sensitive data remains protected throughout the collaboration process. Here are some key benefits of using Azure Confidential Clean Rooms: |
| 41 | + |
| 42 | +- Secure Collaboration and Governance: |
| 43 | +ACCR allows collaborators to create tamper-proof contracts that contain the constraints which are enforced by the clean room. Governance ensures validity of constraints before allowing data to be released into clean rooms and drives transparency amongst collaborators by generating tamper-proof audit trails. This is made possible with the help of the open-source confidential consortium framework used by Azure Confidential Clean Rooms. |
| 44 | +- Regulatory Compliance: |
| 45 | +Confidential computing can address some of the regulatory and privacy concerns by providing a secure environment for data collaboration. This is particularly beneficial for industries such as financial services, healthcare, and telecom, which deal with highly sensitive data and personally identifiable information (PII). |
| 46 | +- Enhanced Data Security: |
| 47 | +ACCR leverages confidential computing to provide a hardware-based, trusted execution environment (TEE). This environment is sandboxed and allows only authorized workloads to execute. This prevents unauthorized access to data or code during processing, ensuring that sensitive information remains secure. |
| 48 | +- Verifiable trust at each step with the help of cryptographic remote attestation forms the cornerstone of Azure Confidential Clean Rooms. |
| 49 | + |
| 50 | +:::image type="content" source="./media/confidential-clean-rooms/accr-illustration.png" alt-text="Graphic of Azure Confidential Clean Rooms benefits, showing zero trust, no data duplicationm container workloads, and managed governance."::: |
| 51 | + |
| 52 | +- Cost-Effective: |
| 53 | +By providing a secure and compliant environment for data collaboration, ACCR reduces the need for costly and complex data protection measures. This makes it a cost-effective solution for organizations looking to leverage sensitive data for analysis and insights |
| 54 | + |
| 55 | + |
| 56 | +##Onboarding to Azure Confidential Clean Rooms |
| 57 | +ACCR is currently in Gated Preview. To express your interest in joining the gated preview, please follow below steps: |
| 58 | +- Fill the form at https://aka.ms/ACCR-Preview-Onboarding (or use QR code on the right) |
| 59 | +- Once you fill in the form, further steps will be shared with you on onboarding. |
| 60 | +- For further questions on onboarding reach out to [email protected]. |
| 61 | +- After reviewing details, we will reach out to you with detailed steps for onboarding. |
| 62 | + |
| 63 | +##Frequently asked questions |
| 64 | + |
| 65 | +- Question: Where is the location Microsoft published side cars? |
| 66 | +- Answer: The Microsoft published side cars are available at: https://mcr.microsoft.com/cleanroom |
| 67 | + |
| 68 | +- Question: Can more than 2 collaborators participate in a collaboration? |
| 69 | +- Answer: Yes, more than 2 collaborators can become part of collaboration. This allows multiple data providers to share data in the clean room. |
| 70 | + |
| 71 | +If you have questions about Azure Confidential Clean Rooms, please reach out to <[email protected]>. |
| 72 | + |
| 73 | +## Next steps |
| 74 | + |
| 75 | +- [Deploy Confidential container group with Azure Container Instances](/azure/container-instances/container-instances-tutorial-deploy-confidential-containers-cce-arm) |
| 76 | +- [Microsoft Azure Attestation](/azure/attestation/overview) |
0 commit comments