The Unofficial Guide to Apple’s Private Cloud Compute - Jonathan Mortensen, CONFSEC

AI EngineerAbout 6 min readJul 31, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Private Cloud Compute (PCC)
  • Stateless Computation
  • Enforceable Guarantees
  • Non-Targetability
  • No Privilege Runtime Access
  • Verifiable Transparency
  • Oblivious HTTP
  • Blind Signatures
  • Secure Enclave (TPM)
  • Secure Boot and Hardened Operating System
  • Remote Attestation
  • Transparency Log
  • Confidential Computing

Apple's Private Cloud Compute (PCC): An Unofficial Guide

This presentation discusses Apple's Private Cloud Compute (PCC), a system designed to perform AI inference on user data remotely while maintaining privacy. The speaker emphasizes that this is an unofficial guide based on publicly available information.

Speaker Background and Disclaimer

The speaker has a PhD in data science and biomedical informatics and has sold two companies in AI/data and cybersecurity/infrastructure. He is currently building a company called Confident Security. He clarifies that he is not an Apple employee and is not speaking on their behalf.

Motivation for Privacy

The speaker motivates the importance of privacy by citing the DeepSeek leak of 100 million sensitive chat logs and highlighting OpenAI's recent requirement to retain all chat data, regardless of privacy settings. He argues that Apple prioritizes privacy as a major selling point and wants to avoid similar privacy breaches.

The Problem Apple Solved

AI requires more compute power than available on a phone, but Apple wants to integrate AI into its devices while maintaining user privacy. The challenge is to enable remote compute without compromising privacy or incurring excessive costs. The core question is: How do you get remote compute while remaining private and cheap?

Conceptual Architecture

The speaker frames the problem as an iPhone communicating with an untrusted remote server (a "black box"). Apple's solution aims to make this black box more transparent and controllable by the iPhone.

The conceptual architecture involves several key components:

  1. Anonymizer: The first step is to anonymize the data, making it harder to target specific users. This is achieved using Oblivious HTTP, where requests are routed through Cloudflare, obscuring the user's IP address.
  2. Separation of Authentication: Apple separates authentication from identity using blind signatures. This is analogous to using anonymous coins at an arcade, where the machines you spend your money on are not linked to your identity.
  3. Remote Attestation: The iPhone verifies the code running on the remote server before sending data. The iPhone asks the AI engine what it is running, and if the AI engine replies with a trusted code, the iPhone can run the AI on the submitted data. This is how they achieve verifiable transparency.
  4. No Privilege Runtime Access: SSH access is removed to prevent unauthorized access.
  5. Enforceable Guarantees: Disks are removed to prevent data logging.
  6. Stateless Computation: With no disk and no access, the data can only be used to respond to the iPhone.

Five Key Requirements of Apple's PCC

Apple's PCC is designed to meet five key requirements:

  1. Stateless Computation: Data is only used to satisfy the request and cannot be logged or used for other purposes.
  2. Enforceable Guarantees: Security is enforced through code, not just policies. For example, the absence of a disk ensures no data can be saved.
  3. Non-Targetability: It should be difficult to target specific users' data.
  4. No Privilege Runtime Access: There is no way to bypass security restrictions in production.
  5. Verifiable Transparency: It must be possible to prove that the above requirements are met.

Six Technical Components

Apple achieves these requirements using six technical components:

  1. Oblivious HTTP: Anonymizes requests using a third party (Cloudflare).
  2. Blind Signatures: Enables authentication without revealing identity.
  3. Secure Enclave (TPM): A separate piece of hardware where private keys are kept, ensuring they cannot be removed.
  4. Secure Boot and Hardened Operating System: A limited version of iOS that is difficult to hack or modify.
  5. Remote Attestation: The iPhone verifies the code running on the remote server before sending data.
  6. Transparency Log: A record of all software deployed on Apple's private nodes, allowing verification of the attestation process.

Remote Attestation Explained

Remote attestation involves the client (iPhone) querying the server for its configuration. The server responds with signed claims (e.g., genuine hardware, specific software versions) and a public key. The client verifies these claims and, if trusted, uses the public key to encrypt data sent to the server. The server can only decrypt the data if it still matches the signed claims.

Transparency Log Explained

The transparency log is a database of software releases and components, signed by authorized personnel. Each record includes the binary's hash and the date of addition. This allows reviewers to verify the behavior of binaries offline and check that remote attestations match the log. If an attestation is not found in the log, it indicates a potential compromise. The log is append-only and uses a Merkel tree to prevent modifications.

How It All Comes Together

The iPhone requests a remote attestation package through the anonymizer. If the iPhone trusts the attestation, it sends the data, which can only be decrypted if the AI engine is running the exact code that was attested to. The transparency log is used to verify that the attested claims match the log's contents.

Gaps and Downsides of Apple's PCC

  • Trust in Apple: Users must trust Apple's supply chain and key management practices.
  • Limited Availability: Only available on Apple devices for consumer use.
  • Latency: Limited by latencies to Apple data centers.
  • Compute Costs: Higher due to encryption overhead.
  • Limited Customization: No custom models or fine-tuning.
  • Client Complexity: Complex client libraries for orchestration.
  • Operational Complexity: No SSH access or logging.
  • No Usage Tracking: Difficult to track usage for cost allocation.
  • Not Open to Third-Party Developers:

Lessons for Non-Apple Environments

Even without Apple hardware, developers can leverage several PCC principles:

  • Oblivious HTTP and Blind Signatures: Libraries are available for implementation.
  • TPMs (Virtual TPMs): Used for secure key storage in Intel/AMD hardware and cloud environments.
  • Secure Boot and Hardened Operating Systems: Standard security practices.
  • Remote Attestation: Emerging standards, tied to TPMs.
  • Transparency Logs: Open-source options like SIG SUM and SIG Store.
  • Confidential VMs with GPUs: Encrypted memory for H100/H200 GPUs.
  • Open Source and Reproducible Builds: Linking source code to binaries for security research.

Market Trends

Apple has set a standard for private AI, and other companies are following suit. Azure AI is doing private inferencing, and Meta has added private processing features.

Confident Security

The speaker's company, Confident Security, is building a similar system for non-Apple environments.

Conclusion

Apple's PCC represents a significant advancement in privacy-preserving AI. While it has limitations, its principles and components can be adapted for use in other environments to enhance data privacy and security. The key takeaways are the importance of verifiable transparency, remote attestation, and the use of secure hardware and software practices.

AI summaries can miss context or contain errors. Check important details against the original video.

MAKE IT YOURS

Read. Remember. Reuse.

Free tools

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.