Security analysis of confidential-compute instruction set architecture for virtualized workloads

Ravi Sahita, Dror Caspi, Barry Huntley, Vincent Scarlata, Baruch Chaikin, Siddhartha Chhabra, Arie Aharon, Ido Ouziel · 2021

Data in-use protection is critical to the data use lifecycle. Trusted execution environments supported by hardware are a key element of a system that provides data protection. The computing model focused on data protection via hardware-attested trusted execution engines is broadly called confidential computing. In this paper, we describe a security analysis of an Intel ISA extension called Intel®Trust Domain Extensions (Intel®TDX) to host confidential compute virtual machine workloads (called Trust Domain Virtual Machines or TD VMs) in the cloud. This paper describes the threat model and security architecture for Intel TDX. We describe the architecture principles, design constraints, and outline open problems that should be solved to increase the utility and scale of confidential computing models.

Read the paper · More papers on PaperTik