When a VM is confidential (CVM), the host cannot access its memory, enabling data-in-use protection. Hardware vendors like Intel (TDX) and AMD (SEV-SNP) provide the underlying technology to achieve this. The use case becomes more complex when a persistent disk is added to a CVM: the disk must also be encrypted, but how can we safely manage its... Weiterlesen: Disk encryption using attestation for Confidential VMs (asg2026)
Intelligence View
⚡ tsecurity.de Intelligence
Disk encryption using attestation for Confidential VMs (asg2026)
When a VM is confidential (CVM), the host cannot access its memory, enabling data-in-use protection. Hardware vendors like Intel (TDX) and AMD (SEV-SNP)…