18–20 Sept 2024
Europe/Vienna timezone

Session

Confidential Computing MC

20 Sept 2024, 10:00

Description

Confidential Computing microconferences in the past years brought together developers working secure execution features in hypervisors, firmware, Linux Kernel, over low-level user space up to container runtimes. A broad range of topics were discussed ranging from entablement for hardware features up to generic attestation workflows.

In the past year - guest memfd has been merged, TDX and SNP host support is getting closer to being merged. Next to go in will be support for ARM CCA and RISC V CoVE. In the meantime, there is progress being made on the Trusted I/O front.

But there is still some way to go and problems to be solved before a secure Confidential Computing stack with open source software and Linux as the hypervisor becomes a reality. The most pressing problems right now are:

  • Support TEE privilege separation extensions (TDX partitioning and AMD SEV-SNP VM Privilege Levels) both on the guest and host side
  • Secure IRQ delivery
  • Secure VM Service Module (SVSM) support for multiple TEE architectures
  • Trusted I/O software architecture
  • Live migration of confidential virtual machines

Other potential problems to discuss are:

  • Remote attestation architectures
  • Deployment of Confidential VMs
  • Linux as a CVM operating system across hypervisors
  • Unification of various confidential computing API

The Confidential Computing Microconference wants to bring developers working on confidential computing together again to discuss these and other open problems.

Key attendees:

Presentation materials

Building timetable...