5–7 Oct 2026
Europe/Prague timezone

CoVE in Action: the Landscape of Confidential VMs on RISC-V

Not scheduled
20m
Confidential Computing MC Confidential Computing MC

Speakers

Ruoqing He (LingCage)Mr Xiaoxia Cui (Damo)

Description

RISC-V CoVE (Confidential VM Extension) brings confidential computing — hardware-enforced isolation of tenant workloads from the hypervisor and cloud operator — to a fully open architecture.
A lightweight TEE Security Manager (TSM) sits below the hypervisor and enforces per-VM memory isolation, while tenants verify their environment through a standard IETF RATS attestation flow. The hypervisor retains scheduling control — it simply cannot see inside a tenant's TEE Virtual Machine (TVM).
We demonstrate CoVE Deployment Model 1 running end-to-end on real RISC-V hardware, built on OpenSBI and integrated with Kata Containers and the confidential-containers project — bringing confidential computing to container runtimes operators already use. No proprietary extensions, no special hardware — just standard RISC-V silicon.

Author

Mr Xiaoxia Cui (Damo)

Co-author

Ruoqing He (LingCage)

Presentation materials

There are no materials yet.