Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Confidential Computing Security Concepts

CNCF Confidential Containers

The security model behind confidential computing depends on several connected concepts: Roots of Trust establish a trustworthy foundation, the Trusted Computing Base defines what must be trusted, and boot measurements record the software loaded into a Trusted Execution Environment (TEE). This chapter explains each concept and how it contributes to protecting data in use.

Root of Trust (RoT)

A Root of Trust is an essential, foundational security component that provides a set of trustworthy functions that the rest of the device or system can use to establish strong levels of security.

Trusted Computing Group What is a Root of Trust?

Functions a RoT Provides

FunctionDescription
Trusted BootEnsures only authorized software starts
MeasurementRecords what software ran (in a tamper-proof way)
Secure StorageStores cryptographic keys isolated from system software
ReportingProduces signed attestation reports
VerificationValidates other components’ integrity

Example RoTs - AMD Secure Processor, Trusted Platform Module (TPM), Virtual Trusted Platform Module (vTPM), Device Identifier Composition Engine (DICE)


Trusted Platform Module (TPM) and vTPM

TPM (Trusted Platform Module) is a computer chip (microcontroller) that can securely store artifacts used to authenticate the platform (your PC or laptop). These artifacts can include passwords, certificates, or encryption keys. A TPM can also be used to store platform measurements that help ensure that the platform remains trustworthy. It’s an example of a RoT component.

A Virtual Trusted Platform Module (vTPM) is a software-based representation of a physical Trusted Platform Module (TPM) 2.0 chip.

Trusted Computing Group TPM summary

TPM Platform Configuration Registers (PCRs)

PCRs are special registers inside a TPM where measurements (hashes) are stored. They can only be extended (not overwritten):

New_PCR_Value = SHA256(Old_PCR_Value || New_Measurement)
PCRWhat It Measures
0UEFI firmware
1UEFI firmware configuration
4Boot manager code and boot attempts
7Secure Boot policy (PK/KEK/db/dbx + the db entry used to authorize each loaded image)
8-15OS/application measurements

Trusted Computing Base (TCB)

The Trusted Computing Base is the set of all hardware, firmware, and software components that you must trust for your system’s security to hold. In a traditional cloud VM, this includes the hypervisor and host OS, both controlled by the cloud provider.

Trusted Computing Base in a traditional VM

Secure Boot, Trusted Boot, and Measured Boot

Secure Boot and Trusted Boot

Secure Boot verifies digital signatures before running bootloaders.

Trusted Boot extends this with a chain of verification — each stage checks the next before passing control.

Secure Boot and Trusted Boot

Measured Boot

Measured boot uses hardware Root of Trust (RoT) eg. TPM to record a cryptographic hash of every stage of the boot process into PCRs. This creates a tamper-evident audit trail that can be verified remotely at any point in time.

Measured Boot doesn’t block anything, instead it records everything that runs (eg. into the TPM’s PCRs). This enables remote attestation where a third party can cryptographically verify the exact software stack that booted.

Measured Boot

Summary Comparison

Comparison of boot security mechanisms: Secure Boot and Trusted Boot prevent unauthorised software from running; Measured Boot records what ran and enables remote verification via attestation.

Summary Comparison Table — Secure Boot vs Trusted Boot vs Measured Boot

Trusted Execution Environments (TEEs)

A Trusted Execution Environment (TEE) is a hardware-enforced execution environment that provides runtime isolation for code and data, protecting them from unauthorised access or tampering by privileged software such as the operating system, hypervisor, and even firmware.

Trusted Execution Environments definition
CharacteristicDescription
Memory EncryptionAll data in the TEE’s memory is encrypted by the hardware. Even physical DRAM access reveals only ciphertext.
IsolationThe TEE is isolated from other processes, VMs, and the host OS. Hardware enforces this boundary.
Remote AttestationThe TEE can prove its identity and integrity to remote parties cryptographically.
Data IntegrityThe hardware detects and prevents tampering with TEE memory.

Types of TEEs

Types of TEEs — VM-based and Process-based

VM-Based TEEs encrypt memory along a traditional VM boundary. The hypervisor cannot read VM memory.

Examples: AMD SEV-SNP, Intel TDX, IBM Secure Execution, IBM PEF

Process-Based TEEs split an app into trusted and untrusted components. Only the sensitive part runs in encrypted memory.

Example: Intel SGX

TCB Reduction with Confidential Computing

Confidential Computing dramatically reduces the TCB. The hypervisor and host OS move out of the TCB. You no longer need to trust the cloud provider’s software stack.

TCB reduction with Confidential Computing

The next section shows how each TEE vendor — AMD SEV-SNP, Intel TDX, and Intel SGX, implements these concepts in practice, and how choices like vTPM placement affect what remains in the TCB.