Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Glossary

CNCF Confidential Containers

Acronyms and key terms used throughout this book, listed alphabetically.

Acronym / TermExpansionBrief Definition
AAAttestation AgentComponent inside the CoCo CVM that handles the attestation process on behalf of the workload
ARKAMD Root KeyTop-level key in AMD’s certificate chain, used to sign the AMD SEV Key (ASK)
ASAttestation ServiceTrustee component that verifies attestation evidence against reference values
ASKAMD SEV KeyIntermediate key in AMD’s certificate chain, signed by the ARK and used to sign the VCEK
BYOMBring Your Own MachineDeployment model where the user supplies their own (remote) machine as the CVM host
CAACloud API AdaptorCoCo component that provisions peer-pod CVMs via cloud provider APIs
CCAConfidential Compute ArchitectureArm’s VM-based TEE architecture (Armv9), introducing Realms managed by the Realm Management Monitor
CDHConfidential Data HubCoCo component inside the CVM that acts as a proxy for secret retrieval
CNIContainer Network InterfaceStandard interface for Kubernetes pod networking plugins (e.g. Flannel, Calico)
CRIContainer Runtime InterfaceKubernetes API that kubelet uses to talk to container runtimes such as containerd and CRI-O
CoCoConfidential ContainersCNCF project for running Kubernetes pods inside CVMs using Kata Containers
CoVEConfidential VM ExtensionsRISC-V specification for VM-based TEEs
CVMConfidential Virtual MachineA virtual machine running inside a TEE, with hardware-encrypted memory
CDIContainer Device InterfaceStandard for exposing hardware devices to containers
DICEDevice Identifier Composition EngineHardware RoT standard for deriving layered identity keys at each boot stage
DMADirect Memory AccessHardware mechanism allowing devices to access system memory without CPU involvement; a source of side-channel risk
FHEFully Homomorphic EncryptionCryptographic technique for computing directly on encrypted data without decrypting it
GHCRGitHub Container RegistryGitHub’s OCI-compatible container and artifact registry (ghcr.io)
GRUBGrand Unified BootloaderCommon Linux bootloader responsible for loading the kernel
IETFInternet Engineering Task ForceStandards body that publishes internet and security protocol specifications (RFCs)
initdataInitialization DataMechanism for passing measured configuration (KBS URL, agent policy) into a CoCo CVM at boot; its hash is bound into the attestation evidence
ITAIntel Trust AuthorityIntel’s hosted attestation verification service for TDX and SGX
KBSKey Broker ServiceTrustee component that releases secrets (keys, certificates) only after successful attestation
KDSKey Distribution ServiceAMD’s public service for distributing VCEK certificates by chip ID and TCB version
KVMKernel-based Virtual MachineLinux kernel hypervisor module used by QEMU to run VMs
LLCLast-Level CacheThe largest shared CPU cache (typically L3); a surface for cache side-channel attacks
LUKSLinux Unified Key SetupStandard disk encryption specification on Linux, used to protect ephemeral CVM storage
MAAMicrosoft Azure AttestationAzure’s attestation verification service for SEV-SNP, TDX, and SGX
MPCSecure Multi-Party ComputationCryptographic protocols that let multiple parties jointly compute a function without revealing their private inputs
MRTDMeasurement Register for Trust DomainIntel TDX build-time measurement register covering the initial TD contents (e.g. the TDVF firmware)
NRASNVIDIA Remote Attestation ServiceNVIDIA’s hosted service for verifying GPU attestation evidence
NSGNetwork Security GroupCloud firewall construct (e.g. Azure) controlling inbound/outbound traffic to VMs
Nydus—containerd snapshotter (nydus-snapshotter) used by CoCo to delegate container image pulling to the guest CVM
OCIOpen Container InitiativeStandards body defining container image and runtime specifications
OPAOpen Policy AgentGeneral-purpose policy engine; used in CoCo to enforce initdata policies
ORASOCI Registry As StorageTool for pushing and pulling arbitrary artifacts (binaries, configs) from OCI registries
OVMFOpen Virtual Machine FirmwareOpen-source UEFI firmware used as the guest firmware in QEMU/KVM VMs
PCEProvisioning Certification EnclaveIntel SGX enclave that certifies the Quoting Enclave’s attestation key
PCKProvisioning Certification KeyIntel platform-specific key used to sign TDX/SGX quote collateral
PCCSProvisioning Certificate Caching ServiceLocal caching proxy for Intel PCS certificates, reducing latency in production deployments
PCRPlatform Configuration RegisterTamper-evident register inside a TPM that accumulates boot measurements via hash extension
PCSProvisioning Certification ServiceIntel’s public service for distributing PCK certificates for TDX and SGX platforms
Peer pods—CoCo deployment model where the pod CVM runs on a remote hypervisor (provisioned via cloud APIs by CAA) instead of nested on the worker node
PSPPlatform Security ProcessorAlternative name for AMD’s dedicated security processor (also called ASP)
QEQuoting EnclaveIntel SGX/TDX enclave that signs attestation quotes using a platform attestation key
QEMUQuick EMUlatorOpen-source machine emulator and virtualizer; used with KVM to run CVMs
RAGRetrieval-Augmented GenerationLLM technique that grounds responses by retrieving relevant documents at query time
RATSRemote ATtestation procedureSIETF framework (RFC 9334) defining roles and flows for remote attestation
RFCRequest for CommentsIETF standards document; RFC 9334 defines the RATS attestation framework
RoTRoot of TrustFoundational hardware component (e.g. AMD SP, TPM) whose integrity is assumed and not derived
RTMRRuntime Extendable Measurement RegisterIntel TDX equivalent of TPM PCRs; accumulates measurements during and after boot
RVPSReference Value Provider ServiceTrustee component that stores and serves “golden” reference measurements for comparison
SEAMSecure Arbitration ModeNew Intel CPU operation mode introduced by TDX to host and manage Trust Domains
SEVSecure Encrypted VirtualizationAMD technology for encrypting VM memory to protect it from the hypervisor
SEV-SNPSecure Encrypted Virtualization — Secure Nested PagingAMD’s extension to SEV adding integrity protection and a hardware attestation report
SFTPSecure File Transfer ProtocolSSH-based protocol for secure file transfer between hosts
SGXSoftware Guard ExtensionsIntel’s process-based TEE technology for running isolated enclaves within an application
SNPSecure Nested PagingThe page-integrity component of AMD SEV-SNP that prevents hypervisor memory tampering
SPIFFESecure Production Identity Framework for EveryoneCNCF standard for workload identity in distributed systems
SPIRESPIFFE Runtime EnvironmentReference implementation of the SPIFFE standard
SVSMSecure VM Service ModuleSoftware component that runs inside a TEE and provides hypervisor-like services (e.g. vTPM) without trusting the hypervisor
TCBTrusted Computing BaseThe minimal set of hardware, firmware, and software components that must be trusted for security to hold
TCGTrusted Computing GroupIndustry consortium that defines TPM and related trusted computing standards
TDISPTEE Device Interface Security ProtocolPCIe standard for attesting a device and admitting it into a VM-based TEE for direct DMA (trusted I/O)
TDVFTDX Virtual FirmwareOVMF-based guest firmware for Intel TDX Trust Domains
TDXTrust Domain ExtensionsIntel’s VM-based TEE technology that protects entire VMs (Trust Domains) from the hypervisor
TEETrusted Execution EnvironmentHardware-enforced isolated region of a processor protecting code and data from privileged software
TPMTrusted Platform ModuleHardware chip (or firmware equivalent) for secure key storage, measurement, and attestation
UEFIUnified Extensible Firmware InterfaceModern PC firmware standard that replaced BIOS; provides Secure Boot capabilities
UKIUnified Kernel ImageA single EFI binary bundling the kernel, initramfs, and kernel command line for measured boot
VCEKVersioned Chip Endorsement KeyAMD per-chip, per-firmware key used to sign SNP attestation reports
vTPMVirtual Trusted Platform ModuleSoftware emulation of a TPM 2.0 chip, provided to a guest VM by the hypervisor or SVSM