Introduction
Confidential computing is a hardware-based technology that safeguards data during processing. For Arm-architecture processors, this is implemented via TrustZone technology.
Trusted execution environments (TEEs) of traditional TrustZone solutions are dedicated to terminal devices. Trusted applications (TAs) must be authenticated by terminal device vendors before running in the TEE OS, making traditional solutions unsuitable for general-purpose computing. The TEE Kit is a next-generation confidential computing technology implemented based on virtual machines (VMs). It is compatible with the existing application ecosystem and extends confidential computing from the application layer to the OS layer. This document describes the software architecture, features, specifications, and constraints of the Confidential Computing TEE Kit powered by a new Kunpeng 920 processor model, and explains how to set up the TEE Kit environment and use confidential virtual machines (cVMs).
Feature Name |
Feature Description |
Application Scenario |
|---|---|---|
Remote attestation |
Proves the trustworthiness of cVMs and confidential computing platforms to users, including:
|
Confidential cloud hosts and secure database enclaves |
Full-disk encryption (FDE) |
Encrypts the entire space across disk partitions to protect sensitive information in cVM images. |
Drive and database encryption |
Key sealing |
Generates a key inside a cVM and binds it to the cVM. The sealing key remains unchanged after the cVM restarts. |
Drive and database encryption |
Confidential device passthrough |
Switches PCIe devices into a confidential computing execution environment and passes them through to cVMs to protect data-in-transit. |
AI model protection, confidential cloud hosts, and secure database enclaves |
Confidential containers |
Protects containers from end to end by leveraging core capabilities of cVMs and replicating basic functions from the Kata/Coco community, such as encryption, decryption, signature verification, and remote attestation. |
AI model protection, serverless, and PaaS |
Secure memory encryption |
Implements transparent memory-encryption protection for TEEs based on the hardware root key. |
Prevention of near-end attacks |
SM acceleration |
Enhances SM algorithm performance and enables algorithm offload through the KAE in cVMs. |
Secure database enclaves and cryptographic computing |
DPDK-OSV network acceleration |
Attaches vhost-user devices to cVMs to enable network acceleration. |
Confidential cloud hosts |
Cloud management platforms |
Manages cVMs on the OpenStack cloud platform, enabling access to compute, storage, and network virtualization services. |
Confidential cloud hosts |
Live VM migration |
Supports cross-node live migration capabilities for cVMs in non-passthrough scenarios. |
Confidential cloud hosts |
Rapid cVM deployment and O&M |
Deploys cVMs using virtcca-deploy. |
Confidential cloud hosts |