Rate This Document
Findability
Accuracy
Completeness
Readability

Change Description

Kunpeng BoostKit 24.0.0 Confidential Computing mainly involves updating virtCCA-related features.

Table 1 New features of BoostKit-virtCCA_1.2.0

Feature

Change Description

Remote attestation of container images for confidential containers

  • Remote attestation can be enabled in confidential containers.
  • Container images support the Integrity Measurement Architecture (IMA).

Encryption of secure memory

Secure memory in the TEE can be encrypted and decrypted, and the virtCCA confidential VM memory is protected by memory encryption.

PCIe device passthrough

Confidential VMs can be directly connected to PCIe devices, including NICs, drives, and GPUs. The compatible devices include SP680 and HP382 NICs and ES3000 V6 drives.

SM algorithms for hardware acceleration

Confidential VMs support hardware acceleration using SM2, SM3, and SM4 algorithms.