我要评分
获取效率
正确性
完整性
易理解

Change Description

Kunpeng BoostKit 25.2.RC2 Confidential Computing mainly introduces updates to virtCCA-related features.

Table 1 New features of BoostKit-virtCCA_1.5.0

Feature

Description

Batch service capability and TEE license configuration

  • Confidential computing can be deployed in batches using the Computing ToolKit.
  • XML files are added to the TMM firmware and iTrustee firmware packages.
  • Confidential computing supports configurable TEE licenses.

Hot swap of cVM devices (virtual NICs and drives) for device scaling

  • Hot-plugging or hot-unplugging a paravirtualized disk during cVM runtime does not affect the normal functioning of the VM and the device.
  • Hot-plugging or hot-unplugging a paravirtualized NIC during cVM runtime does not affect the normal functioning of the VM and the device.

PCIPC-Based VF Passthrough for RoCE to VMs

PCIPC supports RoCE VF passthrough to VMs.

Enhanced confidential container capability and serviceability

  • The kernel of Kata confidential containers can be simplified and optimized.
  • The tool for generating the confidential computing base value now supports confidential containers.
  • One-click deployment scripts are available for confidential containers.
  • Kubernetes supports device passthrough to confidential containers.

Kunpeng Cryptographic-computing Acceleration Library (KCAL)

  • It supports SM3 and SM4 random number derivation and hash functions.
  • KCAL operators support confidential computing environment verification.
  • It adapts to the middleware of privacy computing platforms.