Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
Hardware Root of Trust AMD SEV-SNP & Intel TDX Remote Attestation Verification Zero Untrusted Hypervisor Trust

Confidential Computing, AMD SEV-SNP & Intel SGX/TDX Enclaves Studio

An architectural deep-dive, binary attestation quote dissector, and production code synthesizer for hardware-enforced Confidential Computing. Inspect AES-128/256 memory encryption and RMP page validation, simulate remote attestation verification against AMD KDS and Intel PCK root CAs, audit PCR/MR measurement registers, and synthesize production Go and Rust verifiers.

AES-XTS 256
Memory Cipher Engine
Valid VCEK Chain
Hardware Attestation
SHA-384 Digest
Launch Measurement
Bound Nonce
REPORT_DATA Binding

Binary Attestation Quote & Measurement Inspector

Parse, dissect, and cryptographically validate real-world hardware attestation reports. Audit measurement registers (LAUNCH_DIGEST / MRTD) and verify the 64-byte REPORT_DATA anti-replay challenge.

Cryptographic build hash from reproducible CI/CD pipeline
64-byte nonce derived from client TLS ephemeral public key
Awaiting report data...

Hardware Memory Controller & Reverse Map Table (RMP)

How modern TEE silicon intercepts memory reads/writes between the untrusted host hypervisor and the encrypted guest enclave.

Untrusted Host Space

Ring 0 Hypervisor

Controls physical host hardware, physical page allocations, and host virtual address mappings (HVA).

Read Enclave RAM: Ciphertext Only (AES-256)
Write / Bit-Flip: Hardware RMP Page Fault (#GP)
Remap GPA: RMP Collision Violation

Hardware Encrypted Enclave

Guest VM / Trust Domain

Executes inside secure perimeter with on-die AES-XTS engine decrypting cache lines transparently to the CPU core.

Core L1/L2/L3 Cache: Plaintext (Hardware Tagged)
DRAM Memory Bus: Encrypted via Ephemeral Key
Integrity State: RMP Validated (Bit 0 = 1)

The Reverse Map Table (RMP) Entry Anatomy (16 Bytes per 4KB Page)

Bit Field Width Field Name Architectural Enforcement
Bit 0 1 bit Assigned Specifies whether the physical page belongs to the hypervisor (0) or a confidential guest (1).
Bits 1..9 9 bits ASID Address Space ID of the specific confidential VM owning this physical memory frame.
Bit 10 1 bit Immutable Prevents the hypervisor from writing or reassigning the page while guest holds ownership.
Bits 12..51 40 bits GPA (Guest Physical Addr) Enforces 1:1 mapping between GPA and SPA, preventing hypervisor memory splicing attacks.
Bit 52 1 bit Validated Set by guest via PVALIDATE instruction. Access before validation causes #VC exception.

Hardware Root-of-Trust PKI Architecture

How attestation quotes trace mathematical authenticity back to semiconductor fabrication root keys:

TEE Platform Root Authority (ARK / Root CA) Intermediate Authority (ASK / TCB CA) Leaf Endorsement Key (VCEK / PCK) Public Key Distribution Service
AMD SEV-SNP AMD Root Key (ARK)
Self-Signed RSA 4096
AMD SEV Signing Key (ASK)
RSA 4096 Intermediate
Versioned Chip Endorsement Key (VCEK)
ECDSA P-384
AMD KDS (Key Distribution Service): kdsintf.amd.com/vcek/v1/{product}/{chip_id}
Intel TDX / SGX Intel SGX Root CA
Self-Signed ECDSA P-384
Intel SGX TCB Signing CA
ECDSA P-256 / P-384
Provisioning Certification Key (PCK)
ECDSA P-256
Intel PCS (Provisioning Certification Service) / Local PCCS Caching Service
AWS Nitro Enclaves Amazon Root CA 1
Standard Web PKI Root
AWS Nitro Attestation Intermediate
AWS Private CA
Enclave Session Certificate
ECDSA P-384
Embedded directly within CBOR/COSE attestation document bundle

Confidential Computing Matrix: AMD SEV-SNP vs Intel TDX vs SGX vs Nitro

A rigorous engineering comparison of the four predominant hardware enclave architectures:

Feature / Dimension AMD SEV-SNP Intel TDX Intel SGX AWS Nitro Enclaves
Isolation Boundary Full Virtual Machine Full Virtual Machine (TD) Individual Process / Enclave Isolated VM (No network/disk)
Hardware Memory Encryption AES-128 / AES-256 XTS AES-128 / AES-256 XTS AES-128 (MEE / MKTME) Hypervisor Isolated (No Silicon Enc)
Memory Limit per Enclave Full Host RAM (Terabytes) Full Host RAM (Terabytes) Limited EPC (128MB – 512MB) Dedicated slice of EC2 RAM
Code Modification Needed? Zero (Unmodified Linux) Zero (Unmodified Linux) High (SDK or Gramine LibOS) Moderate (vsock communication)
Memory Replay / Remap Protection Hardware RMP (Reverse Map Table) Secure EPT + TDX Module EPCM (Enclave Page Cache Map) Hypervisor Enforced
Primary Cloud Availability Azure (DCasv5), GCP (N2D), AWS (m6a) Azure (DCesv5), GCP (C3), Alibaba Azure (DCsv2/v3), IBM Cloud AWS EC2 Only (Nitro-supported instances)

Production Implementation Blueprints

Syntax-validated, battle-tested implementations for remote attestation validation and enclave communication.

// Select a blueprint above
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement