Technology
SEV-ES
AMD SEV-ES protects virtual machine privacy by encrypting CPU register states during hypervisor transitions.
SEV-ES extends the AMD EPYC (Zen 2 and newer) security suite by encrypting the guest register state during a VMEXIT. While original SEV focuses on memory encryption, SEV-ES secures the VMCB (Virtual Machine Control Block) to prevent the hypervisor from viewing or modifying guest data during context switches. The hardware uses a dedicated AES-128 engine managed by the AMD Secure Processor (ASP) to handle these transitions automatically. This setup effectively blocks a compromised host from scraping sensitive info (like cryptographic keys or memory addresses) directly from the processor registers.
Related technologies
Recent Talks & Demos
Showing 1-3 of 3