{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:08:38Z","timestamp":1782968918087,"version":"3.54.5"},"reference-count":19,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,8,31]],"date-time":"2023-08-31T00:00:00Z","timestamp":1693440000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>Confidential computing is a security model that fits well with the public cloud. It enables customers to rent VMs while enjoying hardware-based isolation that ensures that a cloud provider cannot purposefully or accidentally see or corrupt their data. SEV-SNP was the first commercially available x86 technology to offer VM isolation for the cloud and is deployed in Microsoft Azure, AWS, and Google Cloud. As confidential computing technologies such as SEV-SNP develop, confidential computing is likely to simply become the default trust model for the cloud.<\/jats:p>","DOI":"10.1145\/3623392","type":"journal-article","created":{"date-parts":[[2023,9,7]],"date-time":"2023-09-07T23:44:26Z","timestamp":1694130266000},"page":"49-67","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Hardware VM Isolation in the Cloud"],"prefix":"10.1145","volume":"21","author":[{"given":"David","family":"Kaplan","sequence":"first","affiliation":[{"name":"AMD"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,9,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"AMD. 2020. AMD SEV-SNP: Strengthening VM isolation with integrity protection and more. AMD White Paper; https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf."},{"key":"e_1_2_1_2_1","unstructured":"AMD. 2023. AMD SEV-TIO: trusted I\/O for secure encrypted virtualization. AMD White Paper; https:\/\/www.amd.com\/content\/dam\/amd\/en\/documents\/developer\/sev-tio-whitepaper.pdf."},{"key":"e_1_2_1_3_1","unstructured":"AMD. 2023. SEV-ES guest hypervisor communication block standardization; https:\/\/www.amd.com\/system\/files\/TechDocs\/56421-guest-hypervisor-communication-block-standardization.pdf."},{"key":"e_1_2_1_4_1","unstructured":"AMD. 2022. SEV secure nested paging firmware ABI specification; https:\/\/www.amd.com\/system\/files\/TechDocs\/56860.pdf."},{"key":"e_1_2_1_5_1","unstructured":"AMD. 2023. Versioned chip endorsement key (VCEK) certificate and KDS interface specification; https:\/\/www.amd.com\/system\/files\/TechDocs\/57230.pdf."},{"key":"e_1_2_1_6_1","volume-title":"Amazon EC2 now supports AMD SEV-SNP","year":"2023","unstructured":"AWS. 2023. Amazon EC2 now supports AMD SEV-SNP; https:\/\/aws.amazon.com\/about-aws\/whats-new\/2023\/04\/amazon-ec2-amd-sev-snp\/."},{"key":"e_1_2_1_7_1","unstructured":"Cai R. 2022. Azure confidential VMs using SEV-SNP (DCasv5\/ECasv5) are now generally available. Microsoft Azure Confidential Computing Blog; https:\/\/techcommunity.microsoft.com\/t5\/azure-confidential-computing\/azure-confidential-vms-using-sev-snp-dcasv5-ecasv5-are-now\/ba-p\/3573747."},{"key":"e_1_2_1_8_1","unstructured":"COCONUT Secure VM Service Module; https:\/\/github.com\/coconut-svsm\/svsm."},{"key":"e_1_2_1_9_1","volume-title":"Microsoft Azure confidential computing powered by 3rd gen EPYC CPUs. AMD","author":"Comp L.","unstructured":"Comp, L. 2021. Microsoft Azure confidential computing powered by 3rd gen EPYC CPUs. AMD; https:\/\/community.amd.com\/t5\/epyc-processors\/microsoft-azure-confidential-computing-powered-by-3rd-gen-epyc\/ba-p\/497796."},{"key":"e_1_2_1_10_1","unstructured":"DMTF. 2023. All published versions of DSP0274; https:\/\/www.dmtf.org\/dsp\/DSP0274."},{"key":"e_1_2_1_11_1","unstructured":"Harriman D. 2022. Integrity and Data Encryption and IO security updates. PCI-SIG; https:\/\/pcisig.com\/blog\/integrity-and-data-encryption-ide-and-io-security-updates."},{"key":"e_1_2_1_12_1","unstructured":"Kaplan D. Powell J. Woller T. 2021. AMD memory encryption. AMD White Paper; https:\/\/www.amd.com\/system\/files\/TechDocs\/memory-encryption-white-paper.pdf."},{"key":"e_1_2_1_13_1","unstructured":"Linux SVSM; https:\/\/github.com\/AMDESE\/linux-svsm."},{"key":"e_1_2_1_14_1","unstructured":"Perez-Vargas C. 2023. Confidential VMs on Azure. Microsoft Windows OS Platform Blog; https:\/\/techcommunity.microsoft.com\/t5\/windows-os-platform-blog\/confidential-vms-on-azure\/ba-p\/3836282."},{"key":"e_1_2_1_15_1","unstructured":"PCI-SIG. 2022. TEE Device Interface Security Protocol; https:\/\/pcisig.com\/tee-device-interface-security-protocol-tdisp."},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Russinovich M. et al. 2021. Toward confidential cloud computing. Communications of the ACM 64 (6) 54?61; https:\/\/dl.acm.org\/doi\/10.1145\/3453930.","DOI":"10.1145\/3453930"},{"key":"e_1_2_1_17_1","unstructured":"See https:\/\/www.spec.org for more information about SPEC\u00b0 benchmarks."},{"key":"e_1_2_1_18_1","unstructured":"VirTEE; https:\/\/github.com\/virtee\/."},{"key":"e_1_2_1_19_1","unstructured":"Young J. 2023. Oh SNP! VMs get even more confidential. Google Cloud Blog; https:\/\/cloud.google.com\/blog\/products\/identity-security\/rsa-snp-vm-more-confidential."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623392","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3623392","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:26Z","timestamp":1750178186000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3623392"}},"subtitle":["Enabling confidential computing with AMD SEV-SNP technology"],"short-title":[],"issued":{"date-parts":[[2023,8,31]]},"references-count":19,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3623392"],"URL":"https:\/\/doi.org\/10.1145\/3623392","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,31]]},"assertion":[{"value":"2023-09-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}