Mechanism · TEE remote attestation for AI workloads

Technical detail

On this page

NVIDIA describes the GPU attestation chain as follows. An on-die root of trust verifies the identity key fused into the GPU and permits only NVIDIA-signed firmware at boot. The driver then opens an SPDM session with the GPU, using a Diffie-Hellman exchange to set up a session key 1. The GPU presents a device identity certificate signed with a device-unique ECC-384 key, which chains to the NVIDIA certificate authority. It then returns a signed set of measurements 2.

Other details of NVIDIA's design:

  • Traffic between the confidential VM and the GPU is protected with AES-GCM through encrypted bounce buffers. NVIDIA states that in future, hosts with TDISP/IDE-compatible CPUs and Blackwell B100/B200 GPUs can use inline encryption instead 1.
  • Hopper's protected-PCIe mode passes all eight GPUs of an HGX node to one confidential VM, but NVLink traffic between them stays unencrypted. Blackwell also encrypts NVLink, for up to eight GPUs per confidential VM 1.
  • Performance counters are disabled in full CC-On mode. They are available only in a CC-DevTools development mode 1.
  • At launch, NVIDIA reported that H100 compute and HBM bandwidth were at par with non-confidential mode. CPU–GPU transfers were limited to roughly 4 GB/s by CPU encryption 2.

Three systems bind application data to a report:

  • PAL*M sets the Intel TDX REPORTDATA field to the concatenation of the operation, a verifier challenge and hashes of the inputs and outputs. It models the protocol in the Tamarin prover 9.
  • Attestable Audits publishes attestations that bind the model hash, the audit code and data, and the result to a transparency log 8.
  • Tinfoil puts a dm-verity root hash of the weights on the measured kernel command line 10.

Search

Full search page