Pith. sign in

REVIEW 1 cited by

Intel TDX Demystified: A Top-Down Approach

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2303.15540 v1 pith:M6YRU5D3 submitted 2023-03-27 cs.CR cs.OS

classification cs.CRcs.OS
keywords intelsecurityaimsapproachcomputingconfidentialdatadomain
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Intel Trust Domain Extensions (TDX) is a new architectural extension in the 4th Generation Intel Xeon Scalable Processor that supports confidential computing. TDX allows the deployment of virtual machines in the Secure-Arbitration Mode (SEAM) with encrypted CPU state and memory, integrity protection, and remote attestation. TDX aims to enforce hardware-assisted isolation for virtual machines and minimize the attack surface exposed to host platforms, which are considered to be untrustworthy or adversarial in the confidential computing's new threat model. TDX can be leveraged by regulated industries or sensitive data holders to outsource their computations and data with end-to-end protection in public cloud infrastructure. This paper aims to provide a comprehensive understanding of TDX to potential adopters, domain experts, and security researchers looking to leverage the technology for their own purposes. We adopt a top-down approach, starting with high-level security principles and moving to low-level technical details of TDX. Our analysis is based on publicly available documentation and source code, offering insights from security researchers outside of Intel.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Enabling Low-Cost Secure Computing on Untrusted In-Memory Architectures

    cs.CR 2025-01 conditional novelty 5.0 of 10

    Secure MPC-based offloading of linear and nonlinear machine-learning computations to real UPMEM PIM hardware achieves up to a 14.66x speedup over a secure CPU baseline.

Pith tools