AMD SEV

E653461

AMD SEV (Secure Encrypted Virtualization) is a hardware-based security technology from AMD that encrypts virtual machine memory to protect it from access by other VMs, the hypervisor, or physical attackers.

All labels observed (5)

Label Occurrences
AMD SEV canonical 2
AMD APM extensions for SEV 1
AMD SEV-ES 1

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf hardware-based security technology
memory encryption technology
abbreviationOf AMD Secure Encrypted Virtualization
linked to: AMD SEV
announcedAt AMD Developer Summit 2016
compatibleWith KVM
Linux kernel virtualization
QEMU
designedTo enable secure multi-tenant environments
reduce trust in hypervisor
developer Advanced Micro Devices
documentation AMD64 Architecture Programmer’s Manual Volume 2
encryptionAlgorithm AES
encryptionType full VM memory encryption
hasFeature encryption keys not visible to hypervisor
hardware-enforced isolation between VMs
inline memory encryption and decryption
transparent memory encryption for VMs
hasVersion AMD SEV-ES
linked to: AMD SEV

AMD SEV-SNP
linked to: AMD SEV
implementedBy AMD Secure Processor
introducedBy AMD Zen microarchitecture
linked to: Zen 3
introducedIn 2016
keyManagement per-VM encryption keys
keyStorage on-chip secure processor
manufacturer Advanced Micro Devices
partOf AMD Infinity Guard
protects virtual machine memory
protectsFrom cold boot attacks
hypervisor access
memory bus snooping
other virtual machines
physical attackers
relatedTo AMD SME
Intel SGX
Intel TDX
requires firmware support
hypervisor support
runsOn AMD EPYC processors
linked to: AMD EPYC

AMD x86-64 processors
linked to: AMD64 architecture
securityGoal confidentiality of VM memory
mitigation of privileged software attacks
standardizedIn AMD APM extensions for SEV
linked to: AMD SEV
supports confidential computing
targetDomain cloud computing
virtualization
targetUser cloud service providers
enterprise virtualization users
uses on-die memory encryption engine

How these facts were elicited

Referenced by (6)

Full triples — surface form annotated when it differs from this entity's canonical label.

Intel SGX relatedConcept AMD SEV
AMD SEV abbreviationOf AMD Secure Encrypted Virtualization
linked to: AMD SEV
AMD SEV hasVersion AMD SEV-ES
linked to: AMD SEV
AMD SEV hasVersion AMD SEV-SNP
linked to: AMD SEV
AMD SEV standardizedIn AMD APM extensions for SEV
linked to: AMD SEV