---
title: "Confidential Computing with AMD SEV-SNP Memory Encryption | Zero-Trust Architecture Canon"
description: "Zero-Trust hardware enclave architecture utilizing AMD SEV-SNP and Intel TDX, encrypting virtual machine memory in-use to protect cryptographic keys and proprietary models from hypervisor and cloud provider access."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/confidential-computing-sev-snp"
locale: "en"
---

# Confidential Computing with AMD SEV-SNP Memory Encryption (`zt-arch-13`)

> **Pillar**: DATA | **Archetype**: DATA_ENVELOPE_ENCRYPTION
> **Blocked MITRE ATT&CK Techniques**: T1005, T1055, T1530, T1003

## Architecture Summary

Zero-Trust hardware enclave architecture utilizing AMD SEV-SNP and Intel TDX, encrypting virtual machine memory in-use to protect cryptographic keys and proprietary models from hypervisor and cloud provider access.

## Adversary Model

Rogue cloud provider administrator or compromised hypervisor process inspects RAM memory to extract TLS private keys or proprietary LLM weights.

## NIST SP 800-207 Core Tenets

- All data sources and computing services are considered resources.
- No asset is inherently trusted.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: Memory encryption enabled at hypervisor level without cryptographic attestation.
- **Authentication Enforcement**: Standard cloud instance IAM credentials.
- **Network Isolation**: Encrypted VPC subnet.

### ADVANCED Maturity Target

- **Implementation Scope**: Confidential VMs (GCP Confidential VM / AWS C6a) with remote hardware attestation.
- **Authentication Enforcement**: Key release policy requiring valid AMD SEV-SNP hardware attestation report before decryption.
- **Network Isolation**: Isolated enclave network with zero direct internet access.

### OPTIMAL Maturity Target

- **Implementation Scope**: Entire AI training and financial ledger processing running in confidential container enclaves.
- **Authentication Enforcement**: Zero-knowledge hardware attestation with multi-party verifiable computation.
- **Network Isolation**: Private memory encryption keys regenerated per container lifecycle.

## Terraform HCL Manifest

```hcl
resource "google_compute_instance" "confidential_vm" {
  name         = "tinycto-secure-ledger"
  machine_type = "n2d-standard-8"
  zone         = "us-central1-a"

  confidential_instance_config {
    enable_confidential_compute = true
  }

  boot_disk {
    initialize_params {
      image = "ubuntu-os-cloud/ubuntu-2204-lts"
    }
    kms_key_self_link = var.kms_key_link
  }
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: confidential-worker
spec:
  nodeSelector:
    cloud.google.com/confidential-compute: "true"
  containers:
  - name: secure-processor
    image: ghcr.io/tiny-cto/ledger:latest
    resources:
      limits:
        memory: "16Gi"
        cpu: "4"
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Confidential Computing with AMD SEV-SNP Memory Encryption | Zero-Trust Architecture Canon",
  "description": "Zero-Trust hardware enclave architecture utilizing AMD SEV-SNP and Intel TDX, encrypting virtual machine memory in-use to protect cryptographic keys and proprietary models from hypervisor and cloud provider access.",
  "url": "https://tinycto.tv/zero-trust/architectures/confidential-computing-sev-snp"
}
```
