AMD SEV-SNP: memory encryption, integrity, and the SEV progression
SEV, SEV-ES, and SEV-SNP are not interchangeable. SNP adds the page-ownership and integrity protections buyers usually mean when discussing current AMD confidential VMs.

Direct answer
AMD SEV encrypts each VM’s memory; SEV-ES also encrypts saved CPU register state; SEV-SNP adds memory-integrity and page-ownership protections designed to resist malicious-hypervisor replay, remapping, aliasing, and corruption attacks, plus runtime attestation reports bound to a chip and TCB version.SEV, SEV-ES, and SEV-SNP compared
| Generation | Added protection | Important limitation |
|---|---|---|
| SEV | Per-VM memory encryption with separate keys | The original model does not provide SNP’s strong malicious-hypervisor memory-integrity protections |
| SEV-ES | Encryption of saved CPU register state on VM exits | Register protection does not add SNP’s page-ownership and remapping controls |
| SEV-SNP | Reverse Map Table, page validation, integrity protections, and runtime attestation | Shared I/O, guest software, availability, and documented side channels remain separate concerns |
The Reverse Map Table and page-validation protocol let SNP track which guest owns a page and whether that page is in an expected state. The design aims to block software replay, corruption, aliasing, and remapping attacks by a malicious hypervisor.SNP
Runtime attestation and VCEK
A guest can request an SNP attestation report at runtime and place application-controlled data into the request for endpoint binding. The report is signed through AMD’s Versioned Chip Endorsement Key model, which binds a key to a particular chip and reported trusted computing base version. Verification still needs freshness, expected measurement, policy and version checks; a valid VCEK signature is not a universal approval.VCEKSNP
- Validate the AMD certificate chain and VCEK for the reported chip/TCB.
- Enforce a fresh challenge and application/session binding.
- Compare the launch measurement and policy with approved values.
- Check TCB versions and security advisories; reject downgrades below policy.
- Release secrets only after the relying party accepts the verifier result.
What SEV-SNP does not protect
- Denial of service by the host or infrastructure operator.
- Shared pages, device input, and other deliberately untrusted I/O paths.
- Vulnerabilities, malware, or unsafe behavior inside the guest.
- Every cache, page-fault, performance, fingerprinting, or ciphertext side channel.
- Online DRAM-bus integrity attacks in the base SNP threat model.
- Ciphertext hiding across every EPYC generation; AMD identifies it as a newer platform feature and publishes generation-specific guidance.
Customer fit and deployment questions
SEV-SNP is a strong fit for lift-and-shift confidential VMs, cloud services that need a malicious-hypervisor threat model, and AMD-hosted confidential GPU systems. It preserves a conventional guest environment, so the guest kernel and application stack remain trusted. Device assignment, migration, debugging, observability, firmware, and cloud availability vary by platform.
Frequently asked questions
What does SEV-SNP add beyond SEV-ES?
SEV-ES protects saved register state. SEV-SNP adds page ownership, validation, and integrity mechanisms intended to resist malicious-hypervisor replay, remapping, aliasing, and corruption attacks, along with runtime reports.
Does SEV-SNP protect shared I/O?
Shared pages and external device input remain untrusted interfaces unless a separate protected-I/O mechanism applies. Guest software must validate data crossing those boundaries.
Is a VCEK-signed report enough to release a key?
No. Verification should also enforce freshness, expected measurement, policy, TCB version, and application/session binding before a relying party authorizes release.
Sources
- SNP
- SEV
- VCEK
- CIPHERAMD-SB-3021: ciphertext side-channel guidanceAMD Product Security
- SNPEEKAMD-SB-3043: SNPeek assessmentAMD Product Security
Relevant GPU availability
Verified specifications, confidential-mode support, and public listings for the accelerators this post covers.
Ready to reserve capacity?
Confidential Nodes matches bare-metal confidential GPU nodes to workloads, with verified provider data behind every listing.
