AMD SEV-SNP: memory encryption, integrity, and the SEV progression

SEV, SEV-ES, and SEV-SNP are not interchangeable. SNP adds the page-ownership and integrity protections buyers usually mean when discussing current AMD confidential VMs.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

AMD SEV encrypts each VM’s memory; SEV-ES also encrypts saved CPU register state; SEV-SNP adds memory-integrity and page-ownership protections designed to resist malicious-hypervisor replay, remapping, aliasing, and corruption attacks, plus runtime attestation reports bound to a chip and TCB version.

SEV, SEV-ES, and SEV-SNP compared

GenerationAdded protectionImportant limitation
SEVPer-VM memory encryption with separate keysThe original model does not provide SNP’s strong malicious-hypervisor memory-integrity protections
SEV-ESEncryption of saved CPU register state on VM exitsRegister protection does not add SNP’s page-ownership and remapping controls
SEV-SNPReverse Map Table, page validation, integrity protections, and runtime attestationShared I/O, guest software, availability, and documented side channels remain separate concerns
SNPSEV

The Reverse Map Table and page-validation protocol let SNP track which guest owns a page and whether that page is in an expected state. The design aims to block software replay, corruption, aliasing, and remapping attacks by a malicious hypervisor.SNP

Runtime attestation and VCEK

A guest can request an SNP attestation report at runtime and place application-controlled data into the request for endpoint binding. The report is signed through AMD’s Versioned Chip Endorsement Key model, which binds a key to a particular chip and reported trusted computing base version. Verification still needs freshness, expected measurement, policy and version checks; a valid VCEK signature is not a universal approval.VCEKSNP

  • Validate the AMD certificate chain and VCEK for the reported chip/TCB.
  • Enforce a fresh challenge and application/session binding.
  • Compare the launch measurement and policy with approved values.
  • Check TCB versions and security advisories; reject downgrades below policy.
  • Release secrets only after the relying party accepts the verifier result.

What SEV-SNP does not protect

  • Denial of service by the host or infrastructure operator.
  • Shared pages, device input, and other deliberately untrusted I/O paths.
  • Vulnerabilities, malware, or unsafe behavior inside the guest.
  • Every cache, page-fault, performance, fingerprinting, or ciphertext side channel.
  • Online DRAM-bus integrity attacks in the base SNP threat model.
  • Ciphertext hiding across every EPYC generation; AMD identifies it as a newer platform feature and publishes generation-specific guidance.
SNPCIPHERSNPEEK

Customer fit and deployment questions

SEV-SNP is a strong fit for lift-and-shift confidential VMs, cloud services that need a malicious-hypervisor threat model, and AMD-hosted confidential GPU systems. It preserves a conventional guest environment, so the guest kernel and application stack remain trusted. Device assignment, migration, debugging, observability, firmware, and cloud availability vary by platform.

Frequently asked questions

What does SEV-SNP add beyond SEV-ES?

SEV-ES protects saved register state. SEV-SNP adds page ownership, validation, and integrity mechanisms intended to resist malicious-hypervisor replay, remapping, aliasing, and corruption attacks, along with runtime reports.

Does SEV-SNP protect shared I/O?

Shared pages and external device input remain untrusted interfaces unless a separate protected-I/O mechanism applies. Guest software must validate data crossing those boundaries.

Is a VCEK-signed report enough to release a key?

No. Verification should also enforce freshness, expected measurement, policy, TCB version, and application/session binding before a relying party authorizes release.

Sources

  1. SNP
  2. SEV
  3. VCEK
  4. CIPHER
  5. SNPEEK
    AMD-SB-3043: SNPeek assessmentAMD Product Security

Relevant GPU availability

Verified specifications, confidential-mode support, and public listings for the accelerators this post covers.

Ready to reserve capacity?

Confidential Nodes matches bare-metal confidential GPU nodes to workloads, with verified provider data behind every listing.