NVIDIA Confidential Computing: extending a CPU TEE to the GPU
NVIDIA Confidential Computing is an attached-device trust architecture. The GPU does not replace the CPU confidential VM; the two are verified and operated as one boundary.

Direct answer
NVIDIA Confidential Computing extends a supported CPU confidential VM into a supported GPU using secure boot, an on-die root of trust, GPU attestation, a protected session with the driver, hardware access controls, and protected CPU–GPU data movement. Production confidentiality requires CC-On plus successful policy-based attestation and key release.The combined CPU-and-GPU boundary
The CPU confidential VM provides the protected guest and driver environment. The GPU establishes measured boot and its own attested device state. A protected session binds the GPU to the driver inside the CVM, and hardware controls constrain access. On Hopper, encrypted and authenticated bounce buffers carry code, data, commands, and metadata across host-visible shared memory.WHITEPAPERDEPLOY
| Component | Security role | Buyer evidence |
|---|---|---|
| CPU TEE | Protects guest memory/state from the host and runs the trusted driver/workload | TDX or SEV-SNP evidence and accepted measurement/policy |
| GPU root of trust and firmware | Measures boot and produces device claims | Device certificate, firmware/security version, RIM comparison |
| Protected session/device path | Binds the GPU to the intended CVM and protects transfers | Supported platform topology and deployment configuration |
| Verifier | Appraises CPU/GPU evidence, collateral, freshness, measurements, and mode | Policy, decision record, NRAS or trusted local-verification design |
| Relying service | Releases model/data/session keys only to an accepted environment | Fail-closed key broker and endpoint binding test |
CC-Off, CC-On, and CC-DevTools are different states
| Mode | Purpose | Publication-safe interpretation |
|---|---|---|
| CC-Off | Ordinary operation | Confidential-computing protections are not active |
| CC-On | Production confidential mode | Intended secure state; still verify fresh evidence and policy before release |
| CC-DevTools | Profiling and development access | Exposes counters/debug-related capability; do not describe as equivalent to CC-On |
GPU attestation and reference integrity measurements
NVIDIA’s attestation stack can evaluate GPU evidence and signed reference integrity measurements. NVIDIA Remote Attestation Service can perform remote appraisal, while local verification needs its own trusted execution context. NVIDIA warns that verification running on an elevated untrusted host can be subverted. The workload owner must decide which verifier to trust and how its result reaches the key broker.ATTESTRIMNRAS
What it protects—and the caveats
- Extends protection for code, data, and commands from the CPU confidential VM into supported GPU execution.
- Protects CPU–GPU transfer through the documented confidential path; transfer-heavy work can pay encryption and bounce-buffer overhead.
- Hopper computes on plaintext inside the protected GPU region. Its on-package HBM is not encrypted; NVIDIA’s threat model treats it as protected from ordinary physical interposers.
- Does not prevent denial of service or every sophisticated physical and side-channel attack.
- Does not make unsafe guest code, model behavior, tool access, logs, or outputs secure.
- Does not turn an unsupported SKU, topology, driver, firmware, or provider instance into a production confidential platform.
Operational requirements
- Use NVIDIA’s live deployment compatibility matrix for the exact Hopper or Blackwell model, CPU TEE, system, VBIOS, firmware, driver, CUDA, hypervisor, and topology.
- Collect evidence for every device admitted to a multi-GPU or multi-node job and bind membership to the protected workload.
- Verify device certificate revocation, current reference measurements, firmware/security versions, CC-On state, freshness, and endpoint binding.
- Gate model, dataset, prompt/session, and tool keys on the accepted combined result.
- Test upgrades, resets, replacement GPUs, autoscaling, evidence-service outages, and development-mode rejection.
- Benchmark compute, transfers, collective communication, loading, startup, and operational recovery under the actual secure configuration.
Frequently asked questions
Can an NVIDIA GPU be confidential without a CPU TEE?
NVIDIA’s documented architecture extends a supported CPU confidential VM to the GPU. The protected driver/workload and device must be verified as one system.
Is CC-DevTools a production confidential mode?
No. It enables profiling and debugging-related capability with a security trade-off. Production requirements should specify CC-On and enforce that claim in attestation policy.
Is H100 HBM encrypted in confidential mode?
NVIDIA documents that Hopper computes on plaintext in the protected GPU region and that on-package HBM is not encrypted. Its physical placement is part of NVIDIA’s threat-model argument; buyers should not publish a blanket “all memory encrypted” claim.
Sources
- WHITEPAPER
- DEPLOY
- ATTEST
- RIMNVIDIA RIM serviceNVIDIA
- NRAS
- MODES
Relevant GPU availability
Verified specifications, confidential-mode support, and public listings for the accelerators this post covers.
Ready to reserve capacity?
Confidential Nodes matches bare-metal confidential GPU nodes to workloads, with verified provider data behind every listing.
