NVIDIA Confidential Computing: extending a CPU TEE to the GPU

NVIDIA Confidential Computing is an attached-device trust architecture. The GPU does not replace the CPU confidential VM; the two are verified and operated as one boundary.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

NVIDIA Confidential Computing extends a supported CPU confidential VM into a supported GPU using secure boot, an on-die root of trust, GPU attestation, a protected session with the driver, hardware access controls, and protected CPU–GPU data movement. Production confidentiality requires CC-On plus successful policy-based attestation and key release.

The combined CPU-and-GPU boundary

The CPU confidential VM provides the protected guest and driver environment. The GPU establishes measured boot and its own attested device state. A protected session binds the GPU to the driver inside the CVM, and hardware controls constrain access. On Hopper, encrypted and authenticated bounce buffers carry code, data, commands, and metadata across host-visible shared memory.WHITEPAPERDEPLOY

ComponentSecurity roleBuyer evidence
CPU TEEProtects guest memory/state from the host and runs the trusted driver/workloadTDX or SEV-SNP evidence and accepted measurement/policy
GPU root of trust and firmwareMeasures boot and produces device claimsDevice certificate, firmware/security version, RIM comparison
Protected session/device pathBinds the GPU to the intended CVM and protects transfersSupported platform topology and deployment configuration
VerifierAppraises CPU/GPU evidence, collateral, freshness, measurements, and modePolicy, decision record, NRAS or trusted local-verification design
Relying serviceReleases model/data/session keys only to an accepted environmentFail-closed key broker and endpoint binding test
ATTESTRIMNRAS

CC-Off, CC-On, and CC-DevTools are different states

ModePurposePublication-safe interpretation
CC-OffOrdinary operationConfidential-computing protections are not active
CC-OnProduction confidential modeIntended secure state; still verify fresh evidence and policy before release
CC-DevToolsProfiling and development accessExposes counters/debug-related capability; do not describe as equivalent to CC-On
MODES

GPU attestation and reference integrity measurements

NVIDIA’s attestation stack can evaluate GPU evidence and signed reference integrity measurements. NVIDIA Remote Attestation Service can perform remote appraisal, while local verification needs its own trusted execution context. NVIDIA warns that verification running on an elevated untrusted host can be subverted. The workload owner must decide which verifier to trust and how its result reaches the key broker.ATTESTRIMNRAS

What it protects—and the caveats

  • Extends protection for code, data, and commands from the CPU confidential VM into supported GPU execution.
  • Protects CPU–GPU transfer through the documented confidential path; transfer-heavy work can pay encryption and bounce-buffer overhead.
  • Hopper computes on plaintext inside the protected GPU region. Its on-package HBM is not encrypted; NVIDIA’s threat model treats it as protected from ordinary physical interposers.
  • Does not prevent denial of service or every sophisticated physical and side-channel attack.
  • Does not make unsafe guest code, model behavior, tool access, logs, or outputs secure.
  • Does not turn an unsupported SKU, topology, driver, firmware, or provider instance into a production confidential platform.
WHITEPAPERDEPLOY

Operational requirements

  1. Use NVIDIA’s live deployment compatibility matrix for the exact Hopper or Blackwell model, CPU TEE, system, VBIOS, firmware, driver, CUDA, hypervisor, and topology.
  2. Collect evidence for every device admitted to a multi-GPU or multi-node job and bind membership to the protected workload.
  3. Verify device certificate revocation, current reference measurements, firmware/security versions, CC-On state, freshness, and endpoint binding.
  4. Gate model, dataset, prompt/session, and tool keys on the accepted combined result.
  5. Test upgrades, resets, replacement GPUs, autoscaling, evidence-service outages, and development-mode rejection.
  6. Benchmark compute, transfers, collective communication, loading, startup, and operational recovery under the actual secure configuration.

Frequently asked questions

Can an NVIDIA GPU be confidential without a CPU TEE?

NVIDIA’s documented architecture extends a supported CPU confidential VM to the GPU. The protected driver/workload and device must be verified as one system.

Is CC-DevTools a production confidential mode?

No. It enables profiling and debugging-related capability with a security trade-off. Production requirements should specify CC-On and enforce that claim in attestation policy.

Is H100 HBM encrypted in confidential mode?

NVIDIA documents that Hopper computes on plaintext in the protected GPU region and that on-package HBM is not encrypted. Its physical placement is part of NVIDIA’s threat-model argument; buyers should not publish a blanket “all memory encrypted” claim.

Sources

  1. WHITEPAPER
  2. DEPLOY
  3. ATTEST
  4. RIM
  5. NRAS
  6. MODES

Relevant GPU availability

Verified specifications, confidential-mode support, and public listings for the accelerators this post covers.

Ready to reserve capacity?

Confidential Nodes matches bare-metal confidential GPU nodes to workloads, with verified provider data behind every listing.