Confidential Computing, Secure Enclaves, and Attestation
Confidential computing is a set of technologies designed to protect data in transit, at rest, and in use. Such protection is often achieved through hardware-based attested trusted execution environments (TEEs). A TEE is an isolated environment within a computer system that prioritizes security and confidentiality when executing sensitive computations. Using a memory encryption engine, TEEs encrypt data before they are stored in memory and decrypt the data only when computation is required. This approach ensures data integrity, data confidentiality, and code integrity—even if the underlying operating system or software stack is compromised.
According to digital asset custodian Vaultody, hardware enclaves offer unmatched security, are tamper-proof against physical access, operate efficiently at the processor level, and are versatile for a wide variety of applications.1
Attestation refers to technical assurances about relevant properties of a system, such as an AI model's performance, fairness, robustness, and transparency. As described by ModelOp, an AI governance software company, attestations are used to document the approved use of AI models, support annual model reviews, and fulfill regulatory reporting obligations.2 They also help ensure that AI systems comply with both internal organizational policies and external regulatory requirements.
Commercial Off-the-Shelf Solutions and Simple Recommendations
- FairNow AI Governance Platform3
- IBM WatsonX Governance4
- Advanced Micro Devices' (AMD's) Secure Encrypted Virtualization (SEV)5
- Intel Trust Domain Extensions6 and Software Guard Extensions (SGX)7
- IBM Z Secure Execution8
- Linux Power Protected Execution Facility9
- ARM Confidential Compute Architecture10 and Platform Security Architecture11
- Google Cloud12
- Microsoft Azure13
- Amazon Nitro Enclaves in AWS14
- Mithril Security's AICert (Note: As of August 2025 AICert is still under development. Do not use it in production of AI systems.)15
How Does This Relate to the Rest of the Guide or Other Threats That the User Cares About?
- Confidential computing: A.CPCC-1, A.CPCC-2, A.CPCC-3, CC.DPCC-1, CC.DPCC-2, COP.DPCC-1, COP.DPCC-2
- Secure enclaves: A.CPCC-1
Other Sources of Information About This Topic
- “Learn About Confidential Computing Attestation” (Red Hat)16
- “ML Property Attestation Using TEEs” (Secure Systems Group, Aalto University)17
- “AI TRiSM Adoption” (ModelOp)18
- “Gartner AI TRiSM Market Guide” (Mindgard)19
- “AI Regulations & Standards” (ModelOp)20
- Confidential Computing (Confidential Computing Consortium)21
- “AI Algorithm Audits” (ISCACA)22
- “Global Approaches to Artificial Intelligence Regulation” (University of Washington)23
- “How Does a Trusted Execution Environment (TEE) Differ from a Secure Enclave?” (Massed Compute)24
- “Secure Enclave” (Apple)25
- “What Is the Definition of a Cryptographic Enclave?” (Packetlabs)26
- “What Are Secure Enclaves?” (Opaque)27
- “Hardware Attacking Edge LLM (New)” (Kansas State University)28
- “Writing Secure Cloud Applications Using Intel SGX” (Large-Scale Data & Systems Group)29
- “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves” (HKU School of Professional and Continuing Education)30
- “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves” (AWS)31
- “Hardware Enclaves” (Vaultody)32
- “Attesting Distributional Properties of Training Data for Machine Learning” (arXiv)33
- “Attestable Audits” (arXiv)34
- “DeepAttest” (Association for Computing Machinery)35
- “Experimenting with Zero-Knowledge Proofs of Training” (Association for Computing Machinery)36
- Reviewing the Role of Machine Learning and Artificial Intelligence for Remote Attestation in 5G+ Networks (IEEE)37
- “Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves” (arXiv)38
- “Distilled Large Language Model in Confidential Computing Environment for System-on-Chip Design” (arXiv)39
- “Evolutionary Large Language Models for Hardware Security” (Association for Computing Machinery)40
Notes
- Vaultody, homepage. Return to content ⤴
- ModelOp, “Attestation.” Return to content ⤴
- FairNow, homepage. Return to content ⤴
- IBM, “Scale Trusted AI with Watsonx.governance.” Return to content ⤴
- Advanced Micro Devices, “AMD Secure Encrypted Virtualization (SEV).” Return to content ⤴
- Intel, “Intel® Trust Domain Extensions (Intel® TDX).” Return to content ⤴
- Intel, “Reduce the Attack Surface Around Your Data to Unlock New Opportunities”; Popa, “Secure Computation”; Adamski, “Overview of Intel SGX—Part 1, SGX Internals.” Return to content ⤴
- IBM, “What Is IBM Secure Execution?” Return to content ⤴
- Linux Kernel, “Protected Execution Facility.” Return to content ⤴
- Arm Limited, “Confidential Compute Architecture.” Return to content ⤴
- Arm Limited, “Security—Platform Security Architecture.” Return to content ⤴
- Google Cloud, “Confidential Computing.” Return to content ⤴
- Microsoft, “Azure Offerings.” Return to content ⤴
- AWS, “AWS Nitro Enclaves.” Return to content ⤴
- Millet, “AICert v1.0—Open-Source AI Traceability Tool for Verifiable Training”; Mithril Security, “AICert”; AICert, homepage. Return to content ⤴
- de Dinechin, “Learn About Confidential Computing Attestation.” Return to content ⤴
- Duddu et al., “Machine Learning Property Attestation Using TEEs.” Return to content ⤴
- ModelOp, “AI TRiSM Adoption.” Return to content ⤴
- Glynn, “Gartner AI TRiSM Market Guide.” Return to content ⤴
- ModelOp, “AI Regulations & Standards.” Return to content ⤴
- Confidential Computing Consortium, Confidential Computing. Return to content ⤴
- Prasad, “AI Algorithm Audits.” Return to content ⤴
- Coringrato, “Global Approaches to Artificial Intelligence Regulation.” Return to content ⤴
- Massed Compute, “How Does a Trusted Execution Environment (TEE) Differ from a Secure Enclave?” Return to content ⤴
- Apple, “Secure Enclave.” Return to content ⤴
- Packetlabs, “What Is the Definition of a Cryptographic Enclave?” Return to content ⤴
- Agrawal, “What Are Secure Enclaves?” Return to content ⤴
- Kansas State University, “[Hardware] Attacking Edge LLM (New).” Return to content ⤴
- Aublin, “Writing Secure Cloud Applications Using Intel SGX.” Return to content ⤴
- Miles, d’Aliberti, and Kovba, “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves.” Return to content ⤴
- Renzo et al., “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves.” Return to content ⤴
- Vaultody, “Hardware Enclaves.” Return to content ⤴
- Duddu et al., “Attesting Distributional Properties of Training Data for Machine Learning.” Return to content ⤴
- Schnabl et al., “Attestable Audits.” Return to content ⤴
- Chen et al., “DeepAttest.” Return to content ⤴
- Garg et al., “Experimenting with Zero-Knowledge Proofs of Training.” Return to content ⤴
- Gallagher et al., Reviewing the Role of Machine Learning and Artificial Intelligence for Remote Attestation in 5G+ Networks. Return to content ⤴
- Dhanraj et al., “Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves.” Return to content ⤴
- Ben, Feng, and Wang, “Distilled Large Language Model in Confidential Computing Environment for System-on-Chip Design.” Return to content ⤴
- Akyash and Kamali, “Evolutionary Large Language Models for Hardware Security.” Return to content ⤴