Confidential Computing, Secure Enclaves, and Attestation

Confidential computing is a set of technologies designed to protect data in transit, at rest, and in use. Such protection is often achieved through hardware-based attested trusted execution environments (TEEs). A TEE is an isolated environment within a computer system that prioritizes security and confidentiality when executing sensitive computations. Using a memory encryption engine, TEEs encrypt data before they are stored in memory and decrypt the data only when computation is required. This approach ensures data integrity, data confidentiality, and code integrity—even if the underlying operating system or software stack is compromised.

According to digital asset custodian Vaultody, hardware enclaves offer unmatched security, are tamper-proof against physical access, operate efficiently at the processor level, and are versatile for a wide variety of applications.⁠1

Attestation refers to technical assurances about relevant properties of a system, such as an AI model's performance, fairness, robustness, and transparency. As described by ModelOp, an AI governance software company, attestations are used to document the approved use of AI models, support annual model reviews, and fulfill regulatory reporting obligations.⁠2 They also help ensure that AI systems comply with both internal organizational policies and external regulatory requirements.

Commercial Off-the-Shelf Solutions and Simple Recommendations

  • FairNow AI Governance Platform⁠3
  • IBM WatsonX Governance⁠4
  • Advanced Micro Devices' (AMD's) Secure Encrypted Virtualization (SEV)⁠5
  • Intel Trust Domain Extensions⁠6 and Software Guard Extensions (SGX)⁠7
  • IBM Z Secure Execution⁠8
  • Linux Power Protected Execution Facility⁠9
  • ARM Confidential Compute Architecture⁠10 and Platform Security Architecture⁠11
  • Google Cloud⁠12
  • Microsoft Azure⁠13
  • Amazon Nitro Enclaves in AWS⁠14
  • Mithril Security's AICert (Note: As of August 2025 AICert is still under development. Do not use it in production of AI systems.)⁠15

How Does This Relate to the Rest of the Guide or Other Threats That the User Cares About?

  • Confidential computing: A.CPCC-1, A.CPCC-2, A.CPCC-3, CC.DPCC-1, CC.DPCC-2, COP.DPCC-1, COP.DPCC-2
  • Secure enclaves: A.CPCC-1

Other Sources of Information About This Topic

  • “Learn About Confidential Computing Attestation” (Red Hat)⁠16
  • “ML Property Attestation Using TEEs” (Secure Systems Group, Aalto University)⁠17
  • “AI TRiSM Adoption” (ModelOp)⁠18
  • “Gartner AI TRiSM Market Guide” (Mindgard)⁠19
  • “AI Regulations & Standards” (ModelOp)⁠20
  • Confidential Computing (Confidential Computing Consortium)⁠21
  • “AI Algorithm Audits” (ISCACA)⁠22
  • “Global Approaches to Artificial Intelligence Regulation” (University of Washington)⁠23
  • “How Does a Trusted Execution Environment (TEE) Differ from a Secure Enclave?” (Massed Compute)⁠24
  • “Secure Enclave” (Apple)⁠25
  • “What Is the Definition of a Cryptographic Enclave?” (Packetlabs)⁠26
  • “What Are Secure Enclaves?” (Opaque)⁠27
  • “Hardware Attacking Edge LLM (New)” (Kansas State University)⁠28
  • “Writing Secure Cloud Applications Using Intel SGX” (Large-Scale Data & Systems Group)⁠29
  • “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves” (HKU School of Professional and Continuing Education)⁠30
  • “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves” (AWS)⁠31
  • “Hardware Enclaves” (Vaultody)⁠32
  • “Attesting Distributional Properties of Training Data for Machine Learning” (arXiv)⁠33
  • “Attestable Audits” (arXiv)⁠34
  • “DeepAttest” (Association for Computing Machinery)⁠35
  • “Experimenting with Zero-Knowledge Proofs of Training” (Association for Computing Machinery)⁠36
  • Reviewing the Role of Machine Learning and Artificial Intelligence for Remote Attestation in 5G+ Networks (IEEE)⁠37
  • “Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves” (arXiv)⁠38
  • “Distilled Large Language Model in Confidential Computing Environment for System-on-Chip Design” (arXiv)⁠39
  • “Evolutionary Large Language Models for Hardware Security” (Association for Computing Machinery)⁠40

Notes

  1. Vaultody, homepage. Return to content
  2. ModelOp, “Attestation.” Return to content
  3. FairNow, homepage. Return to content
  4. IBM, “Scale Trusted AI with Watsonx.governance.” Return to content
  5. Advanced Micro Devices, “AMD Secure Encrypted Virtualization (SEV).” Return to content
  6. Intel, “Intel® Trust Domain Extensions (Intel® TDX).” Return to content
  7. Intel, “Reduce the Attack Surface Around Your Data to Unlock New Opportunities”; Popa, “Secure Computation”; Adamski, “Overview of Intel SGX—Part 1, SGX Internals.” Return to content
  8. IBM, “What Is IBM Secure Execution? Return to content
  9. Linux Kernel, “Protected Execution Facility.” Return to content
  10. Arm Limited, “Confidential Compute Architecture.” Return to content
  11. Arm Limited, “Security—Platform Security Architecture.” Return to content
  12. Google Cloud, “Confidential Computing.” Return to content
  13. Microsoft, “Azure Offerings.” Return to content
  14. AWS, “AWS Nitro Enclaves.” Return to content
  15. Millet, “AICert v1.0—Open-Source AI Traceability Tool for Verifiable Training”; Mithril Security, “AICert”; AICert, homepage. Return to content
  16. de Dinechin, “Learn About Confidential Computing Attestation.” Return to content
  17. Duddu et al., “Machine Learning Property Attestation Using TEEs.” Return to content
  18. ModelOp, “AI TRiSM Adoption.” Return to content
  19. Glynn, “Gartner AI TRiSM Market Guide.” Return to content
  20. ModelOp, “AI Regulations & Standards.” Return to content
  21. Confidential Computing Consortium, Confidential Computing. Return to content
  22. Prasad, “AI Algorithm Audits.” Return to content
  23. Coringrato, “Global Approaches to Artificial Intelligence Regulation.” Return to content
  24. Massed Compute, “How Does a Trusted Execution Environment (TEE) Differ from a Secure Enclave? Return to content
  25. Apple, “Secure Enclave.” Return to content
  26. Packetlabs, “What Is the Definition of a Cryptographic Enclave? Return to content
  27. Agrawal, “What Are Secure Enclaves? Return to content
  28. Kansas State University, “[Hardware] Attacking Edge LLM (New).” Return to content
  29. Aublin, “Writing Secure Cloud Applications Using Intel SGX.” Return to content
  30. Miles, d’Aliberti, and Kovba, “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves.” Return to content
  31. Renzo et al., “Large Language Model Inference over Confidential Data Using AWS Nitro Enclaves.” Return to content
  32. Vaultody, “Hardware Enclaves.” Return to content
  33. Duddu et al., “Attesting Distributional Properties of Training Data for Machine Learning.” Return to content
  34. Schnabl et al., “Attestable Audits.” Return to content
  35. Chen et al., “DeepAttest.” Return to content
  36. Garg et al., “Experimenting with Zero-Knowledge Proofs of Training.” Return to content
  37. Gallagher et al., Reviewing the Role of Machine Learning and Artificial Intelligence for Remote Attestation in 5G+ Networks. Return to content
  38. Dhanraj et al., “Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves.” Return to content
  39. Ben, Feng, and Wang, “Distilled Large Language Model in Confidential Computing Environment for System-on-Chip Design.” Return to content
  40. Akyash and Kamali, “Evolutionary Large Language Models for Hardware Security.” Return to content