The Evolution of Confidential Computing on x86-64
- Time
- 2026-08-08 10:10 ~ 10:40
- Speaker
- Richard Lyu
- Room
- TR512
- Co-write
Abstract
As cloud computing becomes increasingly widespread, data privacy and confidentiality can no longer rely solely on software level encryption. Hardware based isolation and remote trust mechanisms have become essential. This talk will trace the evolution of confidential computing on the x86-64 platform, with a focus on how these technologies are adopted in cloud environments.
We will start with Intel SGX and explain how enclaves establish fine grained trust boundaries. We will then move to today’s mainstream approach: VM based isolation. By comparing the designs of AMD SEV-SNP and Intel TDX, we will examine their differences in memory page protection, remote attestation, and integration with virtualization stacks. This allows existing applications to gain hardware backed confidentiality with little to no code changes, while establishing a verifiable execution environment on top of cloud infrastructure that is not fully trusted.
Speaker
Richard Lyu
Richard Lyu 是 SUSE Labs 的 EFI 開發者,專門從事 edk2/OVMF 及機密運算的開發與研究,同時也是 UEFI Forum 的成員。他畢業於國立陽明交通大學,擁有深厚的低層系統背景,擅長原始碼分析與追蹤。Richard Lyu 曾受邀至國立清華大學的高等 Unix 程式設計課程擔任講者, 也曾至 FOSDEM 2025 、CYBERSEC 2025 發表研究。他熱衷於參與技術社群,曾擔任 HITCON Enterprise 2024 副總召集人,以及 HITCON Training 2023 總召集人。