Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Confidential Computing with Encrypted Memory in OpenNebula

Open Nebula
10/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this screencast, we are going to show how to deploy sensitive workloads with hardware assisted secure virtualization on different cloud service providers, one in Madrid and one in Berlin, using the confidential computing techniques to deploy virtual machines with a trustless approach. This approach is very important for securing data in use in cases when the privacy is not a guarantee to the nature of the hosting. What is confidential computing? Confidential computing refers to the technique with the main focus on protecting the data in use. Workloads that are leveraging confidential computing are running with the encrypted memory. This guarantees that the hypervisor node cannot read the memory assigned to the virtual machine process, ensuring privacy for the virtual machine runtime without having to trust the hypervisor runtime. For confidential computing to work, the CPU of the hypervisor must support certain features. In the case of AMD CPU, the processor unit needs to have secure encrypted virtualization, also known as SEV. In the case of Intel, the Intel Trusted Domain Extension, also known as TDX. These features must be enabled in the BIOS of a hypervisor. Let's have a look on the architecture of the demonstration. There is one OpenAbility frontend that is deployed on a separate node. We have two SEV-compatible hypervisors running KVM virtualization and managed with OpenNebula. As was mentioned previously, SEV functionality must be enabled in BIOS. Additionally to that, the proper libvirt permissions must be set. For more detailed information, please visit the libvirt guide by using the URL seen on the screen. In order to deploy virtual machines that are leveraging the confidential computing technology, you would need to alter your virtual machine template with the following references. The template that we see on the screen is not complete, and we are going to show only the parts required to enable the confidential computing. The virtual machine template must have the launch security section with a specific policy bitmask in the hexadecimal system. We are setting it to 3, that translates to the following policy. The debugging of the guest is disallowed. Key sharing with other guests is disallowed as well. This policy must be fine-tuned according to the desired outcome and desired features as well as the hypervisor capabilities. The memtune snippet is needed to allocate extra memory demanded by the SEV guests. The SEV flags must be exposed to the CPU, so the CPU model must be set to host pass-through. UFI and Q35 machine type are also required. It is also worth mentioning that the proper scheduling is required to make sure that virtual machines of this template are going to be deployed only on the SEV-compatible hosts. We will be adding confidential computing as a native feature in the upcoming 7.2 version. In the meantime, you can use the raw template snippet with the extra configuration. Under the hosts tab, we can confirm that there are two KVM hosts, each named respectively to their geographical location. Under templates, there is the confidential VM template that implements the configuration that was mentioned earlier. Time to deploy a virtual machine from the confidential VM template. Since both of our hypervisors are supporting these features, we are going to instantiate two virtual machines in a single batch. According to the default scheduling policy, each hypervisor is going to host one VM. To highlight that a host can run workloads with confidential computing features enabled and the ones without at the same time, we are going to instantiate two virtual machines using the OpenSUSE 15 virtual machine template. Now let's connect to the virtual machine that was instantiated from the virtual machine template with confidential computing requirements and verify that these requirements are fulfilled. Using the dmesg command, we are going to verify that the guest is SEV-capable. Using the same command, we can confirm that VMs instantiated from the OpenSUSE 15 template are not SEV-compatible. The dmesg output is rather empty. To showcase both the encrypted and non-encrypted memory, we are going to create a few variables inside the guests. One inside the virtual machine that requires confidential computing and another one with the same value will be created inside the virtual machine that doesn't require these confidential computing capabilities. There is also a custom software called SearchMem that is not publicly available due to security reasons. It is reading the specific process memory and looking for a specific variable. We are going to look for a pattern that is equal to the variable we've defined earlier. As you can see, the memory of the process that corresponds to the virtual machine with ID 107 returns no match. That's because the memory of this virtual machine is in fact encrypted. The memory of the process that corresponds to the virtual machine with ID 109 returns the matching results, meaning that the memory is not encrypted and is exposed to the hypervisor. This screencast was developed in the scope of IPSCIS project. Thank you for watching and see you in the next screencast.

TL;DR

  • OpenNebula demonstrates deploying VMs with encrypted memory using AMD SEV technology across distributed hypervisors in Madrid and Berlin, protecting data in use from untrusted infrastructure.
  • Confidential computing requires specific CPU features (AMD SEV or Intel TDX) enabled in BIOS, along with VM template modifications including launch security policies, memory tuning, and host pass-through CPU settings.
  • Live validation proves memory encryption effectiveness: a custom tool successfully reads variables from standard VM memory but finds no matches in SEV-enabled VM memory, confirming hypervisor-level protection.
  • OpenNebula will integrate confidential computing as a native feature in version 7.2, currently requiring manual template configuration with raw snippets for launch security and scheduling policies.

Confidential Computing Architecture and Requirements

This technical demonstration showcases OpenNebula's implementation of confidential computing across distributed cloud infrastructure, specifically deploying SEV-enabled virtual machines on hypervisors located in Madrid and Berlin. The architecture requires AMD SEV (Secure Encrypted Virtualization) or Intel TDX (Trusted Domain Extension) CPU features enabled in BIOS, along with proper libvirt permissions. The demonstration walks through the complete configuration process, including VM template modifications with launch security policies, memory allocation adjustments, CPU pass-through settings, and scheduling requirements to ensure VMs deploy only on SEV-compatible hosts. OpenNebula plans to integrate confidential computing as a native feature in version 7.2, currently requiring raw template snippets for implementation.

Memory Encryption Validation and Security Proof

The screencast provides concrete validation of memory encryption effectiveness by deploying both encrypted and non-encrypted VMs simultaneously on the same hypervisors. Using dmesg commands, the presenter confirms SEV capability in confidential VMs while demonstrating its absence in standard OpenSUSE 15 instances. The most compelling proof comes from a custom SearchMem tool that attempts to read process memory from the hypervisor level. When searching for identical variables created in both VM types, the tool finds no matches in the SEV-enabled VM's encrypted memory but successfully retrieves the variable from the non-encrypted VM's exposed memory. This demonstrates that confidential computing protects data in use even when the underlying infrastructure is untrusted, addressing privacy concerns inherent in public cloud hosting environments.

Chapters

0:00 - Introduction and Use Case
0:28 - Confidential Computing Explained
1:14 - Architecture and Requirements
1:44 - VM Template Configuration
3:07 - Deployment Demonstration
4:15 - SEV Capability Verification
5:50 - Memory Encryption Validation

Key Quotes

0:19 "This approach is very important for securing data in use in cases when the privacy is not a guarantee to the nature of the hosting."
0:40 "This guarantees that the hypervisor node cannot read the memory assigned to the virtual machine process, ensuring privacy for the virtual machine runtime without having to trust the hypervisor runtime."
2:56 "We will be adding confidential computing as a native feature in the upcoming 7.2 version."
6:46 "As you can see, the memory of the process that corresponds to the virtual machine with ID 107 returns no match. That's because the memory of this virtual machine is in fact encrypted."

FAQ

What CPU requirements are needed for confidential computing in OpenNebula?

Hypervisors must have AMD processors with SEV (Secure Encrypted Virtualization) or Intel processors with TDX (Trusted Domain Extension) features. These capabilities must be enabled in the BIOS, and proper libvirt permissions must be configured on the host system.

Can confidential computing VMs run alongside standard VMs on the same hypervisor?

Yes, the demonstration shows that SEV-compatible hypervisors can simultaneously host both confidential computing VMs with encrypted memory and standard VMs without encryption, allowing mixed workload deployment on the same infrastructure.


Categories:
  • » Data Protection » Backup & Recovery
  • » Data Management » Virtualization
  • » Cloud » Private Cloud
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Data Protection
  • Technical Deep Dive
  • Demo
  • Virtualization
  • Confidential Computing
  • Memory Encryption
  • AMD SEV
  • Intel TDX
  • Virtualization Security
  • Trustless Computing
  • KVM Hypervisor
  • Distributed Cloud
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Confidential Computing with Encrypted Memory in OpenNebula

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      11:00 AM
                      10/27/2026
                      Maximize Security, Value, and Returns on Your Microsoft Investment
                      https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                      https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version