Strengthen Workload Security on Top of AMD SEV

Anjuna Seaglass and AMD's SEV (Secure Encrypted Virtualization) technology gives enterprises the flexibility to run their most sensitive workloads in the cloud or on-premises while keeping them protected from insider and external threats. Running any workload in a Trusted Execution Environment (TEE) protects the most sensitive code and data, backed by hardware-based trust that cannot be spoofed.

Reduce the Attack Surface with Anjuna Confidential Containers

Running software in an AMD SEV CVM protects it from external attackers on the machine, but not from administrators with access to the CVM, and not from a zero-day vulnerability in the CVM's operating system (OS). The Anjuna Confidential Container runs a hardened OS and only the customer's specific container inside an AMD SEV CVM. The container allows no secure shell protocol (SSH) access and cannot be exec'ed into, reducing the attack surface to a minimum.

Left click drag to rotate. Two-finger drag / mouse wheel to zoom. Right click drag / Command (or Control) drag to pan.
Encrypt VM Memory with AMD SEV

Encrypt VM Memory with AMD SEV

AMD SEV lets a VM run as a Confidential VM (CVM). The AMD central processing unit (CPU) encrypts CVM memory so that no privileged user outside the CVM — not even a root user or the kernel on the host from which the CVM was launched — can access it. Whether a host is breached through a zero-day vulnerability or compromised by a malicious or compromised insider, this hardware-based protection secures the memory of software running in the CVM in ways that software-only solutions cannot.

Encrypt VM Memory with AMD SEV

AMD SEV lets a VM run as a Confidential VM (CVM). The AMD central processing unit (CPU) encrypts CVM memory so that no privileged user outside the CVM — not even a root user or the kernel on the host from which the CVM was launched — can access it. Whether a host is breached through a zero-day vulnerability or compromised by a malicious or compromised insider, this hardware-based protection secures the memory of software running in the CVM in ways that software-only solutions cannot.

Reduce the Attack Surface with Anjuna Confidential Containers

Running software in an AMD SEV CVM protects it from external attackers on the machine, but not from administrators with access to the CVM, and not from a zero-day vulnerability in the CVM's operating system (OS). The Anjuna Confidential Container runs a hardened OS and only the customer's specific container inside an AMD SEV CVM. The container allows no secure shell protocol (SSH) access and cannot be exec'ed into, reducing the attack surface to a minimum.

Reduce the Attack Surface with Anjuna Confidential Containers

Reduce the Attack Surface with Anjuna Confidential Containers

Running software in an AMD SEV CVM protects it from external attackers on the machine, but not from administrators with access to the CVM, and not from a zero-day vulnerability in the CVM's operating system (OS). The Anjuna Confidential Container runs a hardened OS and only the customer's specific container inside an AMD SEV CVM. The container allows no secure shell protocol (SSH) access and cannot be exec'ed into, reducing the attack surface to a minimum.

Simplify Remote Attestation

Simplify Remote Attestation

Remote attestation is a key pillar of confidential computing. It establishes trust in software running in a TEE through hardware verification that an attacker cannot spoof. Software running in a TEE can request that the AMD CPU generate an attestation report. This report is cryptographically signed by the hardware, proving that the workload is running in a genuine TEE. It also includes software measurements of the workload, proving that it is running a trusted, unmodified version.

Building a remote attestation flow from scratch is complex. Teams must learn the technology, generate an attestation quote, capture software measurements during development, and verify the quote before building the software to apply that knowledge, stand up an attestation verification service, and more.

The Anjuna Policy Manager (APM) is an attestation-aware secret store. It releases secrets to Anjuna Confidential Containers based on the attestation report each container presents and a release policy tied to its software measurements. With the Anjuna command line interface (CLI), CLI, developers can direct the Anjuna Runtime to fetch secrets from the APM and inject them into their code with no code changes required.

Simplify Remote Attestation

Remote attestation is a key pillar of confidential computing. It establishes trust in software running in a TEE through hardware verification that an attacker cannot spoof. Software running in a TEE can request that the AMD CPU generate an attestation report. This report is cryptographically signed by the hardware, proving that the workload is running in a genuine TEE. It also includes software measurements of the workload, proving that it is running a trusted, unmodified version.

Building a remote attestation flow from scratch is complex. Teams must learn the technology, generate an attestation quote, capture software measurements during development, and verify the quote before building the software to apply that knowledge, stand up an attestation verification service, and more.

The Anjuna Policy Manager (APM) is an attestation-aware secret store. It releases secrets to Anjuna Confidential Containers based on the attestation report each container presents and a release policy tied to its software measurements. With the Anjuna command line interface (CLI), CLI, developers can direct the Anjuna Runtime to fetch secrets from the APM and inject them into their code with no code changes required.

Use AMD SEV Anywhere and at Scale

The Anjuna Seaglass platform removes the need to learn the different implementation patterns for AMD SEV across clouds and on-premises environments. Enterprises can harness AMD SEV anywhere with the same unified experience and the same ease of use.

As well, enterprises that are orchestrating workloads at scale with Kubernetes can easily extend the protection over them using AMD SEV. With Anjuna Seaglass, teams can launch a pod as a Confidential Pod, protecting its code and data from a malicious cluster admin or from a node breached through a backdoor vulnerability.

Use AMD SEV Anywhere and at Scale

Reduce the Attack Surface with Anjuna Confidential Containers

Running software in an AMD SEV CVM protects it from external attackers on the machine, but not from administrators with access to the CVM, and not from a zero-day vulnerability in the CVM's operating system (OS). The Anjuna Confidential Container runs a hardened OS and only the customer's specific container inside an AMD SEV CVM. The container allows no secure shell protocol (SSH) access and cannot be exec'ed into, reducing the attack surface to a minimum.

Support the Most Secure Environments

Anjuna Seaglass supports the most secure on-premises environments, including those where access to external networks and the internet is not allowed. Even in air-gapped environments, Anjuna Seaglass provides the mechanism to run and verify the validity of.

Want to take it a test drive?

Customer Success with

AMD

All Case Studies
No items found.

See the power of protection for yourself