AMD SEV (Secure Encrypted Virtualization) encrypts VM memory with per-VM keys, shielding it from the hypervisor. SEV-ES extends this to CPU register state, while SEV-SNP adds memory ownership checks to prevent malicious hypervisors from remapping private pages. SNP enables guests to request signed reports from AMD's secure processor, verifying launch state and configuration. On Google Cloud, the host loads firmware and boot software—including Coconut SVSM for protected services like virtual TPM—before SNP launch.
The process uses SNP_LAUNCH_START, SNP_LAUNCH_UPDATE, and SNP_LAUNCH_FINISH commands, maintaining a SHA-384 hash of the initial image. During remote attestation, a verifier compares this fingerprint against expected values. The Linux kernel exposes SNP via /dev/sev-guest, allowing applications to retrieve reports using the SNP_GET_REPORT ioctl with specified VM privilege levels (VMPL 0-3).
Source: Hacker News · Summarized by HeadlinesBriefing