AMD Sends Out Linux Patches For Enabling SEV-TIO TDISP With PCIe 6.0
([AMD] 3 Hours Ago
AMD SEV-TIO TDISP)
- Reference: 0001658352
- News link: https://www.phoronix.com/news/AMD-SEV-TIO-TDISP-Linux-Patches
- Source link:
The newest Linux kernel patches out of AMD for enhancing the upstream support with the new AMD EPYC 9006 "Venice" processors is for enabling SEV-TIO TDISP that is supported with PCI Express 6.0 and beyond.
In addition to other security enhancements with 6th Gen AMD EPYC processors like the recently posted patches for [1]Enhanced SMT Protection for SEV-SNP guest VMs, another one is SEV-TIO TDISP. Yes. quite a mouthful: Secure Encrypted Virtualization Trusted I/O Trusted Execution Environment Device Interface Security Protocol
Trusted Execution Environment (TEE) Device Interface Security Protocol is supported by PCI Express 6.0 and newer for securing direct I/O device assignment for confidential computing environments, which in the case of AMD EPYC is for use with their Secure Encrypted Virtualization VMs.
A set of 17 Linux kernel patches were sent out today on the Linux kernel mailing list for allowing guests to establish trust in a device supporting the PCIe TDISP specification and interacting with the device via private memory. This work includes a common TEE Security Manager (TSM) being developed in collaboration with Intel, Arm, and RISC-V for handling the TDISP, PCIe encryption, device attestation, and other commonality that will happen between CPU vendor implementations of TDISP.
Those interested in this AMD SEV-TIO TDISP work for the Linux kernel can find the initial patches out for review and discussion on the [2]Linux kernel mailing list .
[1] https://www.phoronix.com/news/AMD-Enhanced-SMT-Protection
[2] https://lore.kernel.org/lkml/20260916115159.1938195-1-aik@amd.com/
In addition to other security enhancements with 6th Gen AMD EPYC processors like the recently posted patches for [1]Enhanced SMT Protection for SEV-SNP guest VMs, another one is SEV-TIO TDISP. Yes. quite a mouthful: Secure Encrypted Virtualization Trusted I/O Trusted Execution Environment Device Interface Security Protocol
Trusted Execution Environment (TEE) Device Interface Security Protocol is supported by PCI Express 6.0 and newer for securing direct I/O device assignment for confidential computing environments, which in the case of AMD EPYC is for use with their Secure Encrypted Virtualization VMs.
A set of 17 Linux kernel patches were sent out today on the Linux kernel mailing list for allowing guests to establish trust in a device supporting the PCIe TDISP specification and interacting with the device via private memory. This work includes a common TEE Security Manager (TSM) being developed in collaboration with Intel, Arm, and RISC-V for handling the TDISP, PCIe encryption, device attestation, and other commonality that will happen between CPU vendor implementations of TDISP.
Those interested in this AMD SEV-TIO TDISP work for the Linux kernel can find the initial patches out for review and discussion on the [2]Linux kernel mailing list .
[1] https://www.phoronix.com/news/AMD-Enhanced-SMT-Protection
[2] https://lore.kernel.org/lkml/20260916115159.1938195-1-aik@amd.com/