Formal Verification of Secure Encrypted Virtualization

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Weerasena, Hansika, Das, Amitabh, Mishra, Prabhat
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866916072032043008
author Weerasena, Hansika
Das, Amitabh
Mishra, Prabhat
author_facet Weerasena, Hansika
Das, Amitabh
Mishra, Prabhat
contents Trusted execution environments (TEEs) provide a secure environment for data and code in use, ensuring that they are protected with respect to confidentiality and integrity. Virtual machine (VM)-based TEEs utilize virtualization technology to create isolated execution spaces that can support a complete operating system or specific applications. AMD secure encrypted virtualization (SEV) is a key technology used in confidential computing in the cloud enabling hardware-based memory encryption to protect sensitive data within VMs. However, AMD SEV often operate without formal assurances of their security guarantees. Our research introduces a formal framework for representing and verifying AMD SEV confidential VMs. Specifically, we conduct design-level and property-level abstraction on AMD SEV specification and conduct property checking on the model to ensure confidentiality, integrity and availability. This approach provides a rigorous foundation for defining and verifying key security attributes for safeguarding execution environments.
format Preprint
id arxiv_https___arxiv_org_abs_2606_01381
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Formal Verification of Secure Encrypted Virtualization
Weerasena, Hansika
Das, Amitabh
Mishra, Prabhat
Cryptography and Security
Hardware Architecture
Trusted execution environments (TEEs) provide a secure environment for data and code in use, ensuring that they are protected with respect to confidentiality and integrity. Virtual machine (VM)-based TEEs utilize virtualization technology to create isolated execution spaces that can support a complete operating system or specific applications. AMD secure encrypted virtualization (SEV) is a key technology used in confidential computing in the cloud enabling hardware-based memory encryption to protect sensitive data within VMs. However, AMD SEV often operate without formal assurances of their security guarantees. Our research introduces a formal framework for representing and verifying AMD SEV confidential VMs. Specifically, we conduct design-level and property-level abstraction on AMD SEV specification and conduct property checking on the model to ensure confidentiality, integrity and availability. This approach provides a rigorous foundation for defining and verifying key security attributes for safeguarding execution environments.
title Formal Verification of Secure Encrypted Virtualization
topic Cryptography and Security
Hardware Architecture
url https://arxiv.org/abs/2606.01381