TEE security: verified attestation across vendors
Intel TDX, AMD SEV-SNP, AWS Nitro and NVIDIA confidential GPUs, each attestation verified to its vendor root. Attestation is evidence; keys stay in their owners' hardware.
Trusted execution environments let an operator run a workload that even the operator cannot inspect. That is only useful if the buyer can check the claim. Tenzro verifies attestation from four families of hardware, each to its vendor's root of trust, before a TEE provider is accepted or a confidential workload is dispatched.
Four platforms
Intel TDX. The provider collects a TD quote from inside the trust domain. Tenzro verifies the quote signature and walks the certificate chain up to Intel's root.
AMD SEV-SNP. The provider requests an attestation report from the secure processor. Tenzro fetches the chip's endorsement key and verifies the full chain from AMD's root key down to the report.
AWS Nitro. The enclave produces a signed attestation document. Tenzro checks the COSE signature and validates the chain to the Nitro root certificate.
NVIDIA confidential GPUs. GPU evidence and measurements are collected and verified, so a model served on a confidential GPU carries evidence about the hardware it ran on.
Each platform is verified by its own rules. A report that does not chain to the right vendor root, or whose measurements do not match what the provider registered, is rejected.
Evidence, not custody
On Tenzro, a TEE is evidence about where and how a workload ran. It is not where keys are kept. Account keys are rooted in the owner's own hardware: a passkey, a TPM 2.0 or a Secure Enclave. A TEE provider proves what it ran; it never holds anyone's keys.
That separation keeps each piece doing one job. Attestation answers "which code, on which hardware, with which measurements". Hardware-rooted keys answer "who authorised this". See Hardware-rooted keys.
Registration requires real evidence
Running on a machine that has TEE hardware is not the same as proving it. A TEE provider is registered only after it presents attestation evidence that verifies, pinned to the provider's DID. Buyers can then choose providers by platform and by the trust credentials issued about them.
Post-quantum signatures
Attestation results and the records that reference them are signed with composite hybrid signatures that pair a classical algorithm with ML-DSA-65. The construction is non-separable: both parts must verify, and neither can be stripped off and used alone. See Cryptography.
TEE-first verification of inference
For confidential inference, the verification that matters is TEE attestation: evidence that a specific model ran inside a verified enclave on verified hardware. Where a workload also needs a compact proof about a computation, such as a settlement or aggregation step, the enclave can produce a Plonky3 STARK and sign its commitment, so a verifier gets both the attestation and the proof. See TEE and ZK proofs.