Protecting Patient Data in Memory via AMD SEV-SNP and Intel SGX Enclaves

Core clinical engineering and protocols for Confidential Computing in Healthcare.

The Vulnerability of 'Data in Use' in the Cloud

Traditional cybersecurity protects data at rest (disk encryption) and data in transit (TLS). However, when data is processed by the CPU, it must be decrypted into system memory (RAM). In public cloud environments, compromised hypervisors, rogue datacenter staff, or kernel exploits can scrape cleartext patient records directly from memory.

Hardware-Enforced Confidential Virtual Machines

SaMDPlatform deploys confidential virtual machines leveraging AMD SEV-SNP and Intel TDX. System memory is encrypted on-the-fly by specialized hardware memory controllers inside the CPU. The hypervisor cannot read or modify memory belonging to the SaMD application, providing mathematical assurance of patient privacy even in shared public clouds.

Health-Domain-Portfolio Erkunden