Providing VM memory encryption to Xen & XCP-ng
At Vates, our aim is to enhance the robust and secure nature of Xen, a well-established virtualization platform, by integrating AMD SEV instructions (Secure Encrypted Virtualization). This will offer an additional security layer via memory encryption from the CPU itself. This feature is meant to be incorporated into XCP-ng upon completion, as a user-friendly solution that doesn't necessitate extensive technical prowess.
In order to accomplish this goal, the project is divided into two concurrent phases:
- Development of a prototype to illustrate its functionality and verify the concept in real use cases.
- Active participation in the Xen. Project to equip the hypervisor code for compatibility with these novel features, with the ultimate objective of merging it upstream.
More to come soon in this repository.