K-0006

Trusted execution environment (TEE)

An execution area protected by the processor that keeps the data inside confidential and unaltered, and the code unaltered, even from the host's own software.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

A trusted execution environment (TEE) is an execution area that the processor protects, so that software outside it, including the host operating system and hypervisor, cannot read the data inside or alter its code and data S-1600 S-1604.

The Confidential Computing Consortium lists data confidentiality, data integrity and code integrity as the core attributes of a TEE, and code confidentiality and attestability as optional S-1604. Isolation and remote attestation are separate properties. The TEE protects a workload, and attestation, the validation of a hardware-signed report of what was loaded, lets a remote party check it S-1604. The consortium defines confidential computing as computation in a hardware-based, attested TEE, so it requires both S-1604. A TEE can cover a whole confidential virtual machine and extend to accelerators S-1604. PAL*M, for example, pairs Intel TDX confidential VMs with NVIDIA H100 GPUs to attest properties of generative models S-0012. In AI verification, TEEs underpin TEE remote attestation for AI workloads and confidential multi-party verification, such as running safety benchmarks while keeping both the model and the test data confidential S-0009. A 2026 MIRI Technical Governance Team post notes that whoever holds the hardware's attestation key can produce valid reports, and that microarchitectural side channels and physical attacks such as bus interposition remain concerns S-0014.

Connections in the research map

Related research

Sources and provenance

  1. S-1600 / Tier A

    NIST Computer Security Resource Center (CSRC) Glossary ↗

    National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center

    Supports: NIST definition of TEE as an area or enclave protected by a system processor

    Locator: term: trusted_execution_environment (NISTIR 8320)

    Version and catalogue details
  2. S-1604 / Tier B

    Common Terminology for Confidential Computing ↗

    Confidential Computing Consortium · 2022 · Confidential Computing Consortium

    Supports: confidential computing defined as computation in a hardware-based, attested TEE; core TEE attributes (data confidentiality, data integrity, code integrity); optional attributes including code confidentiality and attestability; attestation as validation of a hardware-signed report of TCB measurements; confidential VMs protected from the hypervisor and host OS

    Locator: definitions; TEE attributes; attestation; confidential VMs

    Version and catalogue details
  3. S-0012 / Tier B

    PAL*M: Property Attestation for Large Generative Models ↗

    P. Chantasantitam, A. I. Caulfield, V. Duddu, L. J. Gunn, N. Asokan · 2026 · arXiv

    Supports: property attestation using confidential VMs with Intel TDX and NVIDIA H100 GPUs

    Locator: abstract

    Version and catalogue details
  4. S-0009 / Tier B

    Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments ↗

    C. Schnabl, D. Hugenroth, B. Marino, A. R. Beresford · 2025 · ICML 2025 Workshop on Technical AI Governance

    Supports: TEE-based verifiable benchmarks keeping model and test data confidential

    Locator: abstract

    Version and catalogue details
  5. S-0014 / Tier C

    On TEEs for Privacy-Preserving Monitoring in AI Governance ↗

    Gloria Z · 2026 · MIRI Technical Governance Team

    Supports: attestation-key holder can produce valid reports; microarchitectural side channels and physical attacks such as bus interposition as limitations

    Locator: Limitations

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review