Intel® Trust Domain Extensions (Intel® TDX) is a hardware-based security technology designed to protect virtual machines (VMs) from unauthorized access, even by the system software that manages them. TDX enables a new class of workloads known as confidential virtual machines, which keep data and code private while in use.
TDX is part of Intel’s broader Confidential Computing portfolio, focused on protecting sensitive workloads in modern, multi-tenant cloud environments.
The Problem Intel® TDX Solves
In traditional virtualization models:
This model creates risk when workloads run in shared or untrusted environments.
What Is a Trust Domain Intel® TDX?
Intel® TDX introduces the concept of a Trust Domain (TD).
A Trust Domain is:
Even software running at the highest privilege level outside the TD cannot inspect or modify its memory or CPU state.
How Intel® TDX Works (High Level)
The Intel processor enforces strict isolation between:
This reduces reliance on software-based security controls.
Each Trust Domain uses:
Encrypted memory cannot be read or reused by other components.
Intel® TDX limits and validates interactions between:
Only approved operations are allowed, reducing the attack surface.
Intel® TDX supports remote attestation, enabling a workload to prove:
This is critical for zero-trust and compliance-driven deployments.
Intel® TDX vs Traditional Virtual Machines
| Feature | Traditional VM | Intel® TDX |
| Hypervisor trust | Fully trusted | Treated as untrusted |
| Memory visibility | Readable by host | Encrypted and isolated |
| Isolation | Software-based | Hardware-enforced |
| Cloud suitability | Standard | Confidential workloads |
Intel® TDX vs Intel® SGX
| Feature | Intel® SGX | Intel® TDX |
| Protection scope | Application enclaves | Full virtual machine |
| Programming model | Specialized | Standard OS and VM |
| Cloud scalability | Limited | High |
| Primary use | App-level security | VM-level security |
Intel® TDX is designed specifically for cloud-scale confidential VMs, while SGX focuses on application-level isolation.
Common Use Cases
Intel® TDX is well-suited for:
Benefits of Intel® TDX
