NVIDIA
An accelerated-computing company whose Hopper and Blackwell data-centre GPUs offer a confidential-computing mode with hardware attestation.
NVIDIA describes itself as having "pioneered accelerated computing" 1. Its public material relevant to verification concerns its data-centre GPUs:
- Confidential-computing mode. NVIDIA documents a confidential-computing mode for its Hopper and Blackwell data-centre GPUs, in which the GPU is paired with a CPU trusted execution environment and attests its identity and firmware 2; see TEE remote attestation for AI workloads.
- H100 launch. NVIDIA engineers describe the feature's launch on the H100, with an on-die root of trust, a fused device identity key and SPDM attestation 3.
- Counters in confidential mode. NVIDIA disables performance counters in full confidential-computing mode, stating that they could provide an avenue for side-channel attacks 2; see On-chip telemetry from timing, memory and performance counters.
- Fleet telemetry. NVIDIA reports an opt-in, customer-installed fleet-management service that provides read-only GPU telemetry 5. Its Fleet Intelligence service uses a read-only, open-source agent that sends GPU power, performance, health and configuration data to an NVIDIA cloud service 6. The service supports attestation only on Blackwell and Vera Rubin GPUs 6. NVIDIA states that its GPUs "do not have hardware tracking technology, kill switches and backdoors" 5. See On-chip telemetry from timing, memory and performance counters.
- Location verification. Avellar and Grunewald report, citing Reuters, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers 7; see Chip location verification.
- Use by others. Tinfoil's documentation lists NVIDIA GPUs in confidential-computing mode as supported hardware for its enclaves 4; see Tinfoil model identity (Modelwrap).
On this page
Related records
Mechanisms and implementations whose records cite or describe this organization's work.
- Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.
- Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.
Publications
Sources this organization authored or published.
- BAbout NVIDIA. NVIDIA. Source recordCited by NVIDIA
- BC. Shrauder & G. Frederick (2026). Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization. NVIDIA Technical Blog. Source recordCited by Chip location verification; On-chip telemetry from timing, memory and performance counters; NVIDIA
- BNVIDIA (2026). NVIDIA Trusted Computing Solutions Release Notes (R595 TRD1). NVIDIA documentation. Source recordCited by TEE remote attestation for AI workloads
- BS. Nassernia (2025). Boost GPU Memory Performance with No Code Changes Using NVIDIA CUDA MPS. NVIDIA Technical Blog. Source recordCited by Hardware-enabled guarantees (flexHEG) and guarantee processors
- BD. Reber Jr. (2025). No Backdoors. No Kill Switches. No Spyware.. NVIDIA Blog. Source recordCited by Hardware-enabled guarantees (flexHEG) and guarantee processors; Hardware performance throttling and licensing
- BNVIDIA (2025). NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper). NVIDIA documentation. Source recordCited by On-chip telemetry from timing, memory and performance counters; TEE remote attestation for AI workloads; Attestable Audits; NVIDIA
- BNVIDIA (2025). Opt-In NVIDIA Software Enables Data Center Fleet Management. NVIDIA Blog. Source recordCited by Chip location verification; Chips are where they are declared to be; NVIDIA
- CC. Su (2024). Now in General Availability: NVIDIA H100 GPUs in Microsoft Azure Confidential Virtual Machines. NVIDIA Blog. Source recordCited by TEE remote attestation for AI workloads
- CE. Apsey et al. (2023). Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI. NVIDIA Technical Blog. Source recordCited by TEE remote attestation for AI workloads; NVIDIA
Sources
- BAbout NVIDIA. NVIDIA. Source recordSupports: self-description as pioneer of accelerated computing
- BNVIDIA (2025). NVIDIA Secure AI with Blackwell and Hopper GPUs (White Paper). NVIDIA documentation. Source recordSupports: confidential computing on Hopper and Blackwell GPUs; performance counters disabled in confidential-computing mode · pp. 6-18
- CE. Apsey et al. (2023). Confidential Computing on NVIDIA H100 GPUs for Secure and Trustworthy AI. NVIDIA Technical Blog. Source recordSupports: H100 confidential-computing launch: on-die root of trust, device identity key, SPDM attestation
- BTinfoil (2026). A primer on secure enclaves. Tinfoil documentation. Source recordSupports: NVIDIA GPUs in confidential-computing mode listed as supported hardware by Tinfoil
- BNVIDIA (2025). Opt-In NVIDIA Software Enables Data Center Fleet Management. NVIDIA Blog. Source recordSupports: opt-in, customer-installed fleet-management service with read-only telemetry; statement on tracking, kill switches and backdoors (provider-reported)
- BC. Shrauder & G. Frederick (2026). Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization. NVIDIA Technical Blog. Source recordSupports: Fleet Intelligence: open-source read-only agent, telemetry and attestation on Blackwell and Vera Rubin (provider-reported)
- BB. Avellar & E. Grunewald (2026). Near-Term Verification Methods for AI Chip Exports. arXiv. Source recordSupports: NVIDIA reportedly developing delay-based location verification with NVIDIA-run servers (citing Reuters)