Startup Detected? 機密コンピューティングの場合 Direct Kernel Boot or vTPM + Measured Boot 本来TPMに書かれているはずのRoot of Trustは利用できない In the context of Confidential Computing, two main approaches exist. The first is Direct Kernel Boot, in which the hash value of the kernel can be verified through the Attestation Report. The second is Measured Boot, which allows the hash values of various components during the boot process to be objectively measured via a virtual TPM (vTPM). It should be noted that the Root of Trust, which is ordinarily provided by a hardware TPM, is not available in this context. アテステーションレポートで カーネルのハッシュ値が確認できる 起動中の各種コンポーネントのハッシュ値を客観的に観測する