Checked by VoltageGPU · 9 October 2026
Attestation verifiedIntel TDX + NVIDIA confidential computing
An Intel TDX quote, generated inside an Intel TDX trust domain, and NVIDIA GPU attestation tokens, both carrying a hash of the same workload manifest. VoltageGPU checked the quote's signature chain up to Intel's root and the tokens' signatures up to NVIDIA's attestation service. You can check them again yourself, offline, with the commands below.
- Attested
- 2026-10-09 21:54:01 UTC
- time signed by NVIDIA
- GPU
- 1 × GB20X
- NVIDIA Blackwell (GB20X), model signed by NVIDIA
- CPU trust domain
- Intel TDX
- quote v4, chained to the Intel SGX Root CA
- Intel TCB
- UpToDate
- per Intel, 9 October 2026
§ 01 / checked by VoltageGPU
What we verified, line by line
Run on 2026-10-09 21:54:22 UTC by voltagegpu-verified/1: the checks of voltage-verify verify --offline, made stricter (debug mode, GPU token binding, NVIDIA keys chained to a pinned NVIDIA certificate, Intel collateral dated against the NVIDIA-signed time). Each line says what passing means and what the code saw.
Bundle
- Manifest commitments
manifest.commitmentsSHA-256 and SHA-512 of the workload manifest are recomputed and match the bundle (bookkeeping; the binding itself is checked below).
SHA-256 and SHA-512 of the canonical manifest equal the commitments recorded in the bundle
Intel TDX
- TDX quote structure
tdx.structureThe quote is an Intel TDX quote, version 4, TEE type 0x81, with an ECDSA P-256 attestation key and a PCK certificate chain.
TDX quote v4, TEE type 0x81, 4940 bytes
- Quote bound to the manifest
tdx.report_dataThe 64-byte report_data inside the quote is the SHA-512 of the manifest, so the quote was requested with this manifest and its challenge.
quote report_data equals SHA-512 of the manifest
- Trust domain not in debug mode
tdx.debugThe TD attributes signed in the quote say debug is off: the host cannot read the trust domain’s memory through the debug interface.
TDATTRIBUTES.DEBUG is 0
- Intel signature chain
tdx.signaturesThe attestation key signs the quote, the Quoting Enclave vouches for that key, and the platform certificate chains to the Intel SGX Root CA we pin.
attestation key, QE binding, QE report and PCK chain verify up to the pinned Intel SGX Root CA
- Intel collateral
tdx.collateralThe TCB info and Quoting Enclave identity carried in the bundle are signed by Intel’s SGX TCB Signing certificate, which chains to the same pinned root and is not on Intel’s revocation list.
TCB info and QE identity are signed by Intel's SGX TCB Signing certificate, chained to the pinned Intel SGX Root CA and not revoked; fields read from the signed bytes only
- Platform TCB level
tdx.tcbBy Intel’s TCB info and QE identity, both valid at the NVIDIA-signed attestation time, the platform firmware, the TDX module and the Quoting Enclave were at a level Intel rates UpToDate (or SWHardeningNeeded).
platform TCB UpToDate, QE UpToDate, TDX_03 UpToDate, per Intel TCB info issued 2026-10-09
- Revocation
tdx.revocationIntel’s revocation lists, signed by their issuers and valid at the attestation time, do not list the platform certificate or its CA.
PCK certificate not revoked (57 entries in Intel's PCK CRL), PCK CA not revoked (0 entries in the root CRL), both CRLs valid at attestation time
NVIDIA GPU
- NVIDIA signatures
nvidia.signaturesNVIDIA’s Remote Attestation Service signed the GPU tokens, with keys carried in the bundle whose certificates chain to an NVIDIA Attestation Service intermediate (pinned by us, or served by NVIDIA’s own key endpoint), so the downloaded bundle verifies offline with the same keys.
2 NVIDIA-signed tokens verify (ES384, issuer NRAS) with keys carried in the bundle, certificates chained to the pinned NVIDIA Attestation Service intermediate
- GPU attestation bound to the manifest
nvidia.nonceThe nonce NVIDIA signed is the SHA-256 of the same manifest, so the GPU attestation was requested with the same manifest and challenge as the TDX quote. The two proofs are tied together only through that manifest hash.
NRAS eat_nonce equals SHA-256 of the manifest, in the verifier token and every GPU token
- GPU tokens belong to this attestation
nvidia.bindingEvery per-GPU token is the exact one NVIDIA’s summary token names by digest: none was swapped in from another session or left out.
each GPU token is the one NVIDIA's verifier token names (SHA-256 digest in submods), 1 GPU(s)
- GPU claims
nvidia.policyNVIDIA reports, for every GPU: measurements match NVIDIA’s reference values, secure boot on, debug disabled, nonce matched, report signature and certificate chain valid.
overall result true; every GPU: measurements success, secure boot on, debug disabled, nonce matched, report signature and certificate chain validated by NVIDIA
- Token issued with the bundle
nvidia.freshnessNVIDIA issued its token after the creation time declared in the manifest, within 24 hours of it, and not in the future.
NVIDIA token issued 3s after the time declared in the manifest
§ 02 / re-verify it yourself
Do not take our word for it
The trust chain ends at Intel and NVIDIA, not at VoltageGPU. These commands run on your machine.
Get the tool and this exact bundle
voltage-verify is open source (MIT, Python 3.10+). The bundle is the file these checks ran on; compare its SHA-256 with the one printed at the bottom of this page.
pip install "voltage-verify>=0.2.1" curl -fsSL -o bundle.json https://voltagegpu.com/verified/lDf9-pBDNN9pB6azPSEyMg/bundle.json sha256sum bundle.jsonEvery check, on your machine, from the bundle alone
Re-runs the checks above with the Intel collateral and the NVIDIA keys carried in the bundle, no network needed. In this mode voltage-verify takes NVIDIA's public keys from the bundle as given; our NVIDIA signatures check above also verified that each signing key's certificate chains to NVIDIA's Attestation Service. Without --offline the tool fetches NVIDIA's live keys instead, which NVIDIA rotates within days, so that run only works shortly after the attestation.
voltage-verify verify bundle.json --offline --challenge 627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45 --hwmodel GB20X --gpus 1Intel's verdict today
We rated the platform with Intel's TCB info embedded at attestation time. This asks Intel's servers now: signature chain, current TCB status, Quoting Enclave identity and revocation, with the quote still bound to this manifest through its report_data.
python3 -c "import json,base64;s=json.load(open('bundle.json'))['tdx']['quote_b64'];open('quote.bin','wb').write(base64.b64decode(s+'='*(-len(s)%4)))" voltage-verify quote quote.bin --report-data 45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7fWatch it fail when it should
Six mutations (manifest, challenge, quote, GPU claim) must each be rejected.
voltage-verify selftest bundle.json --offline --challenge 627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45That the challenge is yours
Only whoever generated the challenge knows it was fresh. If you asked for this proof, check that the challenge above is the one you issued: a replayed bundle carries someone else's.
That the measurements are the VM image you trust
MRTD and RTMR0 to RTMR3 measure the initial VM state and boot chain. Whether they match a reference image is a policy decision we do not make for you.
§ 03 / limits
What this page does not prove
- That the trust domain and the GPU are the same machine. The Intel quote and the NVIDIA tokens are tied to each other only through the manifest hash they both carry.
- That the GPU executed the image or model named in the manifest. Both proofs carry a hash of a description of the workload, not of the code that ran; that needs a measured launcher.
- Which company operated the machine. The proofs come from Intel and NVIDIA hardware and name no cloud provider.
- Who uploaded this page, or who wrote the manifest. Its free-text fields are user-provided; their hash is in both proofs, so a copied bundle still carries its original text and challenge.
§ 04 / Intel TDX
Measurements and platform status
Read from the signed TD report inside the quote.
- MRTD
- eea8b6a814569a52bd1e12f6b869bb2d9c0c8a7a43e658ffc3b42c199f116157ea7f04d359c7fdfd8ac483152cc13542initial contents of the trust domain (firmware image)
- RTMR0
- f9ac3522e05572c2ede103eb9f243bebddee62d8e8db65a526736ea2bd5eb6dbe69a5ff8082c8050865b5ddadae4fa8atypically firmware configuration
- RTMR1
- 965b54adf526d37237906189a31d9b058c39fac8909d9689e3340505aac4176deed2c2f3374b226304b23137d4832ae9typically boot loader and kernel
- RTMR2
- d9d5a5c17828c2b8b390a7df2fc5f060211342001b8044705182c400e4ab24c761630531ff15f2b0defd384c08816f3atypically kernel command line and initrd
- RTMR3
- 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000free for the workload to extend
- MRSEAM
- 476a2997c62bccc78370913d0a80b956e3721b24272bc66c4d6307ced4be2865c40e26afac75f12df3425b03eb59ea7cthe Intel TDX module
- REPORTDATA
- 45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7fSHA-512 of the manifest
- TDATTRIBUTES
- 0000001000000000debug off
- XFAM
- e702060000000000
- TEE_TCB_SVN
- 05030400000000000000000000000000
- FMSPC
- 20a06d080000Intel platform family
- Quote
- v4, TEE type 0x81, 4940 bytes
- Platform TCB
- UpToDateTCB level of 2025-08-13
- Quoting Enclave
- UpToDate
- TDX module
- TDX_03 UpToDate
- Intel TCB info
- issued 2026-10-09 20:41:15 UTCembedded in the bundle at attestation time, signed by Intel
§ 05 / NVIDIA
GPU attestation claims
| GPU | Model | Driver | VBIOS | Measurements | Secure boot | Debug |
|---|---|---|---|---|---|---|
| GPU-0 | NVIDIA Blackwell (GB20X) | 595.71.05 | 98.02.9E.00.01 | success | on | disabled |
Recorded inside the VM by the tool, not signed by anyone
- nvidia-smi GPU name
- NVIDIA RTX PRO 6000 Blackwell Server Edition
- CC State
- ON
- Multi-GPU Mode
- None
- NVIDIA attestation mode
- single-gpu
- Guest kernel
- 6.8.0-110-generic
- voltage-verify
- 0.2.0bundle written 2026-10-09 21:54:01 UTC
§ 06 / workload manifest
The manifest both proofs carry a hash of
Declared in the manifest; the text fields are user-provided and shown in quotes. Its SHA-512 is the quote's report_data and its SHA-256 the nonce NVIDIA signed: changing one byte breaks both bindings.
- Challenge
- 627ba9c51d4719038e917c7431675b183ac576c819d712178dc8a100f4409a45declared in the manifest
- Manifest written
- 2026-10-09 21:53:58 UTCdeclared in the manifest
- Image
- none named
- SHA-256(manifest)
- aeefa374dde9c9aba705aa3984d83b5c737b3fa0cab81dca3940f2be0edaa686the nonce NVIDIA signed
- SHA-512(manifest)
- 45e6f4a027e0a6b670a265e11f21b81858a70f700706abef927d804898080bf94593e653c10f15ee6af45af71ad48d227a877c3098ed2b4f2eb43bb00af63f7fthe report_data Intel's quote carries
§ 07 / embed
Show it where your clients look
The badge links back to this page. If the page is removed, the badge turns grey and reads "not found".
Need the same proof for your own workload?
A VoltageGPU Confidential VM hands /dev/tdx_guest to you, with full root over SSH. You generate both proofs yourself, on a challenge you choose; the Confidential VM page lists the GPU types on which NVIDIA attestation has been run.