Loading…
Tuesday June 23, 2026 3:00pm - 3:25pm PDT
NVIDIA's attestation infrastructure was born from Confidential Computing - securing Hopper GPUs with hardware-rooted, in-band attestation. As AI hardware evolves to rack-scale systems like Vera Rubin NVL72, attestation must evolve with it: new devices, new modes, and new challenges.

This talk covers three dimensions of that evolution. First, we discuss how CC attestation scales to rack-level with Vera Rubin, including NVIDIA's multi-node solution for CC and the challenge of attesting dozens of GPUs, CPUs, and NVSwitches as a unified trusted system. Second, we show how attestation patterns proven in CC are extending to new modes and device types - including fleet intelligence and out-of-band attestation. Third, we share the standards and interoperability challenges we have encountered along the way: inconsistent implementations across the ecosystem, gaps in attestation policy standards, and binding discrete components into trusted subsystems to prevent relay and substitution attacks.

Attendees will leave understanding where NVIDIA attestation is heading and what we have learned about the open problems the ecosystem must solve together.
Speakers
avatar for Rob Nertney

Rob Nertney

Principal software architect, NVIDIA, NVIDIA
Rob Nertney is a principal software architect for confidential computing. He has spent nearly 15 years architecting the features and deployment of accelerator hardware into hyperscale environments for both internal and external use by developers. He has several patents in processor... Read More →
avatar for Spencer Gilson

Spencer Gilson

Senior Systems Software Engineer, NVIDIA
Spencer is a senior system software engineer working on attestation at NVIDIA. He specializes in designing, developing, and maintaining critical services with an emphasis on security and reliability.
Tuesday June 23, 2026 3:00pm - 3:25pm PDT
Courtyard

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link