---
title: Start your SEV VMs on Google Cloud
description: SEV is a new security feature that is available on AMD’s EPYC processors.
  It stands for Secure Encrypted Virtualization Secure Nested Pages. SEV provides
  a new level of protection for firmware by encrypting the memory pages that contain
  the firmware code. This makes it much more difficult for attackers to gain access
  to the firmware  […]
url: https://canonical.com/blog/start-your-sev-vms-on-google-cloud?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Hugo Huang](https://canonical.com/blog/author/hugohuangtao "More about Hugo Huang")

21 July 2023

# Start your SEV VMs on Google Cloud

[confidential computing](https://canonical.com/blog/tag/confidential-computing)
[Google Cloud](https://canonical.com/blog/tag/google-cloud)
[Ubuntu Pro](https://canonical.com/blog/tag/ubuntu-pro)

---

Share the article

SEV is a new security feature that is available on AMD’s EPYC processors. It stands for Secure Encrypted Virtualization Secure Nested Pages. SEV provides a new level of protection for firmware by encrypting the memory pages that contain the firmware code. This makes it much more difficult for attackers to gain access to the firmware and launch attacks.

## The benefit of SEV

With SEV embedded firmware in your VMs, you will enjoy improved security, increased isolation, enhanced performance for your VMs.

* Improved security. SEV encrypts the memory pages that contain firmware code. This makes it much more difficult for attackers to gain access to the firmware and launch attacks.
* Increased isolation. SEV allows each VM to have its own secure memory space. This means that a VM cannot access the memory of another VM, even if the hypervisor is compromised.
* Enhanced performance. SEV can be used to improve the performance of virtualized applications. This is because SEV allows the hypervisor to offload some of the security processing to the processor.

## The relationship between SEV and Confidential Computing

Confidential Computing is the protection of data in-use with hardware-based Trusted Execution Environment (TEE). TEEs are secure and isolated environments that prevent unauthorized access or modification of applications and data while they are in use. This security standard is defined by the [Confidential Computing Consortium](https://confidentialcomputing.io/). The end-to-end encryption is comprised of three states.

* *Encryption-at-rest* protects your data while it is being stored.
* *Encryption-in-transit* protects your data when it is moving between two points.
* *Encryption-in-use* protects your data while it is being processed.

Confidential Computing provides the last piece of end-to-end encryption: *encry*ption-in-use.

SEV provides an extra layer of safeguard against malicious hypervisor-based attacks, such as data reply and memory re-mapping. These protections establish a secure and isolated execution environment, bolstering overall security.

Furthermore, SEV introduces several optional security enhancements tailored to support various VM use models. It also strengthens protection around interrupt behavior and bolsters defenses against recently discovered side channel attacks.

## How to start a SEV VM (Private Preview) on Google Cloud

In Google Cloud Console, choose Compute Engine and Create an Instance. Make sure you select N2D machine (AMD EPYC).

* *On Aug 31st, 2023, SEV is still in Private Preview on Google Cloud.*

Under Boot disk, select a SEV compatible Operating System, such as Ubuntu 22.04 LTS Pro Server (x86/64, amd64 jammy pro server).

Make sure enable Confidential VM service

Click CREATE. Enjoy your SEV VM!

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed](https://canonical.com/blog/arduino-ventuno-q-is-available-for-pre-order-with-ubuntu-pre-installed)

London, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary of Qualcomm Technologies, Inc.) are excited...

[Canonical](https://canonical.com/blog/author/canonical)

25 August 2026

[### Canonical announces the Enterprise Store as part of Ubuntu Pro](https://canonical.com/blog/canonical-announces-the-enterprise-store)

Canonical introduces a new way to manage software behind firewalls and in air-gapped environments with the Enterprise Store. The Enterprise Store makes software distribution...

[Holly Hall](https://canonical.com/blog/author/hollyhall)

21 July 2026

[### Tracing a memory leak bug in PID 1 and contributing an upstream fix: a Linux support story](https://canonical.com/blog/fixing-memory-bug)

How Canonical Support helped a global retail organization trace the cause for an unusual memory leak originating in PID 1. By investigating the issue across three separate...

[Lidia Luna Puerta](https://canonical.com/blog/author/lidia-luna)

17 July 2026

[### Ubuntu Server: a platform made for enterprise scale](https://canonical.com/blog/ubuntu-server-a-platform-made-for-enterprise-scale)

A platform is an environment that allows software to run smoothly across the infrastructure, runtime, and application layers. The key word there is “smoothly”: a good platform...

[Rhys Knipe](https://canonical.com/blog/author/rhysknipe)

7 July 2026
