Explore secure device attach in Arm CCA Realms
Introduction
About CCA Realms
VirtIO for device attach
Bounce buffers in Realms
Exercise: observe bounce buffers in a Realm
Next Steps
Explore secure device attach in Arm CCA Realms
Who is this for?
This is an advanced topic for developers who want to understand how Arm CCA Realms interact with I/O devices using VirtIO, bounce buffers, and secure device attach mechanisms.
What will you learn?
Upon completion of this Learning Path, you will be able to:
- Define device attach and distinguish VirtIO paravirtualized attach from secure physical device attach
- Summarize what a Realm is and how RME isolates Realm memory
- Describe how VirtIO enables paravirtualized I/O without full device emulation
- Explain when and why SWIOTLB bounce buffers are used in Realms
- Describe how PCIe‑TDISP and PCIe‑IDE support secure physical device attach and attestation
Prerequisites
Before starting, you will need the following:
- An AArch64 or x86_64 computer running Linux or macOS. You can also use a cloud instance from one of these Arm cloud service providers .
- Completion of Get Started with CCA Attestation and Veraison Learning Path
- Completion of the Run an application in a Realm using the Arm Confidential Computing Architecture (CCA) Learning Path
- Completion of the Run an end-to-end Attestation Flow Learning Path
Summary
This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
Frequently asked questions
These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.