When a VM is started, the CIP hardware updates CIP tables with
the protections requested for that VM by the customer. Once successfully
initialized, the hardware makes sure that the hypervisor (or
devices via direct memory access, DMA) is not able to access the
protected memory regions. The hardware generates the hash of the
initial CIP protections and the hash of the initial memory contents,
and updates the attestation measurement signature. The hypervisor
sends the signature back to the customer to attest the virtual machine
that was started.