TRESOR plus TreVisor or an equivalent hypervisor is a necessary but not sufficient step to protecting a virtual machine from the physical server hardware or server operator. You also need trusted EFI (coreboot), Intel TXT, and a separation kernel (of which there are ~3 DOD funded ones, and a few more.
Comments
I care about servers, not clients.
TRESOR plus TreVisor or an equivalent hypervisor is a necessary but not sufficient step to protecting a virtual machine from the physical server hardware or server operator. You also need trusted EFI (coreboot), Intel TXT, and a separation kernel (of which there are ~3 DOD funded ones, and a few more.