{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "M-0017",
    "slug": "tamper-evidence-for-verifier-devices",
    "title": "Tamper evidence for verifier devices",
    "aliases": [
      "Tamper-evident enclosures",
      "Tamper-respondent enclosures",
      "Tamper-indicating enclosures",
      "Anti-tamper sensing"
    ],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.",
    "summary": "Verification devices such as network taps, gateways and recomputation servers would sit in facilities controlled by the party being checked. Tamper-evident and tamper-resistant enclosures aim to make physical interference visible, or to destroy secrets when it happens. Tamper-respondent modules such as the IBM 4765 are validated at FIPS 140-2 Level 4 and erase their secrets when breached. Nuclear safeguards and arms control use tamper-indicating enclosures. Peer-reviewed prototypes detect probing through capacitive covers, radio waves inside server cases, or on-chip impedance sensing. As of September 2026 none has been built or evaluated for AI verifier hardware, and the MIRI overview lists retrofittable, mass-manufacturable enclosures as an open problem. The main obstacles are scale, batteries and inspection burden. The largest known weakness is that seals are often defeated with simple methods: a 1996 Los Alamos study defeated all 94 seals it examined. Any enclosure is only as good as its inspection protocol.",
    "technical": "- **IBM 4765.** FIPS 140-2 Level 4 overall and for physical security. A tamper-respondent matrix monitors for intrusion and adverse conditions, with moderate and severe out-of-range temperature and voltage sensing. A hard tamper triggers active wiping of secrets: the high-speed-erase battery-backed RAM holding core secrets is erased within microseconds, and the module is zeroized and left inoperable [[S-0050]].\n- **Batteryless PUF cover.** A 140 mm × 140 mm flexPCB cover with 16 × 16 electrodes (256 sensor nodes, 128 used differentially) and 100 µm line and space, checked by an STM32F303 microcontroller. After open- and short-circuit checks pass, a key is derived from the differential capacitances, about 5.2 bits of entropy per node with 10x oversampling (about 665 bits in theory). The attacker model assumes penetrations of at least 300 µm; single 0.3 mm holes made key reconstruction infeasible; a full-cover measurement with 10x oversampling takes 384 ms; power is about 0.6 W; testing spanned −20 °C to +60 °C [[S-1315]].\n- **Anti-Tamper Radio.** Two wideband antennas inside a metal case, measured with a vector network analyzer (2–9 GHz) or ultra-wideband transceivers (2.496–7.488 GHz). In a Dell PowerEdge 2850 over 10 days, 40 mm insertions of 1 mm needles were reliably detected; in an empty aluminium box, 16 mm insertions of needles as thin as 0.1 mm were detected. UWB transceivers cost less than US$5 [[S-0052]].\n- **ImpedanceVerif.** An embedded network analyzer on an FPGA measures the frequency response of the power distribution network, and Wasserstein distance is used as the detection statistic [[S-0051]].",
    "category": "off-chip-devices",
    "secondary_categories": [
      "isolation-architecture"
    ],
    "verifies": [
      {
        "claim": "C-0004",
        "role": "supporting",
        "note": "Protects the integrity of taps, gateways and recomputation hardware used for inference-only verification (S-0018, S-0067)."
      },
      {
        "claim": "C-0008",
        "role": "supporting",
        "note": "Protects network devices that enforce or monitor bandwidth boundaries (S-0018)."
      }
    ],
    "threat_model": "adversarial",
    "adversarial_evaluation": "red-teamed",
    "hardware_requirement": "retrofit-device",
    "prover_cooperation": "partial",
    "confidentiality": "preserving",
    "depends_on": [],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "rubric_version": "1.0",
      "rationale": "R2: peer-reviewed tamper-detection results exist under stated adversaries, one in a running server, but no enclosure has been built or evaluated for AI verifier devices.\n\n- **R1** met: enclosure designs with stated attacker models are published [[S-1315]] [[S-0052]], and the MIRI overview describes their role in protecting verification hardware in a host-controlled facility [[S-0018]].\n- **R2** met: published end-to-end results exist under a stated adversary. Anti-Tamper Radio reliably detected needle insertions in a running 19-inch server over a 10-day experiment [[S-0052]]. Immler et al. report statistics over 115 batteryless covers, plus physical attacks against a stated 300 µm penetration model and environmental tests [[S-1315]]. On-chip impedance sensing detected board- and package-level tampering on commercial FPGA kits [[S-0051]]. All three are peer-reviewed; no public code or design files are cited for them.\n- **R3** not met for this use: production-grade, independently validated tamper-respondent modules exist (the IBM 4765 is validated at FIPS 140-2 Level 4) [[S-0050]], and tamper-indicating enclosures are used in safeguards and arms control [[S-1316]]. None has been built for, or evaluated on, AI verifier devices such as optical taps, FPGA gateways or recomputation servers. The MIRI overview lists \"tamper-evident, rapidly mass-manufacturable and retrofittable enclosures\" as an open research question [[S-0018]]. The mechanism's only implementation, [[I-0011]], is a proposed architecture at R1.\n\nConfidence is medium, because how far the server-scale and HSM results transfer to AI verifier hardware is a judgment call.",
      "evidence": [
        "S-0052",
        "S-1315",
        "S-0051",
        "S-0050",
        "S-1316",
        "S-0018"
      ],
      "next_level_gaps": [
        "An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.",
        "An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.",
        "Inspection protocols suited to host-controlled AI facilities."
      ],
      "confidence": "medium",
      "assessed_by": [
        "ai-draft"
      ],
      "assessed_on": "2026-09-23",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Seals are often defeated with simple methods",
        "kind": "demonstrated-attack",
        "severity": "significant",
        "status": "open",
        "description": "In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals are often easier to defeat than low-tech ones.",
        "sources": [
          "S-1317",
          "S-1318"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "Security depends on inspection protocols",
        "kind": "theoretical-argument",
        "severity": "significant",
        "status": "open",
        "description": "Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data must be authenticated.",
        "sources": [
          "S-1318",
          "S-1316"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "Attack classes outside published models",
        "kind": "open-question",
        "severity": "significant",
        "status": "open",
        "description": "The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest gradually renewing the reference.",
        "sources": [
          "S-1315",
          "S-0052"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale.",
        "theme": "hardware-trust",
        "blocked_by": null,
        "sources": [
          "S-0018"
        ]
      },
      {
        "text": "Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport.",
        "theme": "performance-compatibility",
        "blocked_by": null,
        "sources": [
          "S-1315"
        ]
      },
      {
        "text": "Active monitoring needs power, and visual inspection of large enclosures faces access limits.",
        "theme": "access-governance",
        "blocked_by": null,
        "sources": [
          "S-1316"
        ]
      },
      {
        "text": "No evaluation has been published in the AI verification setting.",
        "theme": "adversarial-validation",
        "blocked_by": null,
        "sources": [
          "S-0018"
        ]
      }
    ],
    "challenge_themes": [
      "hardware-trust",
      "adversarial-validation",
      "access-governance",
      "performance-compatibility"
    ],
    "organizations": [],
    "people": [],
    "sources": [
      {
        "source": "S-0050",
        "supports": "FIPS 140-2 Level 4; tamper-respondent matrix; sensed conditions; zeroization",
        "locator": "Table 1; §2 physical security; §8.1 Table 9"
      },
      {
        "source": "S-0049",
        "supports": "existence of a review spanning battery-backed to PUF-based enclosures",
        "locator": "title and abstract (full text not read)"
      },
      {
        "source": "S-1315",
        "supports": "batteryless PUF cover design, attacker model, results, stated limitations, drawbacks of battery-backed enclosures",
        "locator": "abstract; §2.1; §3.1; §8"
      },
      {
        "source": "S-0052",
        "supports": "Anti-Tamper Radio concept, threat model, server experiment, costs, limitations",
        "locator": "abstract; §III–§VI"
      },
      {
        "source": "S-0051",
        "supports": "on-chip impedance sensing for tamper detection",
        "locator": "abstract"
      },
      {
        "source": "S-1316",
        "supports": "tamper-indicating enclosures in verification regimes; approaches; limitations",
        "locator": "abstract; survey sections"
      },
      {
        "source": "S-1317",
        "supports": "seal vulnerability assessment results; mean defeat time for one practised person",
        "locator": "abstract; results; Table 2"
      },
      {
        "source": "S-1318",
        "supports": "high-tech vs low-tech seals; role of protocols and inspector training",
        "locator": "main text"
      },
      {
        "source": "S-0018",
        "supports": "enclosure needs in low-trust AI verification; open question on retrofittable enclosures; inspections",
        "locator": "§2b; §4.2; §5.3.1"
      },
      {
        "source": "S-0067",
        "supports": "tamper-evident enclosures among physical security measures",
        "locator": "physical security discussion"
      },
      {
        "source": "S-0035",
        "supports": "flexHEG secure enclosure for physical tamper protection",
        "locator": "abstract"
      }
    ],
    "concepts": [
      "K-0015",
      "K-0005",
      "K-0018",
      "K-0002"
    ],
    "complements": [
      "M-0013",
      "M-0014",
      "M-0022",
      "M-0009"
    ],
    "alternatives": [],
    "type": "mechanism",
    "implementations": [
      {
        "id": "I-0011",
        "title": "AI 2040 inference-only verification stack",
        "url": "https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/"
      }
    ],
    "url": "https://trustbutveri.fyi/mechanisms/tamper-evidence-for-verifier-devices/",
    "source_file": "content/mechanisms/tamper-evidence-for-verifier-devices.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "## How it works\n\nVerification hardware placed in a facility run by the party being checked needs protection against physical interference [[S-0018]]. The MIRI system overview relies on monitoring of the facility and on occasional random inspections of analog components and anti-tamper seals [[S-0018]]. Obermaier and Immler review enclosures from battery-backed monitoring to PUF-based designs [[S-0049]]. Published approaches fall into four groups:\n\n- **Tamper-respondent modules.** The IBM 4765 coprocessor uses a \"protective, tamper-respondent matrix to monitor for intrusion and adverse physical conditions\" [[S-0050]]. On a hard tamper, it actively erases its core secrets within microseconds [[S-0050]].\n- **Batteryless tamper-resistant covers.** Immler et al. wrap the protected system in a flexible circuit-board cover with a fine electrode mesh [[S-1315]]. A key is derived from the mesh's capacitances, which act as a physical unclonable function (PUF), and decrypts the system's sensitive data only if the cover is intact [[S-1315]].\n- **System-level sensing.** Anti-Tamper Radio monitors how radio waves propagate inside a metal case, so inserted objects change the measured response [[S-0052]]. ImpedanceVerif uses on-chip network analyzers on FPGAs to detect changes in a board's power distribution network, \"without any modifications to the system\" [[S-0051]].\n- **Tamper-indicating enclosures.** In safeguards and arms control, these leave physical evidence of attack [[S-1316]]. They cover the case where an adversary bypasses a sealed opening, for example by drilling through a side [[S-1316]].\n\nIn AI proposals, flexHEG pairs a guarantee processor with \"a secure enclosure providing physical tamper protection\" [[S-0035]]; see [[M-0009]]. The AI 2040 plan lists tamper-evident enclosures among physical security measures [[S-0067]]. The MIRI overview notes that standards exist for secure facilities (SCIFs) [[S-0018]]. What is less established, it says, is \"what defenses can be retrofitted at a massive scale to prevent bypassing of network taps\" [[S-0018]].\n\n## What it establishes\nEnclosures can show that a device was physically accessed [[S-1316]], or can make a breach destroy the keys or data an attacker wants [[S-0050]] [[S-1315]]. They protect the integrity of other mechanisms, such as taps ([[M-0013]]) and bandwidth shapers ([[M-0014]]), rather than proving a claim on their own [[S-0018]]. Johnston argues that \"a seal is no better than the protocols for using it\" [[S-1318]].\n\n## Threat model\n- **Cover.** Immler et al. \"assume penetrations to be at least 300µm in diameter\" [[S-1315]]. They deem cover removal impractical and do not assess chemical solvents [[S-1315]].\n- **Radio sensing.** Anti-Tamper Radio defines success for the attacker as inserting a needle into a sensitive region without detection [[S-0052]].\n- **AI facilities.** The host controls the facility, so the MIRI overview combines enclosures with continuous monitoring and random inspection [[S-0018]].\n\n## Evidence\n- **IBM 4765.** Validated at FIPS 140-2 Level 4, overall and for physical security [[S-0050]].\n- **Batteryless covers.** Immler et al. report statistics over 115 flexPCB covers, physical attacks and environmental testing, aiming at a physical security level comparable to FIPS 140-2 Level 3 [[S-1315]].\n- **Anti-Tamper Radio.** In a running 19-inch server over 10 days, it reliably detected 40 mm insertions of 1 mm needles [[S-0052]].\n- **ImpedanceVerif.** It detected tampering on commercial FPGA development kits, including the proximity of contactless EM probes and a slightly polished chip package [[S-0051]].\n- **Tamper-indicating enclosures.** They support IAEA safeguards and arms-control chain-of-custody regimes [[S-1316]].\n\nAs of September 2026 no enclosure for AI verifier hardware has been evaluated in public. The MIRI overview lists \"tamper-evident, rapidly mass-manufacturable and retrofittable enclosures\" as an open question [[S-0018]].\n\n## Limitations\n- **Seal defeats.** In 1996 a Los Alamos team defeated all 94 seals it examined, with 132 defeats using low-tech methods; one practised person needed 4.3 minutes on average [[S-1317]]. Johnston reports that \"high-tech seals are often easier to defeat than low-tech seals\" [[S-1318]].\n- **Batteries.** Battery-backed designs add bulk, limit the operating temperature range and fail when discharged [[S-1315]].\n- **Inspection and power.** Visual methods on large enclosures face access limits, active approaches need power, and sensor data must be authenticated [[S-1316]].\n- **Drift.** Anti-Tamper Radio's reference measurement can drift as the environment or the measurement system ages, which the authors suggest handling by gradually renewing the reference [[S-0052]].",
    "body_text": "How it works Verification hardware placed in a facility run by the party being checked needs protection against physical interference [S-0018]. The MIRI system overview relies on monitoring of the facility and on occasional random inspections of analog components and anti-tamper seals [S-0018]. Obermaier and Immler review enclosures from battery-backed monitoring to PUF-based designs [S-0049]. Published approaches fall into four groups: - Tamper-respondent modules. The IBM 4765 coprocessor uses a \"protective, tamper-respondent matrix to monitor for intrusion and adverse physical conditions\" [S-0050]. On a hard tamper, it actively erases its core secrets within microseconds [S-0050]. - Batteryless tamper-resistant covers. Immler et al. wrap the protected system in a flexible circuit-board cover with a fine electrode mesh [S-1315]. A key is derived from the mesh's capacitances, which act as a physical unclonable function (PUF), and decrypts the system's sensitive data only if the cover is intact [S-1315]. - System-level sensing. Anti-Tamper Radio monitors how radio waves propagate inside a metal case, so inserted objects change the measured response [S-0052]. ImpedanceVerif uses on-chip network analyzers on FPGAs to detect changes in a board's power distribution network, \"without any modifications to the system\" [S-0051]. - Tamper-indicating enclosures. In safeguards and arms control, these leave physical evidence of attack [S-1316]. They cover the case where an adversary bypasses a sealed opening, for example by drilling through a side [S-1316]. In AI proposals, flexHEG pairs a guarantee processor with \"a secure enclosure providing physical tamper protection\" [S-0035]; see Hardware-enabled guarantees (flexHEG) and guarantee processors. The AI 2040 plan lists tamper-evident enclosures among physical security measures [S-0067]. The MIRI overview notes that standards exist for secure facilities (SCIFs) [S-0018]. What is less established, it says, is \"what defenses can be retrofitted at a massive scale to prevent bypassing of network taps\" [S-0018]. What it establishes Enclosures can show that a device was physically accessed [S-1316], or can make a breach destroy the keys or data an attacker wants [S-0050] [S-1315]. They protect the integrity of other mechanisms, such as taps (Network taps and certifiers) and bandwidth shapers (Bandwidth limits and compartmentalization), rather than proving a claim on their own [S-0018]. Johnston argues that \"a seal is no better than the protocols for using it\" [S-1318]. Threat model - Cover. Immler et al. \"assume penetrations to be at least 300µm in diameter\" [S-1315]. They deem cover removal impractical and do not assess chemical solvents [S-1315]. - Radio sensing. Anti-Tamper Radio defines success for the attacker as inserting a needle into a sensitive region without detection [S-0052]. - AI facilities. The host controls the facility, so the MIRI overview combines enclosures with continuous monitoring and random inspection [S-0018]. Evidence - IBM 4765. Validated at FIPS 140-2 Level 4, overall and for physical security [S-0050]. - Batteryless covers. Immler et al. report statistics over 115 flexPCB covers, physical attacks and environmental testing, aiming at a physical security level comparable to FIPS 140-2 Level 3 [S-1315]. - Anti-Tamper Radio. In a running 19-inch server over 10 days, it reliably detected 40 mm insertions of 1 mm needles [S-0052]. - ImpedanceVerif. It detected tampering on commercial FPGA development kits, including the proximity of contactless EM probes and a slightly polished chip package [S-0051]. - Tamper-indicating enclosures. They support IAEA safeguards and arms-control chain-of-custody regimes [S-1316]. As of September 2026 no enclosure for AI verifier hardware has been evaluated in public. The MIRI overview lists \"tamper-evident, rapidly mass-manufacturable and retrofittable enclosures\" as an open question [S-0018]. Limitations - Seal defeats. In 1996 a Los Alamos team defeated all 94 seals it examined, with 132 defeats using low-tech methods; one practised person needed 4.3 minutes on average [S-1317]. Johnston reports that \"high-tech seals are often easier to defeat than low-tech seals\" [S-1318]. - Batteries. Battery-backed designs add bulk, limit the operating temperature range and fail when discharged [S-1315]. - Inspection and power. Visual methods on large enclosures face access limits, active approaches need power, and sensor data must be authenticated [S-1316]. - Drift. Anti-Tamper Radio's reference measurement can drift as the environment or the measurement system ages, which the authors suggest handling by gradually renewing the reference [S-0052].",
    "referenced_by": [
      {
        "id": "M-0014",
        "title": "Bandwidth limits and compartmentalization",
        "url": "https://trustbutveri.fyi/mechanisms/bandwidth-limits-and-compartmentalization/"
      },
      {
        "id": "M-0018",
        "title": "Chip location verification",
        "url": "https://trustbutveri.fyi/mechanisms/chip-location-verification/"
      },
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0013",
        "title": "Network taps and certifiers",
        "url": "https://trustbutveri.fyi/mechanisms/network-taps-and-certifiers/"
      },
      {
        "id": "M-0022",
        "title": "Side-channel suppression for isolated facilities",
        "url": "https://trustbutveri.fyi/mechanisms/side-channel-suppression/"
      },
      {
        "id": "I-0011",
        "title": "AI 2040 inference-only verification stack",
        "url": "https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/"
      },
      {
        "id": "I-0012",
        "title": "Low-trust AI compute verification system overview",
        "url": "https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/"
      },
      {
        "id": "I-0008",
        "title": "SASH confidential network logger",
        "url": "https://trustbutveri.fyi/implementations/sash-confidential-network-logger/"
      },
      {
        "id": "C-0008",
        "title": "Communication between compute groups is bounded",
        "url": "https://trustbutveri.fyi/claims/bandwidth-is-bounded/"
      },
      {
        "id": "K-0015",
        "title": "Tamper evidence and tamper resistance",
        "url": "https://trustbutveri.fyi/concepts/tamper-evidence/"
      }
    ]
  }
}