Tamper evidence and tamper resistance
Tamper evidence makes interference detectable; tamper resistance makes it difficult or costly; tamper response reacts to it, often by erasing secrets.
Tamper evidence is an external indication that someone has tried to compromise a device's physical security; tamper resistance makes such attempts difficult, costly or both; and tamper response is an automatic action, at minimum erasing plaintext keys, taken when tampering is detected 1 2.
The US standard for cryptographic modules, FIPS 140-2, since superseded by FIPS 140-3, layers these properties 1:
- Level 2 requires evidence of tampering, such as tamper-evident coatings or seals, or pick-resistant locks on covers and doors 1.
- Level 3 adds detection and response circuitry that zeroizes plaintext secret and private keys when covers or doors are opened 1.
- Level 4 requires a complete envelope of protection intended to detect and respond to all unauthorized attempts at physical access 1.
These properties matter because the prover usually controls the hardware: Shavit notes that unlimited physical access could undermine a chip's attestation, and relies on inspections to find hardware attacks that damage chips in ways that are hard to hide 3. The flexHEG proposal houses its guarantee processor in a secure enclosure that provides physical tamper protection (Hardware-enabled guarantees (flexHEG) and guarantee processors) 4. For verifier equipment in the prover's facility, such as network taps and recomputation servers, one verification plan names tamper-evident enclosures among promising and existing physical security methods, the subject of tamper evidence for verifier devices 5. Seals can be defeated with simple methods: a 1996 Los Alamos study demonstrated low-tech defeats for each of the 94 passive and electronic seals it examined, with a mean defeat time of 4.3 minutes for one practised person 6.
Related
Used in
- R1Chip registries and manufacturing records
- R1Hardware-enabled guarantees (flexHEG) and guarantee processors
- R2Tamper evidence for verifier devices
- R2TEE remote attestation for AI workloads⚠
- R1Low-trust AI compute verification system overview
- R1RAND secure inference data center (SIDC) design
- Chips are where they are declared to be
Sources
- ANational Institute of Standards and Technology (2001). Security Requirements for Cryptographic Modules (FIPS PUB 140-2). National Institute of Standards and Technology. Source recordSupports: definitions of tamper evidence, tamper detection and tamper response; physical security Levels 2–4; superseded by FIPS 140-3 · §2.1 Glossary; §4.5; CSRC status page
- ANational Institute of Standards and Technology (2026). NIST Computer Security Resource Center (CSRC) Glossary. NIST Computer Security Resource Center. Source recordSupports: tamper resistant: makes alterations difficult, costly or both (definition written for data) · term: tamper_resistant (NISTIR 8202)
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: unlimited physical access can undermine attestation; inspections detect hard-to-hide hardware attacks · §3.1
- BJ. Petrie et al. (2025). Flexible Hardware-Enabled Guarantees for AI Compute. arXiv. Source recordSupports: flexHEG secure enclosure providing physical tamper protection · abstract
- CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: tamper-evident enclosures named among promising and existing physical security methods for taps and recomputation servers · physical security measures
- BR. G. Johnston & A. R. E. Garcia (1996). Physical Security and Tamper-Indicating Devices. Los Alamos National Laboratory, LA-UR-96-3827. Source recordSupports: 94 seals studied; 1–3 low-tech defeats demonstrated for each, 132 in total; mean defeat time 4.3 minutes by one practised person · abstract; results