Implementation · Attestable Audits
Relies on the TEE vendor and inherits TEE attacks
On this page
SignificantTheoretical argumentOpenInherited evidence
Evidence scope
The prototype trusts AWS Nitro, not the Intel TDX or AMD SEV-SNP attestation roots targeted by the cited confidential-VM studies. Those studies are class context, not a demonstrated attack on this Nitro prototype 1.
The design depends on trusting the TEE vendor, AWS in the prototype 1. The authors cite memory-aliasing, ciphertext side-channel and malicious-interrupt attacks on confidential VMs (BadRAM, CIPHERLEAKS, Heckler). Their answer is to revoke vulnerable base images once such attacks are discovered 1.
Response
The authors propose revoking vulnerable base images; they do not report a red-team evaluation of the prototype 1.
Sources: [1]