Mechanism · Chip location verification

Evidence & limits

On this page

R1Proposed for bounding how far a chip is from trusted landmark servers when checked

The design is public and detailed, but the one reported prototype has a single published result, which cannot be checked.

Assessed use: bounding how far a chip is from trusted landmark servers when checked

Rubric assessment

  • R1 met: Brass and Aarne give a full design with adversary classes, attacks and cost estimates 1. Aarne, Fist and Withers describe landmark-based verification 7, and Avellar and Grunewald set out how a regulator could run it 4.
  • R2 not met: the IAPS brief reports a rudimentary H100 prototype and one result, a Singapore landmark bounding a chip in Singapore to within 300 miles 2. Ulyssean describes an H100 and AMD SEV-SNP setup with 38 cloud landmarks and a timing method, but publishes no code or systematic end-to-end location results or error rates 3. The single result cannot be reproduced from the available information. NVIDIA's delay-based scheme, reported by Avellar and Grunewald 4, has no published design or results. Tee and Happel publish reproducible results for GPU fingerprinting, which is a component, not end-to-end location verification 9. The most mature implementation for this use, the draft Sovereignty Certificates specification (Lucid sovereignty (location) certificates), is itself R1 10.

Confidence is medium: the demo describes its setup and timing method, but the code is not public and its single location result lacks the data needed for independent reproduction 2 3.

Gaps to the next level
  • A public implementation, or reproducible end-to-end results, on data-centre accelerators with a real landmark network.
  • Published measurements of false-positive and false-negative rates under realistic internet routing.
  • An evaluation against a stated adversary covering delay manipulation, faster network paths, landmark compromise and key extraction.

Assessed 2026-09-25 against rubric v1.1.

Evidence

  • Prototype. An IAPS issue brief from May 2025, which summarises Brass and Aarne's 2024 report, states that a rudimentary version has been prototyped on NVIDIA H100 chips 2. It shows one result, a landmark in Singapore bounding a chip in Singapore to within 300 miles 2. Ulyssean says it built the demonstration with an H100, an AMD SEV-SNP CPU and 38 Google Cloud Run landmarks. Its site describes a toy GPU task, five requests per landmark and shortest-response timing, but gives no end-to-end location result series; it says the code will be released after cleanup 3.
  • NVIDIA. Avellar and Grunewald report, citing Reuters reporting from December 2025, that NVIDIA has confirmed it is developing location verification that estimates a chip's location from communication delays with NVIDIA-run servers 4. NVIDIA's own announcement from that month describes an opt-in fleet-management service that customers install and that reports read-only telemetry, with a client agent slated to be open-sourced 5. The announcement states that NVIDIA GPUs do not have hardware tracking technology, kill switches or backdoors 5. In May 2026 NVIDIA announced Fleet Intelligence, a fleet-management service whose read-only agent it released as open source. NVIDIA reports that the service collects GPU telemetry and verifies GPU integrity, and its announcement describes no location check 6.
  • Costs. The 2024 report estimates that a solution would cost less than $1 million to set up and maintain for several years 1. The 2025 brief puts the chip firmware and software update at under $1 million, and 100 to 500 landmarks at $25,000 each a year, or $2.5 million to $12.5 million a year 2. Avellar and Grunewald repeat the brief's figures 4.
  • Ratings. Ansari rates software-based delay methods as near-term and hardware-integrated, tamper-resistant versions as needing R&D 8. Avellar and Grunewald rate delay-based location verification as novel in maturity, high in effectiveness and not invasive 4.
  • Component result. Tee and Happel's GPU fingerprinting re-identified 24 rented H200 GPUs with 98.8% accuracy from a single run 9. It tests chip identification, not location 9.
  • Specification. The Sovereignty Certificates specification (Lucid sovereignty (location) certificates) is a draft, version 0.1.0, dated 2025-10-21 10. As of September 2026 its repository holds no reference implementation 10.

Limitations

  • Delay inflation. Added delay moved estimated positions by up to 1,000 km in research Brass and Aarne cite; they propose a hard time limit as the counter 1.
  • Faster paths. Dark fibre and other private high-speed links can lower measured delays artificially 1 4.
  • False negatives. A limit set at the vacuum speed of light cannot be beaten, but honest chips may often fail it 1.
  • Landmark compromise. Manipulating a third of the landmarks shifted estimates by about 700 km in cited research 1, and compromised landmarks can spoof measurements directly 4.
  • Key extraction. An extracted key breaks the link between reply and chip 9. Ansari lists glitching and focused-ion-beam editing among physical attacks on embedded mechanisms 8.
  • Tunnelling. The draft specification argues that tunnels add latency and produce inconsistent geometry, and requires rejecting such results 10.
  • Coverage gaps. Chips in transit or storage cannot be checked 4.

Known flaws

Blockers

  • No public code or reproducible end-to-end location results are available for the reported H100 prototype.

  • Per-chip keys must be provisioned and protected against extraction; hardware-integrated, tamper-resistant versions still need R&D.

  • The time limit forces a trade-off: a limit at the speed of light in fibre can be beaten by faster links, while one at the vacuum speed of light makes honest chips fail often.

  • A trusted landmark network must be built and secured, and who should operate it, under what oversight, is unsettled.

Search

Full search page