Mechanism · Chip location verification

Sources

On this page
  1. BA. Brass & O. Aarne (2024). Location Verification for AI Chips. Institute for AI Policy and Strategy. Source recordSupports: design, problem framing, adversary classes, distance bound, fibre versus vacuum speed limits and false negatives, precision, attacks and hard time limits, costs, key storage · Detailed Summary; Solution requirements and threat models; Delay-based methods sections; Three adversarial strategies; Proposed Solution Requirements
  2. BA. Brass (2025). Location Verification for AI Chips (issue brief). Institute for AI Policy and Strategy. Source recordSupports: reported H100 prototype (builder not named) and its single Singapore result; summary of Brass and Aarne's 2024 report; development and landmark network cost estimates · issue brief, pp. 1-2
  3. BUlyssean (2025). Ping-based Location. Ulyssean demonstration site. Source recordSupports: Ulyssean's account of the H100 and AMD SEV-SNP demonstration, 38 landmarks, timing method, code status · Technical details, public JavaScript asset
  4. BB. Avellar & E. Grunewald (2026). Near-Term Verification Methods for AI Chip Exports. Institute for AI Policy and Strategy. Source recordSupports: regulator workflow; maturity and effectiveness ratings; costs; transit gap; evasion and landmark compromise; NVIDIA confirmed developing delay-based verification with NVIDIA-run servers (citing Reuters, December 2025) · §1.6; Executive Summary
  5. BNVIDIA (2025). Opt-In NVIDIA Software Enables Data Center Fleet Management. NVIDIA Blog. Source recordSupports: NVIDIA's opt-in, customer-installed fleet-management service with read-only telemetry and an agent to be open-sourced; NVIDIA's statement that its GPUs lack hardware tracking, kill switches and backdoors (provider self-description) · blog post
  6. BC. Shrauder & G. Frederick (2026). Introducing NVIDIA Fleet Intelligence for Real-Time GPU Fleet Visibility and Optimization. NVIDIA Technical Blog. Source recordSupports: Fleet Intelligence (May 2026): read-only agent released as open source; telemetry and GPU integrity attestation, no location check described (provider self-description) · blog post
  7. BO. Aarne et al. (2024). Secure, Governable Chips: Using On-Chip Mechanisms to Manage National Security Risks from AI & Advanced Computing. Center for a New American Security. Source recordSupports: speed-of-light upper bound; landmark-server illustration; hundreds of landmarks · 'Location Verification', p. 11
  8. BS. Ansari (2026). Hardware-Level Governance of AI Compute: A Feasibility Taxonomy for Regulatory Compliance and Treaty Verification. arXiv. Source recordSupports: feasibility rating; physical attacks on embedded mechanisms · §3.1 (M6); §4.3
  9. BW. Tee & J. Happel (2026). GPU Fingerprinting for Location Verification. arXiv. Source recordSupports: key-extraction weakness; fingerprinting proof of concept and its stated limitations · Abstract; threat model; results; limitations
  10. BSovereignty Certificates Working Group (2025). Sovereignty Certificates: draft specification, version 0.1.0. GitHub (Lucid-Computing/sovereignty-certificate-specification). Source recordSupports: draft protocol structure, threat model, anchor diversity and tunnelling check · §0.3, §4.2, §6.3, §8.1, §8.3.3, §8.3.4

Search

Full search page