Mechanism · Confidential multi-party verification
Memory-bus interposition extracts attestation keys and forges attestations
On this page
Evidence scope
Applies to enclave workflows using affected Intel or AMD platforms, including Cove's TDX reference and the PySyft pilot's TDX and H100 stack 2 9. A physical host attacker who defeats the accepted trust root defeats that variant's confidentiality and veracity. These studies do not test the PySyft workflow or ZkAudit's cryptographic route.
The platform-specific attacks and fixes are collected in the TEE findings. Intel TDX attestations were forged with physical access to DDR5 systems and combined with H100 relay 13 14. AMD SEV-SNP attestation was defeated on DDR4 by Battering RAM and from malicious host software by RMPocalypse before AMD's fixes 15 16 17.
Response
The researchers report that Intel and AMD treat physical interposer attacks as out of scope. AMD reports firmware fixes for RMPocalypse 13 14 17.