Mechanism · Model identity attestation

Underlying attestation can be forged or relayed

On this page

← All known flaws

CriticalDemonstrated attackOpenInherited evidence

Evidence scope

Critical for the enclave route against an operator with physical access to affected hardware, or control of an unpatched SEV-SNP hypervisor. It does not apply to the recomputation route. PAL*M excludes physical attacks, and Tinfoil acknowledges this boundary 2 13.

The enclave route inherits the platform-specific TEE attestation failures. Intel TDX forgery and H100 relay were demonstrated with physical access and host control 9. Battering RAM defeated AMD SEV-SNP attestation on DDR4 servers; RMPocalypse did so from malicious host software on platforms without AMD's fixes 10 11 12. These demonstrate failures of the trust roots, not of each model-commitment protocol.

Response

The TEE.fail authors report that physical interposer attacks are outside Intel's and AMD's threat models. AMD reports fixes for RMPocalypse 9 12.

Sources: [9] · [10] · [11] · [12] · [13] · [2]

Search

Full search page