Mechanism · Safeguard attestation

Memory-bus interposition extracts attestation keys and forges attestations

On this page

← All known flaws

SignificantDemonstrated attackOpenInherited evidence

Evidence scope

Applies to variants using the affected Intel or AMD trust roots. PAL*M excludes physical attacks 4. A TDX-backed safeguard claim against a physical host attacker would be defeated, but these studies do not demonstrate a break of the AWS Nitro proof-of-guardrail prototype or of verifier-side recomputation 1 10.

The TEE findings cover DDR5 attacks on Intel TDX, the H100 relay demonstration, DDR4 attacks on AMD SEV-SNP, and software-only SEV-SNP forgery before AMD's fixes 12 13 14 15 16. These are inherited hardware limits; a governance analysis explains why physical access matters in a treaty setting 8.

Response

Intel and AMD place the physical attack class outside their threat models, according to the researchers. AMD reports firmware fixes for RMPocalypse 12 13 16.

Sources: [12] · [13] · [14] · [15] · [16] · [4] · [8] · [1] · [10]

Search

Full search page