Mechanism · TEE remote attestation for AI workloads

DDR4 memory-bus interposers forge SGX and SEV-SNP attestation (Battering RAM, WireTap)

On this page

← All known flaws

CriticalDemonstrated attackOpenMechanism-level evidence

Evidence scope

Critical for the tested DDR4 SGX and SEV-SNP configurations against a physical host attacker. The authors exclude DDR5 from these demonstrations, including TDX servers; the DDR5 attacks have a separate finding 4 5.

Two independent teams broke server TEE attestation on DDR4 memory with interposers they built themselves. Both attacks need physical access to install the device and root privileges on the host 4 5.

  • Battering RAM, by researchers at KU Leuven and the Universities of Birmingham and Durham, uses an interposer with a bill of materials of $47.62. It creates memory aliases at runtime, which bypasses the boot-time alias checks that AMD and Intel introduced against static aliasing attacks such as BadRAM. On Intel Scalable SGX it gained arbitrary read and write access to enclave plaintext and extracted SGX's platform provisioning key, which lets an attacker forge attestation certificates for arbitrary quoting enclaves. On up-to-date AMD SEV-SNP servers it captured the launch digests of genuine VMs and replayed them into modified VMs, so that backdoored VMs pass attestation 4.
  • WireTap, by researchers at Purdue University and Georgia Tech, uses an interposer built for under $1000 that records DDR4 bus traffic. On a Xeon Scalable server in fully trusted status it recovered the ECDSA attestation key of SGX's Quoting Enclave in 45 minutes and forged SGX quotes. The authors then showed end-to-end attacks on SGX-based blockchain deployments 5.

Both attacks are limited to DDR4 systems. The Battering RAM authors state that all commercial TDX machines use DDR5, and the WireTap authors state that 4th and 5th generation Xeon Scalable processors need DDR5 and are not affected by their current work 4 5. According to the Battering RAM authors, Intel and AMD acknowledged the findings but consider physical attacks on DRAM out of scope for their current products 4. The WireTap authors report that Intel considers their attack outside the SGX threat model, and that there is no mitigation besides running servers in secure physical environments 5.

Sources: [4] · [5]

Search

Full search page