Mechanism · TEE remote attestation for AI workloads

Root of trust concentrated in a few hardware vendors

On this page

← All known flaws

SignificantTheoretical argumentOpenMechanism-level evidence

Evidence scope

Vendor trust is an assumption of the attestation chain. The root-seed extraction study concerns AMD EPYC Milan and firmware downgrade with privileged host and platform-flash access; it is not evidence of the same failure on Intel, NVIDIA or all AMD generations 37.

The root of trust is the certificate authorities of a small number of vendors (AMD, Intel and NVIDIA), which generate the keys and fuse them onto the chips. Gloria Z notes that whoever has access to a hardware key, or can certify one, can in principle produce valid reports for arbitrary measurements without the physical chip 11. Attestable Audits notes that the approach holds only "as long as the vendor of the secure hardware is trusted" 8. A 2026 preprint reports that a host with root control and the ability to rewrite platform flash can downgrade an AMD EPYC Milan processor to legacy security-processor firmware and extract the hardware root seed from which SEV-SNP attestation keys are derived. The authors state that this lets them forge attestation reports for any firmware version 37. AMD describes the firmware-loader flaw the attack starts from as a legacy attack mitigated in 2021 38.

Sources: [11] · [8] · [37] · [38]

Search

Full search page