Source · Tier A · Peer-reviewed

Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory Aliasing

J. De Meulemeester, D. Oswald, I. Verbauwhede, J. Van Bulck. 2026. 47th IEEE Symposium on Security and Privacy (S&P 2026).

Linkhttps://batteringram.eu/
VersionRead the authors' site and the paper PDF linked from it (https://batteringram.eu/batteringram.pdf) on 2026-09-24. Venue from the BibTeX entry on the authors' site (47th IEEE S&P, May 2026); no DOI is printed in the PDF or on the site.
Accessed2026-09-24
NoteIndependent attack paper (KU Leuven, University of Birmingham and Durham University). DDR4 memory interposer with a bill of materials of $47.62. Reports arbitrary plaintext access to Intel Scalable SGX enclaves, extraction of SGX's platform provisioning key, and a full attestation breach on up-to-date AMD SEV-SNP by replaying launch digests. The site states that Intel and AMD acknowledged the findings but consider physical attacks on DRAM out of scope, and links Intel's guidance and AMD bulletin AMD-SB-3024. Hardware schematics and proof-of-concept code at https://github.com/batteringramattack/batteringram.

Cited by