Interestana
Home/News/DDRop Attack Undermines Intel TDX and AMD SEV-SNP Confidential Computing
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

DDRop Attack Undermines Intel TDX and AMD SEV-SNP Confidential Computing

DDRop Attack Undermines Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have unveiled a novel hardware attack, dubbed DDRop, capable of compromising the memory protection mechanisms of Intel's Trust Domain Extensions (TDX) and AMD's Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP). These technologies are foundational to confidential computing, a paradigm designed to protect data while it is being processed in memory, even from the cloud provider or system administrator. The DDRop attack operates by silently dropping write operations to a server's main memory. This manipulation causes the processor to continue reading outdated, encrypted data as if it were the most current information, thereby bypassing the intended security guarantees.

The successful execution of the DDRop attack necessitates that an attacker already possesses control over the server's software. Furthermore, the attacker requires brief physical access to the machine. This physical access is used to insert a small, custom-built circuit. This circuit is the key component that intercepts and manipulates memory write operations, creating the conditions for the attack. The implications of this vulnerability are significant, as it directly targets the integrity of data processed within confidential computing environments, which are often used for highly sensitive workloads such as financial transactions, healthcare data, and proprietary algorithms.

Confidential computing aims to establish secure enclaves within a system's memory where data can be processed in an encrypted state. Intel TDX and AMD SEV-SNP are hardware-based implementations of this concept. TDX, introduced by Intel, creates isolated execution environments called trusted domains. SEV-SNP, an enhancement to AMD's SEV technology, provides memory encryption and integrity protection for virtual machines, preventing the hypervisor from accessing or tampering with guest memory. The DDRop attack's ability to circumvent these protections by presenting stale data to the processor highlights a critical flaw in how memory writes are handled and verified within these secure environments. The attack effectively tricks the processor into operating on potentially compromised or outdated information, undermining the confidentiality and integrity assurances provided by these advanced security features.

This discovery raises concerns about the overall security posture of cloud infrastructure and enterprise systems that rely on confidential computing for data protection. The requirement for physical access, while a barrier, does not eliminate the threat, particularly in scenarios involving insider threats or sophisticated supply chain attacks. The researchers' disclosure, made public on May 14, 2024, prompts an urgent need for hardware and software vendors to investigate and implement mitigations to address the DDRop vulnerability. The long-term impact could lead to revised security protocols and potentially new hardware designs to ensure the robust protection of data in use.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next