New hardware device can RAM into encrypted memory, expose your data
Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments.
But the attacker would need physical access to the victim system.
Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh.
As a result, they've been able to devise a small hardware interposer, dubbed DDRop, that when wired to an appropriate circuit board, interferes with DDR5 write operations.
Unable to tell that memory isn't fresh, a protected VM becomes vulnerable to a replay attack that uses stale, attacker-selected data.
They describe their work in a paper titled, "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes." Their attack requires physical access and so it is relevant mainly in scenarios where confidential computing guarantees have been made to tenants by cloud service providers.
"DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module," explained Jo Van Bulck, a professor in the DistriNet lab at KU Leuven, Belgium, in an email to The Register.
"It corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory.
The protected VM keeps computing on old data that still decrypts perfectly.
We are releasing the complete interposer design as open-source hardware." The attack breaks the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP, used in trusted execution environments (TEEs).
Van Bulck and colleagues Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede developed a proof-of-concept attack on a current Intel TDX server.
"By injecting maliciously crafted secure page-table entries, we can force any protected VM into debug mode and read out its private memory in plaintext," said Van Bulck.
"Furthermore, writing to critical TDX metadata structures enables forged attestation reports, so that a backdoored VM appears trusted to the remote user." Both attacks, said Van Bulck, succeed deterministically in under two minutes without crashing the machine.
Several of these researchers developed a similar attack on DDR4.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.